# Cortex XDR Reviews 2026. Verified Reviews, Pros & Cons | Capterra

> Is Cortex XDR the right Endpoint Protection solution for you? Explore 18 verified user reviews from people in industries like yours to make a confident choice.

Source: https://www.capterra.com/p/175139/Traps/reviews

---

Cortex XDR

4.4 (18)

[View alternatives](https://www.capterra.com/p/175139/Traps/alternatives/)

Provider data verified by our Software Research team, and reviews moderated by our Reviews Verification team. [Learn more](https://www.capterra.com/our-story/)

* * *

Last updated March 13th, 2026

# Reviews of Cortex XDR

Ease of use

4.1

Customer Service

4.6

## Showing most helpful reviews

Showing 1-18 of 18 Reviews

Sort by:

Most Helpful

Rating

Company Size

Reviewer's Role

Length of Use

Frequency of Use

VR

Verified Reviewer  
Sr. Cyber Security Analyst  
Computer & Network Security  
Used the software for: 1-2 years

### "XDR for endpoint security is a game changer."

January 7, 2025

5.0

It has brought a security posture enhancement. Important audit related demands were fulfilled by querying on XDR dataset. It is accurate with work/policy assigned.

Pros

I am an administrator off this tool and it is a powerful tool with good capabilities. Seamless integration with other sensors, log ingestion and log stitching gives a brief story of an incident. It has remediation suggestions based on AI. XDR analytics and Behavioral detection feels promising to foil up ZERO day attack. We can also configure Co-relation rules. XQL provided by palo alto can be used to query the whole dataset and covers data that are not covered in UI.

Cons

Costing is on heavy side, each feature has add-on license cost. UI takes time to understand. Policy structure is a bit rigid.

Review Source

JP

Jai P.  
Cybersecurity Engineer  
Computer & Network Security  
Used the software for: 6-12 months

### "A double defense for threat: Cortex XDR"

November 21, 2024

5.0

Cortex Xdr is a comprehensive security solutions which help in improving the security posture of the organizations. It comes with advanced threat detection which help security team to focus on high priority incidents rather than wasting time on low severity incidents. Its friendly interface and customizable dashboard provides the clear visualization of incidents and easy to recognize the incidents. It can be integrated with soar as well as siem which allow security team to investigate. It has automated response which help in taking the action on incidents before the attack happen.

Pros

Cortex XDR is an extended version of XDR. The best thing in Cortex XDr is it has integrated threat detection which help in combining the endpoint, network, and even cloud data. It allow the comprehensive visibility and also provide the threat detection across the environment. It comes with automated response capabilities which make easier for security team to responds to threats quickly and efficiency. It has customizations dashboard as per the need of organizations and user. The best thing is it can be integrated with other security solutions like SIEM, SOAR. The best thing is support of Cortex, they provide the imidate reponse on High ticket and for medium they take 1-2 hr.

Cons

We face some challenges while configuring it, but with a proper security team we can achieve it. Its hard for the non technical guy or fresher to use it but with a proper training they can achieve it. Sometimes we face issues like false positive alerts, which can be decrease by proper investigation of incidents by security teams. It has limited integrations with third party tools. Sometimes it block the external devices even adding in excepptional but it can be solved by support team.

Alternatives considered

[Trend Micro](https://www.capterra.com/p/238490/Deep-Security-Smart-Check/)

Reason for choosing Cortex XDR

Cortex Xdr support is best than trend micro and other tool. It comes with integration of SIEM and SOAR tool. Its threat intelligence help to identify threat faster than other,

Review Source

Davesh M.  
Automation Engineering Intern  
Computer Software  
Used the software for: Less than 6 months

### "Difficult to get setup"

April 24, 2019

3.0

Pros

Quick intrusion/threat detection, silent background running

Cons

Extremely difficult to roll out to company, was blocking company wide software such as 7-zip, was blocking Skype for Business messages, took forever to troubleshoot and properly roll out and install. In addition, the software does not have a great UI, it appears very serious and unnecessarily serious when detecting small threats

Review Source

SO

Shawn O.  
IT Systems Specialist  
Primary/Secondary Education  
Used the software for: 2+ years

### "Cortext XDR - Great Endpoint Protection and so much more."

October 2, 2023

5.0

Pros

Cortex made our network more secure. When we swapped from our previous anti-virus platform to Cortex XDR we started seeing things that had slipped past our old AV platform and was causing issues in our network. Cortex made it easy to locate and clean these machines and if needed it made it easy to isolate them until they were cleaned and approved to be put back on our network.

Cons

The biggest con for our team, being part of a public school system, is the cost. The cost of this platform compared to traditional anti-virus/endpoint protection platforms such as Avast, Symantec, etc. is very significant and we had to get a trial of this setup and running as a proof of concept to justify the cost difference to our board and county commission in order to get the money to purchase this product but it has definatley been worth it.

Alternatives considered

[Carbon Black Endpoint](https://www.capterra.com/p/168868/Cb-Predictive-Security-Cloud/)[Intercept X Endpoint](https://www.capterra.com/p/151731/Sophos-Endpoint-Protection/)[Malwarebytes for Business](https://www.capterra.com/p/251770/Malwarebytes-for-Business/)[Avast Ultimate Business Security](https://www.capterra.com/p/170318/Avast-Business-Antivirus-Pro-Plus/)

Reason for choosing Cortex XDR

Multiple reasons to be honest and different reasons for each of the competitors. For some of the competitors they got ruled out because of a lack of features or analytics that we wanted to see. Others was ruled out because they did not offer a large enough of an educational discount to get the price down within the budget that we had to work with.

Switched from

[Avast Business CloudCare](https://www.capterra.com/p/236796/Avast-Business-CloudCare/)

Cortex XDR was more secure and provided more valuable information and analytics than our previous product.

Review Source

JJ

Jerome J.  
Helpdesk Manager  
Health, Wellness and Fitness  
Used the software for: 1-2 years

### "Cortex XDR Review"

October 19, 2021

4.0

Cortex is a solid product. We haven't had any major complaints from the user community. We haven't had to unblock any major products that were perceived as spam at this point. Many other products tended to block updates to products due to the executable file not being recognized by their database. We haven' had that issue with Cortex.

Pros

Our team is responsible for the deployment of Cortex into our Mac and PC environment. The agent was very easy to distribute utilizing our Deployment Software tool. The dashboards provide an excellent view into what is active and reporting back to the tool. We haven't had any major whitelist issues between the tool and endpoints.

Cons

I would like to see the scan on demand option as an easy one-click process for end users so they can be pro-active.

Alternatives considered

[Symantec Endpoint Security](https://www.capterra.com/p/227396/Symantec-Endpoint-Protection/)[Trellix Endpoint Security](https://www.capterra.com/p/151734/McAfee-Endpoint-Security/)

Reason for choosing Cortex XDR

Cortex is a lighter client than the alternatives. The agents are less chatty between the endpoints and the server. And the overall cost was significantly better.

Switched from

[Symantec Endpoint Security](https://www.capterra.com/p/227396/Symantec-Endpoint-Protection/)

Cortex is a lighter client and is less chatty between endpoints and the server.

Review Source

SS

Shitij S.  
Sr. Security Manager  
Information Services  
Used the software for: 1-2 years

### "Excellent product with great flexibility in terms of outcomes"

June 1, 2021

4.0

I evaluated this technology and compared it to other SOAR and NDR platforms in the space. We did choose Cortex XDR due to the use case coverage and close knit relationships with Palo's executive teams. Overall, very happy with the acquisition of this product line in our IT environment and the security program has benefited directly because of the day-to-day use of this product across a wide variety of business and technical use cases in our environment.

Pros

The ability to create custom playbooks and integrate APIs from disparate vendors was the highlight of our use of this product.

Cons

Customer support can be patchy. Also, depending on the use case being implemented, documentation and systems engineering support from Palo can vary. We were able to work through these issues being an Enterprise user for PANW, however, small to mid size companies may find the time to value to drag a fair bit.

Alternatives considered

[Humio](https://www.capterra.com/p/169894/Humio/)[Snowflake](https://www.capterra.com/p/148267/Snowflake/)

Reason for choosing Cortex XDR

Ease of use, existing use of their product lines in our environment, and degree of coverage in terms of our key use cases.

Switched from

[Splunk Enterprise](https://www.capterra.com/p/94317/Splunk/)

We were not happy with the use case coverage and were spending a lot of money on a wide set of security vendors. Our portfolio teams undertook an applications rationalization effort, which is what prompted our evaluation and move to Cortex.

Review Source

KM

Karl M.  
CISO  
Banking  
Used the software for: 6-12 months

### "Rock solid EDR product with high accuracy"

January 11, 2025

5.0

The product is rock solid and gets latest threat intel feed from around the world so that it stays current against 0-day threats amongst other new intrusion techniques.

Pros

We were thoroughly impressed by the speed of detection and accuracy of detection from their EDR component.

Cons

As of right now, there isn't any. Perhaps the UI can be more modernized.

Review Source

VR

Verified Reviewer  
Technical Security Officer  
Fund-Raising  
Used the software for: 1-2 years

### "Good Endpoint Security Solution"

September 12, 2019

5.0

Traps is good software to have. It did stop some malicious software that was downloaded.

Pros

This product doesn't do the old-fashioned signature based detection, but works by observing attack technique and behaviors. One of our workers had an Excel document which tried to reference some command line software to manipulate data. Of course this is very much how a virus could work, so Traps blocked it. Although this was a false positive, the solution using that Excel was not approved so Traps did a good thing. Management through the admin portal is visually pleasing and intuitive for most if the options.

Cons

We moved from on-prem installation to Cloud version of Traps. In the beginning the training options for the cloud version were almost non-existent. Even now, our training option was cancelled because of no other applicants for it. There is a free on-demand version of the training which I now will settle for. Managing the "Agent Installations" is not really intuitive.

Reason for choosing Cortex XDR

Part of a big package of Palo Alto offerings, so price was interesting but also tests we did were good.

Review Source

VR

Verified Reviewer  
ThreatZERO Consulting Supervisor  
Computer & Network Security  
Used the software for: 6-12 months

### "Its a trap"

December 4, 2018

3.0

Pros

The product works well. Its not a full solution although it can help hit compliance with legacy servers

Cons

it can be resource intensive and requires that some exploits run partially before being caught.

Review Source

VR

Verified Reviewer  
Global Account Executive  
Computer Software  
Used the software for: 6-12 months

### "This is awesome"

August 9, 2018

5.0

Pros

I like that this was a well designed product that pushed my org's concept of IT security

Cons

It's expensive. We had to work to find budget for this

Review Source

RB

Rene B.  
Senior IT System Engineer  
Chemicals  
Used the software for: 2+ years

### "Cortex XDR - verhaltensbasierte Thread Detection"

August 9, 2024

4.0

Wir haben bisher nur gute Erfahrungen gemacht was die Erkennungsrate angeht. Relativ wenige false positives und solide Erkennung schadhafter Prozesse.

Pros

Die verhaltensbasierte Echtzeiterkennung, die auch schadhafte laufende Prozesse beendet.

Cons

Relativ hungrig was Arbeitsspeicher angeht.

Switched from

[Mcafee Total Protection](https://www.capterra.com/p/219069/Mcafee-Total-Protection/)

Hashbasierte Antivirenerkennung war nicht mehr state of the Art.

Review Source

SB

Stefan B.  
Network- and Security Engineer  
Chemicals  
Used the software for: 2+ years

### "Cortex XDR"

March 14, 2023

5.0

Sehr ausgereiftes Produkt welches mit einer guten Darstellung überzeugt.Sehr gute Thread Erkennung.auch mit der lokalen Analyse (KI)

Pros

Gute Darstellung aller Clients und BedrohungenKlare Strukturen innerhalb des ProgrammsEinfache InstallationGute und einfache Update-Prozesse

Cons

Aktuell kann ich da nichts zu sagen. Wir sind aktuell sehr zufrieden mit dem Produkt

Review Source

DG

Daniel G.  
Systems Administrator  
Hospitality  
Used the software for: 2+ years

### "Best AV I’ve Used"

August 5, 2022

5.0

It’s the most effective endpoint protection software I’ve used to date.

Pros

I’ve never seen it miss blocking actual malware. The hueristic analysis is also very accurate.

Cons

It often mistakes IT admin tools as malware. Which is understandable, albeit annoying.

Review Source

DO

David O.  
Network Administrator  
Construction  
Used the software for: 2+ years

### "Much better than signature based AV"

August 13, 2019

5.0

We needed a malware protection system that really worked. We had tried other AV programs but they would all fail at some point. We have had zero problems with workstations getting infected since using Traps.

Pros

Traps does not rely on AV signatures. It relies on detecting the programmatic exploits that virus writers use to infect PCs. It also uses the behavior of programs to detect malicious activity. And it really works. It has caught malicious infected documents, spyware, adware, and grayware trying to infect our systems. And it stops the programs cold. Also, the new version is cloud based so we can protect remote users.

Cons

The endpoint agent updating process is still not as automatic as I think it should be. But it has been vastly improved in the latest version.

Review Source

TW

Troy W.  
Software Engineer  
Hospital & Health Care  
Used the software for: 1-2 years

### "As a User I Don't Notice It, Which is Good"

February 17, 2022

5.0

Pros

This software seems to have a light footprint on performance when running on computers. I have it running all the time on mine and I don't notice any performance hit as a result, which is good. It seems to work well on lower-end performing computers (i5 processor, 8GB RAM) as well as higher-end performing ones (e.g. i7 processor, 16GB+ RAM, etc).

Cons

No cons I can think of; however, I am only a user (not an admin), so I only see one side of this software, which looks good from my perspective. I don't notice it's running, which is the best you can hope for in a security product that's always running on your computer.

Review Source

JB

Javier B.  
CSO  
Computer Software  
Used the software for: 1-2 years

### "Good solution for Endpoint... but with comments"

May 13, 2019

4.0

The general experience is very positive. There have been hardly any incidents after almost 2000 deployments and, on the other hand, the level of protection and information on the endpoints has improved enormously.

Pros

In standard endpoints it works perfectly. Protects equipment easily and efficiently. It has support for most of the operating systems updated in a company and the false positive rate is acceptable

Cons

The need to be connected to the internet is a limitation of the product. Proxy-based architectures are not supported, which makes it impossible to use them for systems in network segments without internet access

Review Source

RS

Richard S.  
IT Supervisor  
Education Management  
Used the software for: 6-12 months

### "Decent Anti-Virus"

February 7, 2020

4.0

It has been a pretty decent product overall. We used a management system to deploy it to out desktops and laptops. Wish they had a way to deploy it from the portal.

Pros

It was easy to deploy to the end users computers. Easy to manage from one location. Installing and activating the license was pretty easy and straight forward. It was a good solution to interface with our firewall.

Cons

I had it installed on a few desktops and servers during the testing period. The vendor had a page setup for us. But once we bought the software I had to un-install the trial verison and install it again with out license. You could do any type of upgrade.

Reason for choosing Cortex XDR

It interfaced with out firewall appliance.

Review Source

JA

Jack A.  
Engineer  
Financial Services  
Used the software for: I used a free trial

### "Next gen endpoint protection with some caveats"

July 23, 2020

4.0

Overall, the product is promising offering next gen protection against 0 day attacks. We found management interface needing improvement and features need to be added to cater for very big deployments.

Pros

We liked most the capability and detection rate of detecting malware and malicious behavior, even without internet.

Cons

Some software from known vendors were detected as false positive. Management interface lacks some nice to have features, specially for large deployment.

Alternatives considered

[CrowdStrike](https://www.capterra.com/p/147662/CrowdStrike-Falcon/)[Trellix Endpoint Security](https://www.capterra.com/p/151734/McAfee-Endpoint-Security/)

Review Source

Similar Products

Featured

## Related categories

[Endpoint Protection](https://www.capterra.com/endpoint-protection-software/)[XDR (Extended Detection & Response)](https://www.capterra.com/xdr-software/)[Computer Security](https://www.capterra.com/computer-security-software/)