No more typing reviews! Try our Samantha, our new voice AI agent.

ExtraHop Reveal(x) 360 vs TrendAI Vision One comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
ExtraHop Reveal(x) 360
Ranking in Extended Detection and Response (XDR)
41st
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
3
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (23rd), Container Security (52nd), Network Traffic Analysis (NTA) (13th)
TrendAI Vision One
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
107
Ranking in other categories
Endpoint Detection and Response (EDR) (4th), Network Detection and Response (NDR) (3rd), Attack Surface Management (ASM) (3rd), AI-Powered Cybersecurity Platforms (4th), AI Security (2nd)
 

Mindshare comparison

As of May 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.7%, down from 5.1% compared to the previous year. The mindshare of ExtraHop Reveal(x) 360 is 1.0%, up from 0.3% compared to the previous year. The mindshare of TrendAI Vision One is 3.4%, down from 3.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
TrendAI Vision One3.4%
Cortex XDR by Palo Alto Networks4.7%
ExtraHop Reveal(x) 3601.0%
Other90.9%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Maksym Toporkov - PeerSpot reviewer
Head of Research And Development at Quipu GmbH
A competitive choice for network detection and response with exceptional user interface, ease of implementation and minimal false positives
The NDR feature analyzes network traffic, creating records with connection details. While these records offer insights, there's a limitation in investigating payloads directly. ExtraHop provides an option for an additional server to save payloads, but its temporary storage has constraints. Unlike some competitors, it lacks an automatic payload-saving feature for each detection, presenting an improvement opportunity. Suggested enhancement involves the main sensor prompting payload storage for specific detections, streamlining the investigation process, and contributing to a more efficient workflow. A drawback includes packet storage limitations for payload data, necessitating timely extraction for thorough investigations.
SemihDalkıran - PeerSpot reviewer
Cyber Security Senior Technical Consultant at a consultancy with 11-50 employees
Built faster threat response and improved visibility with real-time monitoring and flexible deployment
TrendAI Vision One allows us to monitor attacks in real time, which is a significant benefit. We can quickly see where the attack is coming from. TrendAI Vision One enables us to use different products with a flexible license. For example, if a customer is using endpoint security and wants to switch to another solution, they can instantly use a different Trend Micro product, such as email. TrendAI Vision One has helped to reduce the time to detect and respond to different threats, as it can respond to attacks very quickly. With playbook templates, in cases of recurring attacks, responses can be made quickly using predefined playbooks. TrendAI Vision One has helped to reduce noise from false positives. There have been false positives before, but it was due to the customer not telling us which app they were using. Best practice configurations must be applied properly to avoid such issues. TrendAI Vision One helps customers consolidate the use of security vendors and reduce silos by offering one platform for all product management.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's very stable. I've never experienced downtime for the ASM console or ASM core."
"The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"The behavior-based detection feature is valuable."
"After deploying Traps, we saw the performance of the network improve by 65 to 70 percent."
"The most valuable for us is the correlation feature."
"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"Cortex is the best tool for endpoint detection, with playbooks that automate and gather endpoint logs, block malicious processes, and update incident tickets, showcasing end-to-end processes with automation in investigation and reducing the analysis workflow."
"It is very easy to collect and handle data in ExtraHop Reveal(X) Cloud. Integration with Big Data is also easy. Many of our customers integrate it with Big Data platforms like Splunk or Elastic. It is also easy to handle and easy to understand."
"It stands out for its intuitive and efficient user interface, robust detection capabilities with minimal false positives, and the ability to handle encrypted traffic, making it a valuable asset for network security and management."
"It is scalable."
"Their technical support is more effective and of better quality than other competitors."
"The scalability is very good, and once again, being based on the cloud makes it very scalable."
"The workbench alerts provide valuable insights into attack chains and relevant information, while Observer techniques give a comprehensive overview of ongoing activities."
"Trend Vision One has reduced the time we spend detecting and responding to threats; I'd say we're 80% faster than before."
"TrendAI Vision One allows us to monitor attacks in real time, which is a significant benefit, and we can quickly see where the attack is coming from."
"Since the alerts are high fidelity and TrendAI Vision One requires less overall from the security analyst perspective, it reduces cyber risk effectively."
"I can prevent my environment from different types of attacks based on what I see in the Vision One console."
"It is a stable product. It works very well."
"Trend Vision One provides centralized visibility and management across protection layers, which is crucial for compliance."
 

Cons

"When it comes to core analysis and security analysis, Cortex needs to provide more information."
"Being able to filter the events to see those that are related to the actual alert would save time spent by the engineer."
"Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
"The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"I have run into some detection issues with Cortex XDR. It needs to be better at detection of internal attacks."
"Palo Alto Networks Cortex XDR does not detect malicious activity like in other anti-virus solutions like Trend Micro and Windows with Cisco."
"We would also like to have advanced tech protection and email scanning."
"They can include integration with SAP. Currently, no vendor provides network performance monitoring in the SAP market. It is a very big market. We have around 400 customers for SAP in Korea. In the USA, there are more than 10,000 customers."
"There needs to be more support."
"Their professional service can be improved."
"A drawback includes bucket storage limitations for payload data, necessitating timely extraction for thorough investigations."
"Integration with other tools and deploying in hybrid environments need improvement."
"They should increase their potential for third-party integrations."
"Areas that need improvement in TrendAI Vision One include the AI-based mechanism, AI-based detections, and AI-based autonomous detections, which are currently lacking."
"The product needs to have a lot more maturity, and they need to improve the overall technical support framework for getting the value out of XDR."
"It would be better if it were more user-friendly. It would also be better if the implementation were more straightforward."
"They have a DLP module in Tredn Moicros and they need to enhance its capabilities."
"In comparison to Trellix, one disadvantage of Trend Micro is the DLP feature. Trend Micro has a light DLP, while Trellix offers a perfect DLP."
"The automation capabilities on-premises could be improved, as we currently have to manually activate servers and push policies."
 

Pricing and Cost Advice

"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"I don't recall what the cost was, but it wasn't really that expensive."
"Its pricing is kind of in line with its competitors and everybody else out there."
"It has reasonable pricing for the use cases it provides to the company."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"The pricing is a little high. It is per user per year."
"I don't have any issues with the pricing. We are satisfied with the price."
"The price was fine."
"When compared to other solutions, it aligns with the market average, indicating a competitive pricing level."
"The pricing of the solution is okay. There is a need for me to look into the new pricing plan introduced by the solution recently."
"It is definitely not cheap. I do believe you get what you pay for to some degree. It is cost-effective."
"I find it to be a cost-efficient platform."
"The pricing is fair and not on the higher side."
"It would be nice if it was a little bit cheaper, but I think it has a fair price. It is comparable to others in the market."
"The price is reasonable. It's not exorbitant. CrowdStrike and other players are on the higher side."
"Trend Vision One offers a competitive price-to-value ratio."
"Trend Micro XDR is reasonably priced for its value, comparable to other products like VMware Carbon Black."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
893,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
12%
Construction Company
10%
Computer Software Company
7%
Government
7%
Manufacturing Company
10%
Computer Software Company
10%
Comms Service Provider
9%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise20
Large Enterprise49
No data available
By reviewers
Company SizeCount
Small Business55
Midsize Enterprise13
Large Enterprise43
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Trend Micro XDR?
Trend Micro has a different costing Structure than any i have ever seen. The products are purchased with credits, wh...
What needs improvement with Trend Micro XDR?
To provide centralized visibility and management across various protection layers could be better. I would add differ...
What advice do you have for others considering Trend Micro XDR?
When an incident appears in TrendAI Vision One, I open it and on the first page, you get to see the timeline of where...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
ExtraHop Reveal(X) Cloud, Reveal(X) Cloud
Trend Vision One, Trend Micro XDR, Trend Micro XDR for Users, Trend Vision One - XDR for Networks, Trend Micro Vision One
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Wizards of the Coast
Panasonic North America, Decathlon, Fischer Homes, Banijay Benelux, Unigel, DHR Health,
Find out what your peers are saying about ExtraHop Reveal(x) 360 vs. TrendAI Vision One and other solutions. Updated: April 2026.
893,311 professionals have used our research since 2012.