No more typing reviews! Try our Samantha, our new voice AI agent.

Kaspersky Next XDR Expert vs Rapid7 InsightIDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Kaspersky Next XDR Expert
Ranking in Endpoint Detection and Response (EDR)
36th
Ranking in Extended Detection and Response (XDR)
28th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
19
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
34th
Ranking in Extended Detection and Response (XDR)
19th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (4th)
 

Mindshare comparison

As of August 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.7%, down from 3.8% compared to the previous year. The mindshare of Kaspersky Next XDR Expert is 1.0%, down from 1.7% compared to the previous year. The mindshare of Rapid7 InsightIDR is 1.3%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.7%
Rapid7 InsightIDR1.3%
Kaspersky Next XDR Expert1.0%
Other94.0%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Manikumar David - PeerSpot reviewer
IT Manager at R K Khanna and Associates
Experienced weak security checks and increased system load with limited control
Kaspersky Endpoint Detection and Response is not up to the mark compared to what I have seen from earlier products. I was using CrowdStrike, and Kaspersky Endpoint Detection and Response is not up to the mark compared to CrowdStrike and other products. Kaspersky Endpoint Detection and Response sometimes seems to allow certain files which should not be allowed on its own. I trust Kaspersky Endpoint Detection and Response to check the files, but I cannot sit and check all the files that are coming in. Kaspersky Endpoint Detection and Response has its own weaknesses. Kaspersky Endpoint Detection and Response slows the system slightly. It uses more resources than what CrowdStrike does. When any attack happens or something is happening with other products I am using, Kaspersky Endpoint Detection and Response stops certain things. However, it does not take me to the file, and it is not user-friendly.
Prajwal Chougale - PeerSpot reviewer
System Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The interface is easy to use and it is more up to date than our previous solution."
"This software helps us understand any issues that may arise when someone is not at work."
"Cortex is the best tool for endpoint detection, and I have used it to verify hashes or domains to identify malicious activity, trigger playbooks that automate and gather endpoint logs, block malicious processes, and update incident tickets, showcasing end-to-end processes with automation in investigation and reducing the analysis workflow."
"I can highlight that we have not faced any security incidents with Cortex XDR by Palo Alto Networks, and even though our environment is quite dynamic, we have not faced any security incident with Cortex XDR by Palo Alto Networks until now."
"Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"The anti-exploit is impenetrable."
"It is a simple platform to use."
"I do customize the policies to determine what to do and what not to do."
"One of the most valuable aspects of Endpoint Detection and Response (EDR) solutions is their ability to detect and respond to spam and viruses in their early stages."
"We have a concept of working from home. Most endpoints are not in the domain. It is our first line of defense. While we had Kaspersky deployed, it gave good insight into the upcoming challenge or threat."
"Stability-wise, I rate the solution a ten out of ten."
"It is a secure solution with a lot of IT management features."
"The tool's performance and prevention are amazing."
"Kaspersky EDR is far superior to other products. It gives detailed information about malware, geolocation, and more. Also, the agent itself is very lightweight compared to other products. The packages and updates were quite small in size, just a few KBs."
"One of the good features is the provider's Faulting capability. If any of our systems detect malware, we can check the behavior of the malware by sending it to Kaspersky's sandbox environment. This helps us assess how destructive the malware is. After analyzing it, we can create use cases and protection measures based on that behavior. So, this is the best feature of Kaspersky."
"I rate Rapid7 nine out of 10 for affordability"
"It gives all the advantages of a SIEM, however, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts."
"The platform offers unlimited storage and agent-based solutions."
"Previously, when something happened, such as when a hacker was attacking one of our customers, we were always behind, or we did not know that we were hacked until the ransomware started, but with the Rapid7 solution, at every step, we could online see what a person was doing, and we could prevent ransomware."
"The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
"We were able to identify criminals attempting to login from China and put a stop on their IP locations."
"Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling."
"The solution's initial setup is easy."
 

Cons

"When it comes to malware files, it should be a little quick because, at times, it would give a wrong result in the sense of what it might be on malware, even if it still might be a normal one."
"There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state."
"I have seen lagging with Cortex XDR by Palo Alto Networks. There was one time when we faced a threat actor trying to gain access to our system. When our team utilized the tool, we were all on the same dashboard and we faced a lag issue at that time of around five minutes, which was quite significant."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"It'll help if customization was easier."
"Cortex XDR by Palo Alto Networks is a very good product, but financially, it is very expensive, so the company should look into that area."
"The encryption is not up to the mark."
"This is a very costly product."
"Kaspersky EDR could be improved by adding network detection capabilities to enhance convenience and security."
"Incorporating an AI protection tool with the capability to detect and prevent zero-day threats, particularly those with a five-star rating in terms of severity would be beneficial."
"The product does not detect zero-day threats."
"Kaspersky Endpoint Detection and Response lacks configuration options."
"There is room for improvement in the support."
"Enhancing user-friendliness should be a priority."
"One of the main areas where the tool could improve is its integration capabilities. For example, I find it challenging to integrate it with other solutions. It would be helpful if the tool could make it more open to integration with other tools."
"The main issue was compatibility with the cloud itself. The CPU usage immediately spiked, causing the machines to hang and sometimes even forcing server or computer restarts."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"The main problem lies in the processes within the client's operating systems."
"The product allows us to make only 30 custom rules."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in."
"Lacks a mobile application."
"Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already."
"The interface for doing investigation needs to be enhanced with minor improvements that would make it more useful."
 

Pricing and Cost Advice

"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"The price is on the higher side, but it's okay."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"Our customers have expressed that the price is high."
"The pricing is a little high. It is per user per year."
"The tool's price is moderate."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"The tool's pricing was high during the last renewal."
"The tool's pricing is reasonable."
"I rate the solution's pricing model a seven on a scale of one to ten, where one is cheap, and ten is expensive."
"I was satisfied with the pricing of Kaspersky."
"It is cost-effective in terms of services and features compared to other more expensive EDR solutions like CrowdStrike and Trend Micro."
"The pricing falls within the average range."
"I rate the product price a five on a scale of one to ten, where one is low price and ten is high price."
"Yearly payments are to be made toward the licensing costs of the solution."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"The pricing and licensing are competitive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"It is more reasonably priced than other vendors."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Rapid7 InsightIDR is priced very well and is cost-effective."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Comms Service Provider
10%
Construction Company
10%
Financial Services Firm
9%
Outsourcing Company
8%
Manufacturing Company
9%
Financial Services Firm
9%
Comms Service Provider
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Kaspersky Endpoint Detection and Response?
Kaspersky Endpoint Detection and Response is not up to the mark compared to what I have seen from earlier products. I...
What advice do you have for others considering Kaspersky Endpoint Detection and Response?
It seems okay. CrowdStrike was not heavy on my network or usage. I would rate this product an 8.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Kaspersky Next XDR Expert vs. Rapid7 InsightIDR and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.