No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Palo Alto Networks Cortex XSOAR excels in automation and playbook creation, significantly improving productivity and efficiency in SOC environments.
Its extensive library of integrations and playbooks makes it highly adaptable and useful for various security operations, enhancing incident management and automation.
The integration capabilities are exceptional, facilitating seamless coordination with different tools and platforms, ultimately streamlining security operations.
Palo Alto Networks Cortex XSOAR has a profound impact on reducing the Mean Time to Resolution (MTTR) for incidents, contributing to more efficient security operations.
Its automation and custom workflows positively influence organizations by enabling faster incident response and allowing teams to focus on innovation rather than repetitive tasks.

CONS

Documentation for building automation is not very good and needs improvement.
Cortex XSOAR is perceived as expensive, and the pricing model could be improved.
System slowdown occurs with an influx of alerts, affecting investigation speed.
Cortex XSOAR can be complex to learn and implement, requiring significant vendor involvement.
Integration and customization need enhancement, with existing compatibility issues for certain formats.
 

Palo Alto Networks Cortex XSOAR Pros review quotes

Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Mar 6, 2026
Palo Alto Networks Cortex XSOAR has had a huge impact on our organization's mean time to resolution for incidents, improving the security SOC operations efficiency tremendously, by more than 80% to 90%.
MM
Cybersecurity Senior Analyst
Jul 28, 2026
The time to respond was reduced by approximately sixty percent, which specifically reduced the manual effort required from analysts.
Animesh.Kumar - PeerSpot reviewer
Senior Solutions Architect at Think Power Solutions
Aug 3, 2026
The biggest advantage in Cortex XSOAR that I see is its extensive AI capabilities, where it unifies all your log collection mechanisms and can ingest the logs from almost all of the end devices.
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
Ashwani-Tyagi - PeerSpot reviewer
Regional Manager at Orange
Aug 3, 2026
Palo Alto Networks Cortex XSOAR can reduce the Mean Time to Resolution (MTTR) drastically because there is a lot of automation which has already been implemented.
reviewer2866401 - PeerSpot reviewer
Senior Cyber Defense Analyst at a manufacturing company with 10,001+ employees
Jul 13, 2026
Palo Alto Networks Cortex XSOAR has impacted my organization positively because it has these automations and customized workflows.
Aruna-Udawatte - PeerSpot reviewer
VP Of Digital Transformation at Netsys Solutions (Pvt) Ltd
Aug 3, 2026
The biggest advantage of Palo Alto Networks Cortex XSOAR for us and our clients is the support that we are getting from Palo Alto Networks.
SreejeshSoman - PeerSpot reviewer
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
Aug 6, 2026
Palo Alto Networks Cortex XSOAR is the number one security platform, so their response also rates highly.
DayaramGoyal - PeerSpot reviewer
Vice President, Technology at Cache Digitech Pvt Ltd.
Aug 18, 2025
Palo Alto Networks Cortex XSOAR is a good product with enhanced and efficient playbooks, as demonstrated during our use case simulations.
AP
Assistant Security Architect at Cloudnomics
Mar 2, 2026
Palo Alto Networks Cortex XSOAR has had a positive impact on the mean time to resolution for incidents (MTTR), as it has significantly reduced noise.
CC
Enterprise Security Architect V at FirstEnergy
May 12, 2025
What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali.
 

Palo Alto Networks Cortex XSOAR Cons review quotes

Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Mar 6, 2026
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX.
MM
Cybersecurity Senior Analyst
Jul 28, 2026
The biggest area for improvement is simplifying playbook development and debugging.
Animesh.Kumar - PeerSpot reviewer
Senior Solutions Architect at Think Power Solutions
Aug 3, 2026
One area for improvement I see in Cortex XSOAR is the cost.
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
Ashwani-Tyagi - PeerSpot reviewer
Regional Manager at Orange
Aug 3, 2026
One disadvantage or thing which can be improved in Palo Alto Networks Cortex XSOAR is the cost because it is too costly.
reviewer2866401 - PeerSpot reviewer
Senior Cyber Defense Analyst at a manufacturing company with 10,001+ employees
Jul 13, 2026
Another area I can suggest is the searching or reporting feature where you have to write a query, which is definitely good for searching your incidents.
Aruna-Udawatte - PeerSpot reviewer
VP Of Digital Transformation at Netsys Solutions (Pvt) Ltd
Aug 3, 2026
It is both difficult to implement, deploy, and integrate the product.
SreejeshSoman - PeerSpot reviewer
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
Aug 6, 2026
The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher.
DayaramGoyal - PeerSpot reviewer
Vice President, Technology at Cache Digitech Pvt Ltd.
Aug 18, 2025
It was expensive, making it essential for the customer to evaluate whether ROI is coming from the business model, as they are also acting as a SOC provider.
AP
Assistant Security Architect at Cloudnomics
Mar 2, 2026
While I personally appreciate this approach, I have observed that junior analysts on my team find it difficult to build playbooks.
CC
Enterprise Security Architect V at FirstEnergy
May 12, 2025
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.