Try our new research platform with insights from 80,000+ expert users

Lookout vs Trellix Endpoint Detection and Response (EDR) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
7th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
108
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Lookout
Ranking in Endpoint Detection and Response (EDR)
51st
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
Threat Intelligence Platforms (TIP) (27th), Mobile Threat Defense (3rd)
Trellix Endpoint Detection ...
Ranking in Endpoint Detection and Response (EDR)
23rd
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
26
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.4%, down from 4.0% compared to the previous year. The mindshare of Lookout is 0.7%, up from 0.4% compared to the previous year. The mindshare of Trellix Endpoint Detection and Response (EDR) is 1.1%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.4%
Trellix Endpoint Detection and Response (EDR)1.1%
Lookout0.7%
Other94.8%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
DB
IT Manager at NHS Trust
Enhanced mobile security with visibility into app and website usage, but installation challenges remain
We use Lookout for mobile devices, such as phones It has reduced our risk around mobile devices. I like the security features and being able to see what apps and websites people are using. There is nothing we have come across that we've desired. We have been using Lookout for one year. The…
Ronald Paz - PeerSpot reviewer
Consulting Systems Engineer at Boomslang Tech
Improved endpoint investigations and response have reduced risk but integration still needs work
I believe that Trellix Endpoint Detection and Response (EDR) can be improved with better integration with other tools such as Cisco, Check Point, and Palo Alto. Cybersecurity professionals need agnostic tools that integrate with all the tools in their network. I think the workflow could be better; it is difficult to translate as simple letters and needs a more intuitive investigation workflow. I chose a six for my rating because I need EDR integration with different tools, tools with an intuitive investigation workflow, advanced native threat hunting queries, and cloud and hybrid visibility expansion. An important point would be noise reduction and alert context enrichment, as some medium-severity alerts may require additional contextual enrichment or automatic correlation with identity risk scores to help prioritize better.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR features advanced threat detection capabilities."
"The tool's use cases are relevant to security."
"Cortex XDR's most valuable feature is its intelligence-based dashboards."
"The product's initial setup phase is very easy."
"Monitoring is most valuable."
"It's very stable. I've never experienced downtime for the ASM console or ASM core."
"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"The initial setup is pretty easy."
"We have not had any issues with bugs or breakdowns."
"The protection offered by the product is the most valuable feature. It detects vulnerabilities or traps on our users' phones and then prompts them to clean up their devices. Tools we used previously would only discover, which required us to gather information on the backend, so Lookout is a welcome upgrade."
"The most valuable features are the antivirus as a whole, the anti-malware, and all of the protection features that scan our enterprise devices."
"The dashboard makes it easier and more effective to analyze data."
"It is a scalable solution and very easy to use."
"It is a stable solution. Stability-wise, I rate the solution a nine out of ten...I rate the solution's technical support team a nine and a half or ten out of ten."
"The product and the services we have are quite good."
"If there is any malicious behavior in the workstation or server, the tool stops or isolates it automatically and generates alerts."
"The product is user-friendly."
"Trellix has done a good job reducing threats."
"This is a stable product."
 

Cons

"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"Product might have some bugs."
"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution."
"Additionally, I think the price is very high, and if it can be adjusted, I believe it will be a very good solution."
"The product's pricing could be better."
"It would be good to have a better way to search for a file within the UI."
"I would like to see them include NDR (Network Detection Response)."
"The initial setup requires a little bit of experience with configuration."
"From the analysis that we've done, they do seem to be maybe a step behind in trying to enter the market with a new solution. But when they do pick up, they do come out with some good products."
"We just submitted an enhancement request reflecting the main area we want to see improvement in; the APIs. Currently, we're able to build dashboards, but it's somewhat backward because we use our MDM API to create them. Lookout should provide API to customers so we can query our data and use it in our cloud, and this is the only outstanding area for improvement with the product right now."
"Trellix does not support Linux and Mac."
"When it comes to some unknown fileless attacks, the tool is not able to detect them properly, making it an area where improvements are required."
"I'd like the tool to become more like an XDR, with one management system and endpoint activation."
"The CPU utilization of the product is quite high compared to its competitors."
"Customer support for Trellix Endpoint Detection and Response (EDR) specifically is not good; it is slow and lacks sufficient engineers to attend to client cases effectively."
"The console has a lot of bugs, and it creates many issues."
"Initially, I was using it on servers, but it consumes a lot of resources on servers."
"The technical support must be improved."
 

Pricing and Cost Advice

"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"Cortex XDR is a costly solution."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"This is an expensive solution."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"The price was fine."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"Lookout is definitely on the lower end when it comes to price point and that seems to be the only differentiator. The technology is in place in this space and it's really about who is coming in at the better price point now."
"The pricing is fair; it's comparable to our previous solution, and we carried out multiple POCs and POVs (proof of value). The product is worth the money we pay for it."
"McAfee MVISION Endpoint Detection and Response is reasonable in terms of cost. It's a tool my company has been using for a few years now. It costs $25,000 to $30,000 for six hundred users."
"On a scale of one to ten, where one is low and ten is high, I rate the solution's pricing an eight out of ten."
"The pricing is always high."
"The price is reasonable."
"The cost is okay, compared to other products."
"Pricing is a problem in South Africa. It could be cheaper here. The rand-to-dollar exchange rate makes it expensive for us. A 25 dollar endpoint cost becomes quite significant when converted to rand."
"Speaking about the price, you must use the product to find the product's cost for you."
"The product’s pricing is reasonable."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
884,797 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
9%
Comms Service Provider
7%
Computer Software Company
15%
Manufacturing Company
10%
Financial Services Firm
9%
Government
7%
Financial Services Firm
12%
Government
10%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise47
By reviewers
Company SizeCount
Small Business2
Large Enterprise5
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise3
Large Enterprise11
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Lookout?
The pricing is a little expensive. We are currently looking at comparisons with other solutions, including Umbrella.
What needs improvement with Lookout?
There is nothing we have come across that we've desired.
What is your primary use case for Lookout?
We use Lookout for mobile devices, such as phones.
What is your experience regarding pricing and costs for McAfee MVISION Endpoint Detection and Response?
I pay for what we get. But the service level from my partner company is not enough to overcome a complex case.
What needs improvement with McAfee MVISION Endpoint Detection and Response?
I believe this is a product in evolution. I do not think it is a final tool to conduct forensics or information foren...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CipherCloud
McAfee MVISION EDR, MVISION EDR, MVISION Endpoint Detection and Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Sutherland Global Services
Find out what your peers are saying about Lookout vs. Trellix Endpoint Detection and Response (EDR) and other solutions. Updated: March 2026.
884,797 professionals have used our research since 2012.