No more typing reviews! Try our Samantha, our new voice AI agent.

Expel vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Expel
Ranking in SOC as a Service
4th
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
1
Ranking in other categories
Managed Detection and Response (MDR) (15th)
Palo Alto Networks Cortex X...
Ranking in SOC as a Service
2nd
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
51
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd)
 

Mindshare comparison

As of June 2026, in the SOC as a Service category, the mindshare of Expel is 6.9%, down from 9.0% compared to the previous year. The mindshare of Palo Alto Networks Cortex XSOAR is 5.1%, down from 19.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
SOC as a Service Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR5.1%
Expel6.9%
Other88.0%
SOC as a Service
 

Featured Reviews

reviewer2578461 - PeerSpot reviewer
MDR Specialist at a tech services company with 201-500 employees
Rapid threat management and diverse technology integration for effective monitoring
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.
Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Security automation has transformed incident workflows and now reduces response time dramatically
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX. We have communicated with the vendor team about this, but they are prioritizing product functionality over usability because most target customers are technical and understand a primitive UI. They face difficulties in implementing UI changes as their team is stretched. Thus, the UI/UX of the tool needs significant improvement. There are plans on their roadmap, but a lot remains to be done. Parts of the tool run on an older framework, causing slowness. Usability is a broader issue than features alone. This usability problem is common in many cybersecurity tools, unlike customer-facing applications. Some integrations have speed issues and might not function seamlessly with different upstream configurations, requiring manual updates. These are the main pain points we encountered, particularly with UI/UX, integration speed, and the usability of certain inbuilt playbooks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses."
"Palo Alto has reduced the time that it takes to go through the process of investigating a reported abuse."
"The most valuable feature is automation."
"It is a scalable solution."
"The solution has very good integration capabilities; it's really the best at integration, with commands inside every integration that make it very useful as a product, and the automation is excellent."
"I would rate the stability of Cortex XSOAR as nine out of ten."
"Palo Alto has gotten the investigators more presence to actually go in the report because being that the platform will email the investigator that it's been assigned to, now the investigators will jump in there and start going through the review process a lot quicker."
"The orchestration in XSOAR is significantly easier compared to other SOAR tools I've used."
"The most valuable features of Palo Alto Networks Cortex XSOAR are its overall track record and features that fit our use case."
 

Cons

"The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management."
"When Palo Alto bought the solution, the pricing increased by 1.5 times. There's been a 50% increase, which is a lot."
"For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else. In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added."
"I would like to see Cortex become less dependent on Active Directory and group policies to manage the deployment. Maybe I need to update my understanding of how to deploy it, but that's the way I know how to use it."
"I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX."
"For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective."
"Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated."
"The solution is not a Palo Alto product so technical support is inadequate."
"The formats are not compatible, are readily not available, and are not readable."
 

Pricing and Cost Advice

Information not available
"On a scale of one to ten, where one is a low price, and ten is a high price, I rate the pricing a nine."
"The price of Palo Alto Networks Cortex XSOAR could be reduced. We are always looking for a discount. There is an annual license needed to use this solution."
"It's cheaper compared to its competitors."
"The solution's cost is high."
"The solution's pricing needs improvement."
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"The pricing is fair. The pricing reflects the value and feature set it offers."
report
Use our free recommendation engine to learn which SOC as a Service solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
11%
Construction Company
11%
Manufacturing Company
8%
Financial Services Firm
13%
Computer Software Company
8%
Manufacturing Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise9
Large Enterprise26
 

Questions from the Community

What is your experience regarding pricing and costs for Expel?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What needs improvement with Expel?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for m...
What is your primary use case for Expel?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
Regarding areas for improvement in Palo Alto Networks Cortex XSOAR, I want to highlight one concern about playbook creation. While I personally appreciate this approach, I have observed that junior...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My primary use cases for Palo Alto Networks Cortex XSOAR are malware incidents, specifically phishing-related incidents, Trojan horses, spyware, and similar threats.
 

Also Known As

Workbench, Expel SOC-as-a-Service
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Amanda Fennell CSO
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Arctic Wolf Networks, Palo Alto Networks, LevelBlue and others in SOC as a Service. Updated: June 2026.
902,270 professionals have used our research since 2012.