Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Palo Alto Networks Cortex XDR has drastically reduced endpoint attack surfaces through advanced detection capabilities and sandboxing.
The multi-layered approach provides peace of mind by stopping exploits, ransomware, worms, and viruses from compromising endpoints.
It offers high stability and scalability, improving network performance significantly after deployment.
Palo Alto Networks Cortex XDR's automation and playbooks help reduce the analysis workflow and quickly detect and block malicious activities.
Its integration with AI provides behavioral detection, presenting a comprehensive 360-degree view of security posture by ingesting logs from multiple resources.

CONS

Cortex XDR by Palo Alto Networks has significant functionality differences across Windows, Linux, and Mac versions.
Support from Palo Alto Networks is difficult to access and often unhelpful, with slow response times and lack of knowledgeable assistance.
Cortex XDR by Palo Alto Networks suffers from a large number of false positives, which complicates threat management.
The product is complex to implement, and its pricing is considered high compared to competitors.
There is poor integration with third-party solutions and limited ability to customize reports.
 

Cortex XDR by Palo Alto Networks Pros review quotes

ManagerO5d72 - PeerSpot reviewer
Manager of InfoSec at Jo-Ann Stores
Dec 12, 2018
Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place.
RH
Security Engineer at U.S. Acute Care Solutions
Jan 10, 2019
We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for.
LT
Lead IT Security Analyst at a mining and metals company with 1,001-5,000 employees
Jan 17, 2019
The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind.
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
OS
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Feb 7, 2019
If the user leaves our premises or network, Palo Alto Traps will still be on that endpoint and will still apply our policies.
SH
Manager Information Technology at Avendus
Feb 7, 2019
It blocks malicious files. It prevents attacks. It doesn't require many updates, it's a very light application.
AK
Information Technology Manager at a hospitality company with 10,001+ employees
Feb 7, 2019
After deploying Traps, we saw the performance of the network improve by 65 to 70 percent.
Netw9886 - PeerSpot reviewer
Network Manager of Cyber Defence at a government with 1,001-5,000 employees
Feb 11, 2019
The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical.
RR
Cybersecurity Engineer at GFR Media
Oct 7, 2019
The one feature of Palo Alto Networks Traps that our organization finds most valuable is the App ID service.
Traps677 - PeerSpot reviewer
IT-Administration at a mining and metals company with 51-200 employees
Jun 24, 2019
We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us.
it_user1009236 - PeerSpot reviewer
SOC Analyst at a tech services company with 201-500 employees
Jul 9, 2019
The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week.
 

Cortex XDR by Palo Alto Networks Cons review quotes

ManagerO5d72 - PeerSpot reviewer
Manager of InfoSec at Jo-Ann Stores
Dec 12, 2018
There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration.
RH
Security Engineer at U.S. Acute Care Solutions
Jan 10, 2019
They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else.
LT
Lead IT Security Analyst at a mining and metals company with 1,001-5,000 employees
Jan 17, 2019
Previously, the endpoint would leave the environment, not being on our VPN, essentially unable to interact with the server to upload files. It was unable to retrieve new file verdicts. It was using a thing called "local analysis" to determine if something was a malicious file or not. There was no dynamic analysis.
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
OS
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Feb 7, 2019
Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere.
SH
Manager Information Technology at Avendus
Feb 7, 2019
Managing the product should be easier.
AK
Information Technology Manager at a hospitality company with 10,001+ employees
Feb 7, 2019
There are some default policies which sometimes affect our applications and cause them to run around. In the hotel industry, we use a different type of data versus Oracle and SQL. By default, there are some policies which stop us from running properly. Because of this, the support level is also not that strong. We have to wait to get a results.
Netw9886 - PeerSpot reviewer
Network Manager of Cyber Defence at a government with 1,001-5,000 employees
Feb 11, 2019
There are some false positives. What our guys would have liked is that it would have been easier to manipulate as soon as they found a false positive that they knew was a false positive. How to do so was not obvious. Some people complained about it. The interface, the ESM, is not user-friendly.
RR
Cybersecurity Engineer at GFR Media
Oct 7, 2019
It automatically detects security issues. It should be able to protect our network devices while operating autonomously.
Traps677 - PeerSpot reviewer
IT-Administration at a mining and metals company with 51-200 employees
Jun 24, 2019
Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats.
it_user1009236 - PeerSpot reviewer
SOC Analyst at a tech services company with 201-500 employees
Jul 9, 2019
The solution needs better reports. I think they should let the customer go in and customize the reports.