Cortex Xpanse is usually used for security from clients.
Cortex Xpanse offers comprehensive security by identifying trojans, malware, and unknown exposed assets while providing digital brand protection and monitoring, benefiting organizations of all sizes.


| Product | Mindshare (%) |
|---|---|
| Cortex Xpanse | 2.8% |
| CrowdStrike Falcon | 6.0% |
| Darktrace | 4.3% |
| Other | 86.9% |
Cortex Xpanse provides robust threat detection and management with features like real-time reporting and asset discovery. Its antivirus and firewall enhance security, while dark web monitoring facilitates swift action on vulnerabilities and certificates. However, improvements in cloud connectivity and dark web scanning are needed. Enterprises, especially those with Security Operations Centers, find it useful for its installation ease, device control, and security measures, despite firewall complexity.
What are key features of Cortex Xpanse?Cortex Xpanse is predominantly applied in large enterprises for safeguarding applications and databases against ransomware and malware. Organizations with Security Operations Centers leverage its customizable policies for client security and vulnerability remediation. It aids in managing attack surfaces as a proactive security strategy.
| Author info | Rating | Review Summary |
|---|---|---|
| System Administrator at a retailer with 5,001-10,000 employees | 4.5 | I find Cortex Xpanse excellent for client security, easy to manage, highly stable, and scalable, fully supporting compliance. My only minor concern is technical support, rated seven. I am very satisfied with this Palo Alto product overall. |
| Account Manager at Cairo International Airport Co. | 4.0 | I use Cortex Xpanse for attack surface management, valuing its proactive alerts and asset discovery for security. I desire better dashboard customization and more cost-effective pricing, but I highly recommend it, especially for public-facing services. |
| Senior Vice President at Chi Networks | 4.5 | I find this solution very stable and effective at catching malware, with great support. Its UI needs improvement, and scalability is limited now, but overall, I rate it nine out of ten. |
| Cyber Security Consultant at kas | 3.5 | I find Cortex Xpanse strong for attack surface management and continuous monitoring, especially for large enterprises. However, I note its high cost and lack of comprehensive adversary intelligence, which makes its Dark Web coverage difficult to confirm. |
| IT System Administrator at Bouri | 4.0 | I value Cortex Xpanse's firewall and antivirus, noting its stability and scalability. Yet, I experience cloud connectivity issues, difficult deployment, and high cost, making it better for large enterprises despite good technology. |
| Cybersecurity incident response team lead at Information Technology Solutions- ITS | 5.0 | I find Cortex Xpanse stable, scalable, and easy to use for vulnerability remediation and asset discovery, offering good value. While it lacks dark-web scanning and isn't for backup use cases, it's effective. I rate it 9/10. |
The best feature of the product is that it's easy to manage when we have set it up.
The beneficial impact of Cortex Xpanse for the company is security.
I'm not sure right now; I have nothing to comment on regarding what could be improved in the product. We are using it and we are satisfied.
I have nothing to comment right now on what other features I would like to see included in future updates.
I have been working with Cortex Xpanse for three, four years.
I would rate Cortex Xpanse as highly stable, around 10 on a scale from one to ten.
I would also rate its scalability as a 10.
Regarding technical support, I would rate it as a seven.
Positive
I personally took part in the installation and deployment of Cortex Xpanse.
It took us a couple of months approximately, as we were testing everything for a long time when implementing things. We have several clients, different kinds of clients.
A team of five to six people took part in the installation of Cortex Xpanse in our organization.
I don't know the licensing or setup cost; I have no idea about the cost.
We work with the cloud version of Cortex Xpanse.
We are working with Palo Alto products right at the moment. We have Cortex and GlobalProtect that we are using.
I'm not sure if we utilize Cortex Xpanse's capability to identify internet-facing assets.
I'm not sure about the automated threat assessment of Cortex helping prioritize vulnerabilities.
I would assess the integration capabilities of Cortex Xpanse as good; no issues so far with integration with other tools from different vendors.
Cortex Xpanse supports our organization's regulatory compliance efforts 100%, and it's what we need from it.
Right now, I am working only with Palo Alto for security.
I am not planning to work with some other vendors.
On a scale of one to ten, I rate Cortex Xpanse a nine.

When there is an alert from Cortex Xpanse regarding a certificate or surface, it prompts us to take immediate action. It checks vulnerabilities periodically, ensuring they are addressed, which helps in proactively managing security. The asset discovery feature identifies subnets and domains, performing regular checks on certificates.
Cortex Xpanse should offer better customization and configuration options on its dashboard. Additionally, considering the pricing element, it could be more cost-effective given the benefits.
We have had Cortex Xpanse for two years.
I don't work directly with deployments, but the setup process for Cortex Xpanse was straightforward, with the installation taking about an hour per unit.
The implementation of Cortex Xpanse helps keep our assets safe. It's a vital part of our security control, offering significant benefits.
Pricing for Cortex Xpanse should be commensurate with the benefits it offers. It's an investment in maintaining security.
As an attack surface manager, I highly recommend Cortex Xpanse, especially if there are many services exposed publicly on the internet.
I rate Cortex Xpanse an eight out of ten, indicating its effectiveness in security management.

The solution is primarily used for protecting our applications and databases, shielding them from threats such as ransomware and malware.
The most valuable aspect is its ability to catch trojans and malware. The definitions running behind it effectively detect threats that antivirus programs do not.
As we are a data center company with technology specialists for deployment, I don't think there are issues with support and other aspects.
Some improvements are needed in the user interface. It may require more enhancements.
We have been using the solution for probably three or four years now.
The solution is very stable. Its stability can be rated as eight or nine, or maybe even ten out of ten.
The product is not very scalable at present. However, they are committed to future enhancements to improve scalability.
The support team is helpful. I would rate the support as ten out of ten.
Positive
We have four to five maintenance staff members working in three shifts, totaling close to 12 individuals.
Not yet. I performed the analysis, however, my finance team indicates that it is okay as we are achieving good margins.
Currently, the solution aligns with our budget.
We are also using eSect for some of our customers.
I would rate the overall solution nine out of ten.
I recommend Cortex Xpanse primarily for large enterprises, especially those with a Security Operations Center (SOC) in place.
Cortex Xpanse is a strong solution for attack surface management, including digital brand protection and continuous monitoring. It effectively identifies unknown exposed assets, provides intelligence on infected users before an incident occurs, and offers vulnerability reporting. The solution ensures enterprises can monitor how they are perceived by customers and on the Dark Web. The detailed reporting of vulnerabilities helps prioritize issues based on attack surface revelations.
It's challenging to confirm the absolute coverage and penetration of Cortex Xpanse into the Dark Web. The solution lacks comprehensive intelligence on adversaries and risks, which other competitors might provide. Improvements in visibility and intelligence around adversaries and potential threats would enhance its effectiveness. Furthermore, the lack of a definitive metric for penetration in the Dark Web makes it difficult for the solution to prove its worth to customers.
I last sold Cortex Xpanse about one year ago.
Cortex Xpanse is a bit expensive compared to other market solutions like FortyRicoh and RiskIQ, making it more suitable for enterprise companies.
FortyRicoh, RiskIQ
I rate Cortex Xpanse a seven out of ten. More insight about adversaries and risks could make it closer to a perfect score. Also, ensuring that the intelligence from the solution includes more data about potential threats would be beneficial.
I use the solution in my company since Cortex Xpanse is good in installation and full control devices, but the firewall is not that simple.
The most valuable features of the solution are its firewall and antivirus. I also like the fact that the tool serves as an XDR product. My company uses Sophos as it is easy to link our branches to our headquarters.
I use Cortex Xpanse and Sophos for endpoint security purposes.
With Cortex Xpanse, there is an issue with connectivity in the cloud. Sometimes, the machine cannot be uninstalled easily or installed, so you may lose control when trying to get the password.
In our company, we are using most of the connectivity as endpoints with the help of Cortex on cloud. The endpoint connectivity in the cloud is an area where improvements are required.
There is an issue with the old versions of Cortex, and so when we have an older one with Windows or any OS, we have a problem with its connectivity with the cloud.
I have been using Cortex Xpanse for two years. My company uses the tool.
It is a stable solution. Stability-wise, I rate the solution a nine out of ten.
Scalability-wise, I rate the solution a nine out of ten.
My whole company uses the tool.
My company follows a schedule to check the portal, and we have to check it to prevent any issues in any of our company's regions. The antivirus processes everything before we do any testing, and we can follow the schedule and check the issue. If everything is good, there is no harm. The tool would block the issue if needed.
My company has not used much of the solution's technical support. When we forgot the password, it didn't take us a long time to restore the password. The support is not bad, but it is not too fast. I rate the technical support a seven out of ten. There is no support for the tool in Egypt, and Palo Alto is not trying to get much market share.
Neutral
I have experience with Sophos. Earlier, we were using Kaspersky, but there were issues with the machines, leading to many errors.
The solution is not easy to deploy and is more complicated than Sophos.
The solution is deployed on an on-premises model.
The deployment process took a few days to be completed. We were able to build the endpoints for the whole enterprise.
Cortex Xpanse is more expensive than the firewall tools from Sophos.
The tool's cost is too high.
Cortex is more expensive than Sophos, Kaspersky, or any other solutions. We chose Cortex XDR because of its technology. Cortex is made more expensive every year.
Our company uses continuous monitoring capability. There is no problem using the tool as an antivirus product. It is an expensive tool for our company.
Speaking about the tool's AI, the product is good and helps block malicious parts, but it does not have a specification.
I recommend the tool to large companies because of its price. For medium business or small business, Cortex Xpanse is not the best.
I rate the tool an eight out of ten.

The customer bought a license for Cortex Xpanse and Cortex XSOAR to customize the policies for vulnerability remediation.
Cortex Xpanse has an easy-to-use user interface. It has two models:
1. You can get quarterly reports about your environment.
2. If you have a yearly subscription, real-time case reporting and attack surface management.
No. 1 benefits smaller companies because they have a huge number of assets. They just need a report in order to work through it. No 2. Targets large-scale companies that will benefit from it as the very fact that it discovers assets and their vulnerabilities is a benefit.
Cortex Xpanse needs to add dark-web scanning.
I have been using Cortex Xpanse for the past six months.
I rate Cortex Xpanse ten out of ten for stability.
Cortex Xpanse is a scalable solution.
We deployed Cortex Xpanse once the license came up.
Cortex Xpanse is cheaper than other solutions.
I use the latest version of Cortex Xpanse. The solution is deployed on-cloud in our organization.
Users who don't need the backup use case can definitely buy Cortex Xpanse. However, there are better alternatives for users who really need the backup use case.
Overall, I rate Cortex Xpanse a nine out of ten.