Our primary use case is anti-malware and anti-exploit.
Security Engineer at U.S. Acute Care Solutions
We've had a significant increase in blocking with a decrease in false positives
Pros and Cons
- "We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
- "The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
- "They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else."
What is our primary use case?
How has it helped my organization?
Traditional anti-virus is signature-based, whereas Traps is behavior-based. Therefore, it doesn't necessarily whitelist things, it looks for anything with bad behavior. Thus, we've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for.
What is most valuable?
The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past.
What needs improvement?
Going from version 4 to version 5, they had a major change in their user interface. Version 5 is now all cloud managed, while it has a very intuitive, useful interface, it doesn't have all the features that were in the version 4 interface. For example, we lost being able to automatically trigger upgrades, like creating manual groups to upgrade with. It doesn't currently have the ability to use the Active Directory to create groups.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It's fairly stable. They do have bugs which come up every once in a while, but they're usually good about getting them taken care of within a release.
What do I think about the scalability of the solution?
It is definitely scalable.
Primarily, it is just being used by myself. The help desk also uses it. There are probably a total of around ten users.
We've deployed it to about 1500 endpoints so far. There is a possibility that we may expand our usage, but not in the foreseeable future. We are at pretty much at 100 percent deployment at this point.
How are customer service and support?
I would describe Palo Alto's technical support as audio waterboarding. They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else.
Which solution did I use previously and why did I switch?
We were previously using Sophos for antivirus, and are still using Sophos for antivirus, but we're using Traps to augment it.
How was the initial setup?
The initial setup was pretty straightforward on version 4, but on version 5, it is almost idiot-proof.
The initial deployment of getting the servers and everything up took about a week, but getting everything deployed was somewhere closer to six weeks.
What about the implementation team?
We implemented it in-house. We incrementally did some systems to make sure that it wouldn't block anything that it shouldn't. After that, we used Active Directory to push it to everything else.
Very little staff is required for deployment and maintenance, as Traps is self-maintaining.
What was our ROI?
I feel that we have seen ROI. There have been a number of blocked, bad files that could have gotten through, but were stopped by Traps.
What's my experience with pricing, setup cost, and licensing?
The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic. So, if you have 1100 computers today, you can license that. Therefore, as long as you're below your licensing cap, you're fine.
Which other solutions did I evaluate?
We looked at Palo Alto vs Sophos, which has a anti-malware system called Intercept X, but it did quite literally nothing. We thought about Symantec, but we didn't end up testing them against Traps.
What other advice do I have?
The implementation is fairly straightforward and easy. With version 5, everything is now on the cloud. It is easy to work with and use. I would use mobile device management (MDM) or Active Directory (AD) to push the file everywhere when installing it, as it will auto go from there. The management is pretty low. Thus, it will be set it, and for the most part, you can forget it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Head of Network and Communication Department at a program development consultancy with 10,001+ employees
The level of security I get for my endpoints and servers is extremely valuable.
What is most valuable?
The level of security I get for my endpoints and servers is extremely valuable.
How has it helped my organization?
No signature updates of the AV needed, so no old signatures. No patching, very little operational effort needed.
What needs improvement?
Performance at the endpoint is much better than with the old AV.
No signature updates needed.
Stops the attack before it is executed.
For how long have I used the solution?
Two years.
What was my experience with deployment of the solution?
No.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
Perfect.
Technical Support:Real experts.
Which solution did I use previously and why did I switch?
Yes. We switched because the footprint was heavy, the protection rate decreases and the operational costs (incidence response) were high.
How was the initial setup?
Yes, it took one hour to install the back end and the rollout was done by software deployment. Project lasted four weeks .
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
Ask your local dealer.
Which other solutions did I evaluate?
Yes.
What other advice do I have?
If you are already a Palo Alto Networks Firewall customer you can have perfect Integration between your clients/servers and your firewalls. Automated response without supporting and APIs.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Head Of Sales at Cascade Solutions
A stable solution for security with good support
Pros and Cons
- "The tool's use cases are relevant to security."
- "The tool needs to be improved in terms of integration and interface."
What is our primary use case?
The tool's use cases are relevant to security.
What needs improvement?
The tool needs to be improved in terms of integration and interface.
For how long have I used the solution?
I have been working with the solution for five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I would rate the product's scalability a nine out of ten.
How are customer service and support?
The product's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is easy. The solution's deployment took five days to complete.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive. It's pricing is on a yearly-basis.
What other advice do I have?
I would rate the tool a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network and security engineer at a tech services company with 11-50 employees
Easy to set up and won't slow down your system but is expensive
Pros and Cons
- "It'll not slow down your system when compared to others."
- "We would also like to have advanced tech protection and email scanning."
What is our primary use case?
I'm testing the product right now. I use the solution for endpoint security.
What is most valuable?
Everything is fine.
It'll not slow down your system when compared to others.
The initial setup is easy.
What needs improvement?
I'd like the solution to provide URL filtering and web-based prevention. We'd like to block web pages at a high level.
We would also like to have advanced tech protection and email scanning.
For how long have I used the solution?
I've been using the solution for a year.
What do I think about the stability of the solution?
The product is very stable and the performance is good. It doesn't slow down the systems it runs on. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale well.
More than 100 people are using the solution right now.
How are customer service and support?
We've never needed the assistance of technical support just yet.
Which solution did I use previously and why did I switch?
I've also used McAfee MVISION Endpoint.
I'm testing them both and finding the advantages and disadvantages between them.
How was the initial setup?
The solution is very easy to set up.
What's my experience with pricing, setup cost, and licensing?
You do have to pay for a license in order to use a solution. It's expensive.
What other advice do I have?
We're a reseller.
We are using the latest, most up-to-date version, of the product.
I would recommend using it with another protection layer. Cortex should provide an additional layer of security apart from this. You might have to integrate with other vendors also.
If you are looking to deploy a security solution as a whole, this is a good option.
I'd rate the solution seven out of ten. If we had more advanced security features, I'd rate it higher.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
ISEC Unit Manager at a tech services company with 11-50 employees
We can manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus
Pros and Cons
- "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
- "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
What is our primary use case?
We have deployed Cortex XDR for a couple of clients in manufacturing.
What is most valuable?
Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus.
What needs improvement?
The dashboard could be more user-friendly.
For how long have I used the solution?
I've been using Cortex XDR for two years.
What do I think about the stability of the solution?
Cortex XDR is stable enough.
What do I think about the scalability of the solution?
Cortex's scalability is good. We have about 200 users on it at the moment.
How are customer service and support?
Palo Alto support is great.
How was the initial setup?
Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied. We need two people to deploy and maintain the solution.
What's my experience with pricing, setup cost, and licensing?
Our clients pay for the license every year. It's just a standard fee with no additional costs.
What other advice do I have?
I rate Cortex XDR eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Pre-sales engineer at a tech services company with 51-200 employees
Best support and good interface, price, and security
Pros and Cons
- "Its interface and pricing are most valuable. It is better than other vendors in terms of security."
- "It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
What is our primary use case?
We are using it for a banking client.
What is most valuable?
Its interface and pricing are most valuable. It is better than other vendors in terms of security.
What needs improvement?
It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It is very stable. I wouldn't recommend the latest version. Being a new version, it would have bugs, which is similar to the new versions of other products.
What do I think about the scalability of the solution?
In Peru, we have approximately 20,000 users. The banking client doesn't have any plans to expand the usage. We might increase its usage by 200 to 500 with new clients.
How are customer service and technical support?
Technical support of Palo Alto is the best.
How was the initial setup?
It is very easy to deploy. The deployment is quick. The deployment of the management console takes just two hours, but the deployment of the agent takes approximately a month.
We have five to eight engineers for deployment and maintenance.
What other advice do I have?
I would rate Cortex XDR a nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Ingeniero de Soporte at a tech services company with 11-50 employees
Stable, flexible, and easy to deploy
Pros and Cons
- "They did what they said. This solution could apply to any scenario."
- "I would like to see better protection, specifically to protect email applications."
What is our primary use case?
We deploy this solution in Universities and banks because it's private. Our company is a private company.
What is most valuable?
They did what they said. This solution could apply to any scenario.
What needs improvement?
The configuration could be simplified.
I would like to see better protection, specifically to protect email applications.
What do I think about the stability of the solution?
This solution is stable.
How was the initial setup?
It's easy to deploy
You need the experience to configure the equipment, but the configuration is easy to deploy.
What's my experience with pricing, setup cost, and licensing?
The price could be improved. Our customers have expressed that the price is high. When compared with other services, it's more expensive, but it's not too high.
What other advice do I have?
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Services Director at ITVikings
Stable platform with good technical support services
Pros and Cons
- "We can visualize and control the activities in the environment from anywhere."
- "The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."
What is our primary use case?
We use the product to monitor and control all the systems. It helps us understand user behavior.
How has it helped my organization?
The product gives full visibility and control of the endpoints in the environment. The users and the employees can protect their systems by investigating files for incidents.
What is most valuable?
The platform's most valuable feature is being a cloud-based solution. We can visualize and control the activities in the environment from anywhere.
What needs improvement?
The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced.
For how long have I used the solution?
We have been using Cortex XDR by Palo Alto Networks for two months.
What do I think about the stability of the solution?
The platform is stable. As far as you have the internet, the product is secure.
What do I think about the scalability of the solution?
The platform is scalable.
How are customer service and support?
They have a good technical support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. It is easy to maintain as well.
What about the implementation team?
I implemented the product myself.
What other advice do I have?
I recommend Cortex XDR by Palo Alto Networks and rate it an eight out of ten. It is a good solution for the commercial sector as they can work on the cloud. I advise others to refer to user guides for understanding the processes easily.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Microsoft Sentinel
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Fortinet FortiClient
HP Wolf Security
Elastic Security
Trellix Endpoint Security Platform
Symantec Endpoint Security
Kaspersky Endpoint Security for Business
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
Hi There, We have a customer who wants to have Cortex & Microsoft solutions on all their Windows 10 endpoints. So here is my query - Can Cortex XDR co-exist with Microsoft Defender for Endpoint on same endpoints and both operate optimally and independently of each other? Thanks in advance! Dr. Praveen Talwar (Praveen.Talwar@Spark.co.nz)
Hello @Praveen Talwar, please note that you can also create a new question from your Home feed: https://www.itcentralstation.c... . This way, it will get higher visibility (it just should not include any marketing or sales content). I hope this is helpful.