No more typing reviews! Try our Samantha, our new voice AI agent.
Security Engineer at U.S. Acute Care Solutions
Real User
Jan 13, 2019
We've had a significant increase in blocking with a decrease in false positives
Pros and Cons
  • "We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
  • "The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
  • "The anti-exploit is impenetrable."
  • "They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else."
  • "They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone."

What is our primary use case?

Our primary use case is anti-malware and anti-exploit.

How has it helped my organization?

Traditional anti-virus is signature-based, whereas Traps is behavior-based. Therefore, it doesn't necessarily whitelist things, it looks for anything with bad behavior. Thus, we've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for.

What is most valuable?

The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past.

What needs improvement?

Going from version 4 to version 5, they had a major change in their user interface. Version 5 is now all cloud managed, while it has a very intuitive, useful interface, it doesn't have all the features that were in the version 4 interface. For example, we lost being able to automatically trigger upgrades, like creating manual groups to upgrade with. It doesn't currently have the ability to use the Active Directory to create groups. 

Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,298 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's fairly stable. They do have bugs which come up every once in a while, but they're usually good about getting them taken care of within a release.

What do I think about the scalability of the solution?

It is definitely scalable.

Primarily, it is just being used by myself. The help desk also uses it. There are probably a total of around ten users.

We've deployed it to about 1500 endpoints so far. There is a possibility that we may expand our usage, but not in the foreseeable future. We are at pretty much at 100 percent deployment at this point.

How are customer service and support?

I would describe Palo Alto's technical support as audio waterboarding. They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else.

Which solution did I use previously and why did I switch?

We were previously using Sophos for antivirus, and are still using Sophos for antivirus, but we're using Traps to augment it.

How was the initial setup?

The initial setup was pretty straightforward on version 4, but on version 5, it is almost idiot-proof.

The initial deployment of getting the servers and everything up took about a week, but getting everything deployed was somewhere closer to six weeks.

What about the implementation team?

We implemented it in-house. We incrementally did some systems to make sure that it wouldn't block anything that it shouldn't. After that, we used Active Directory to push it to everything else.

Very little staff is required for deployment and maintenance, as Traps is self-maintaining.

What was our ROI?

I feel that we have seen ROI. There have been a number of blocked, bad files that could have gotten through, but were stopped by Traps.

What's my experience with pricing, setup cost, and licensing?

The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic. So, if you have 1100 computers today, you can license that. Therefore, as long as you're below your licensing cap, you're fine.

Which other solutions did I evaluate?

We looked at Palo Alto vs Sophos, which has a anti-malware system called Intercept X, but it did quite literally nothing. We thought about Symantec, but we didn't end up testing them against Traps.

What other advice do I have?

The implementation is fairly straightforward and easy. With version 5, everything is now on the cloud. It is easy to work with and use. I would use mobile device management (MDM) or Active Directory (AD) to push the file everywhere when installing it, as it will auto go from there. The management is pretty low. Thus, it will be set it, and for the most part, you can forget it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
ManagerO5d72 - PeerSpot reviewer
Manager of InfoSec at Jo-Ann Stores
Real User
Dec 24, 2018
We have not had any malware successfully execute on an endpoint since deploying Traps.
Pros and Cons
  • "Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
  • "Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
  • "There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
  • "There is a severe gap in functionality between Windows, Linux, and Mac versions."

What is our primary use case?

How has it helped my organization?

Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place. We have not had any malware successfully execute on an endpoint since deploying Traps.

What is most valuable?

Wildfire, advanced detection capabilities, and whitelist/blacklist features. These features have provided us an easy way to lock down our systems to prevent execution of unknown code and scripts and to prevent launching of code from end user writable directories.

What needs improvement?

The application whitelisting/blacklisting feature is based purely on path and filenames. Changing a filename can bypass it easily. The uninstall admin password for the client is passed in clear text during install. 

There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration. This is ridiculous for an enterprise product. 

Traps 5.0 does not integrate with Palo Alto's Panorama product, which was a big selling point of Traps 4.0. Traps 5.0 has no ability to send an email to alert of detections. Instead customers have to jump through hoops to use Palo Alto's log management service to forward logs into a 3rd party SIEM and then build your alerts from there. No EDR functionality, though this is supposedly coming.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Mostly positive. We've had some episodes early on where upgrades caused some issues with the backend database, but that seems to have cleared up. This issue would not impact the Traps 5.0 users as it is SaaS based.

What do I think about the scalability of the solution?

This software exists on every workstation and server in our company with ~10,000 people using the solution. For on-prem, we run 3 nodes and it handles the load just fine. We could always add more nodes if necessary. For the SaaS solution, that is all on Palo Alto's side.

How was the initial setup?

Setup was pretty straight forward. The product is very granular and customers can turn on features as they are ready/comfortable in order to keep the deployment simple. For organizations with a good understanding of their infrastructure, deployment should be pretty simple.

What about the implementation team?

We deployed Traps ourselves. We went big bang and deployed all features at once. We had a strong understanding of our systems and were able to provide whitelisting settings up front that made sense. There was a bit of post-deployment work to resolve things that were missed, but all things considered the deployment strategy went smoothly and was the right call.

What was our ROI?

For an endpoint security service, that is hard to state. We have not seen a malware infection since deployment.

What's my experience with pricing, setup cost, and licensing?

I feel it is fairly priced.

Which other solutions did I evaluate?

We evaluated 

What other advice do I have?

I think Traps has the best mix of features by price in the industry. It is not flawless by any means, but Palo Alto seems committed to it and are improving it. Traps 5.0 is promising, though they have a ways to go before I'd be willing to implement it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,298 professionals have used our research since 2012.
PeerSpot user
Head of Network and Communication Department at a program development consultancy with 10,001+ employees
Vendor
Jun 25, 2017
The level of security I get for my endpoints and servers is extremely valuable.
Pros and Cons
  • "The level of security I get for my endpoints and servers is extremely valuable."

    What is most valuable?

    The level of security I get for my endpoints and servers is extremely valuable.

    How has it helped my organization?

    No signature updates of the AV needed, so no old signatures. No patching, very little operational effort needed.

    What needs improvement?

    Performance at the endpoint is much better than with the old AV.

    No signature updates needed.

    Stops the attack before it is executed.

    For how long have I used the solution?

    Two years.

    What was my experience with deployment of the solution?

    No.

    What do I think about the stability of the solution?

    No.

    What do I think about the scalability of the solution?

    No.

    How are customer service and technical support?

    Customer Service:

    Perfect.

    Technical Support:

    Real experts.

    Which solution did I use previously and why did I switch?

    Yes. We switched because the footprint was heavy, the protection rate decreases and the operational costs (incidence response) were high.

    How was the initial setup?

    Yes, it took one hour to install the back end and the rollout was done by software deployment. Project lasted four weeks .

    What about the implementation team?

    In-house.

    What's my experience with pricing, setup cost, and licensing?

    Ask your local dealer.

    Which other solutions did I evaluate?

    Yes.

    What other advice do I have?

    If you are already a Palo Alto Networks Firewall customer you can have perfect Integration between your clients/servers and your firewalls. Automated response without supporting and APIs.

    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Cybersecurity Services Director at ITVikings
    Reseller
    Dec 2, 2023
    Stable platform with good technical support services
    Pros and Cons
    • "We can visualize and control the activities in the environment from anywhere."
    • "The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."

    What is our primary use case?

    We use the product to monitor and control all the systems. It helps us understand user behavior.

    How has it helped my organization?

    The product gives full visibility and control of the endpoints in the environment. The users and the employees can protect their systems by investigating files for incidents.

    What is most valuable?

    The platform's most valuable feature is being a cloud-based solution. We can visualize and control the activities in the environment from anywhere.

    What needs improvement?

    The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced.

    For how long have I used the solution?

    We have been using Cortex XDR by Palo Alto Networks for two months.

    What do I think about the stability of the solution?

    The platform is stable. As far as you have the internet, the product is secure.

    What do I think about the scalability of the solution?

    The platform is scalable.

    How are customer service and support?

    They have a good technical support team.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup is straightforward. It is easy to maintain as well.

    What about the implementation team?

    I implemented the product myself.

    What other advice do I have?

    I recommend Cortex XDR by Palo Alto Networks and rate it an eight out of ten. It is a good solution for the commercial sector as they can work on the cloud. I advise others to refer to user guides for understanding the processes easily.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    PeerSpot user
    Lissette Acurio - PeerSpot reviewer
    Solution Engineer at Secure Soft Corporation
    Reseller
    Aug 24, 2023
    An easy-to-use product with an intuitive dashboard that enables users to navigate easily
    Pros and Cons
    • "The product has an intuitive dashboard."
    • "It is a complex solution to implement."

    What is our primary use case?

    The solution is like a next-level EDR. It can collect information from other solutions to have a global view of the risks and vulnerabilities.

    What is most valuable?

    The product has an intuitive dashboard. The first time a client interacts with the solution, they do not face any problems. It is easy for the client to navigate through the tool.

    What needs improvement?

    It is a complex solution to implement.

    For how long have I used the solution?

    My organization sells the solution.

    How are customer service and support?

    I did not have any problem with support.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I believe the implementation is not very easy, but it is not very complex either.

    What's my experience with pricing, setup cost, and licensing?

    The price of the product is not very economical. It is suitable for clients that have a lot of money to invest.

    What other advice do I have?

    Customers often ask for proof of concept. People wanting to use the solution should analyze the different tools that can be integrated with the product. At first, clients only consider it an EDR, but later, they might realize that the tool does not have all the capabilities they need. Overall, I rate the solution an eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    PeerSpot user
    Head Of Sales at Cascade Solutions
    Reseller
    May 18, 2023
    A stable solution for security with good support
    Pros and Cons
    • "The tool's use cases are relevant to security."
    • "The tool needs to be improved in terms of integration and interface."

    What is our primary use case?

    The tool's use cases are relevant to security. 

    What needs improvement?

    The tool needs to be improved in terms of integration and interface. 

    For how long have I used the solution?

    I have been working with the solution for five years. 

    What do I think about the stability of the solution?

    The solution is stable. 

    What do I think about the scalability of the solution?

    I would rate the product's scalability a nine out of ten. 

    How are customer service and support?

    The product's technical support is good. 

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The tool's setup is easy. The solution's deployment took five days to complete. 

    What's my experience with pricing, setup cost, and licensing?

    The solution is expensive. It's pricing is on a yearly-basis. 

    What other advice do I have?

    I would rate the tool a seven out of ten. 

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    PeerSpot user
    reviewer2171169 - PeerSpot reviewer
    Senior Business Development Manager at a tech services company with 201-500 employees
    Real User
    May 8, 2023
    Efficiently detects any issues
    Pros and Cons
    • "This software helps us understand any issues that may arise when someone is not at work."
    • "Dashboards do not allow everyone to see what's happening."

    What is our primary use case?

    It is used as a device that can detect any issues and changes when people are not at work. In one case, we use it when someone is not at work or has already used their allotted time off. This helps us understand any issues that may arise when someone is not at work, which could lead to changes in the way we work.

    What needs improvement?

    There are many areas that could use improvement. One thing that is important to keep in mind is that times change, and we need to be adaptable to what happens. Ultimately, we want to see positive results and improvements.

    In the next release, I would add dashboards that allow everyone to see what's happening, not just the security team. Users can view the data and see what's happening. Also, I think the Data Lake from Cortex XDR should be public, not private.

    For how long have I used the solution?

    I have been using the solution for two years.

    How was the initial setup?

    The initial setup was easy.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is cheap.

    What other advice do I have?

    I rate it a nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Information information analyst at Seeton
    Real User
    Apr 14, 2023
    It's a simple platform that's easy for administrators and users
    Pros and Cons
    • "Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features."
    • "The playbooks could be improved to include more functionalities or actions."

    What is most valuable?

    Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features. 

    What needs improvement?

    The playbooks could be improved to include more functionalities or actions. 

    For how long have I used the solution?

    I have been using Cortex XDR for a few months.

    What do I think about the stability of the solution?

    Cortex XDR is highly stable. 

    What do I think about the scalability of the solution?

    Cortex XDR is scalable. 

    Which solution did I use previously and why did I switch?

    We previously used McAfee, but we switched because of our customer. We checked Gartner's to learn about each vendor and solution and consulted with the customer about the features they needed. 

    How was the initial setup?

    Cortex XDR is a cloud-based solution, so the deployment is straightforward. They give you your credentials to access the platform and you change some settings to customize it. 

    What other advice do I have?

    I rate Cortex XDR by Palo Alto nine out of 10. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2026
    Buyer's Guide
    Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.