Cofense Triage vs. Palo Alto Networks Cortex XDR

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cofense Triage
Score 9.2 out of 10
Enterprise companies (1,001+ employees)
Cofense Triage accelerates phishing qualification, investigation, and response by automating standard responses to suspicious emails to make analysts more efficient and driving out actionable intelligence, and providing incident response playbook.N/A
Palo Alto Networks Cortex XDR
Score 8.7 out of 10
N/A
Traps replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.N/A
Pricing
Cofense TriagePalo Alto Networks Cortex XDR
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cofense TriagePalo Alto Networks Cortex XDR
Free Trial
YesNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeOptionalNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cofense TriagePalo Alto Networks Cortex XDR
Top Pros
Top Cons
Features
Cofense TriagePalo Alto Networks Cortex XDR
Incident Response Platforms
Comparison of Incident Response Platforms features of Product A and Product B
Cofense Triage
7.2
33 Ratings
15% below category average
Palo Alto Networks Cortex XDR
-
Ratings
Integration with Other Security Systems7.132 Ratings00 Ratings
Attack Chain Visualization6.926 Ratings00 Ratings
Centralized Dashboard7.833 Ratings00 Ratings
Live Response for Rapid Remediation7.230 Ratings00 Ratings
Best Alternatives
Cofense TriagePalo Alto Networks Cortex XDR
Small Businesses
AlienVault USM
AlienVault USM
Score 7.8 out of 10
SentinelOne Singularity
SentinelOne Singularity
Score 9.4 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.2 out of 10
SentinelOne Singularity
SentinelOne Singularity
Score 9.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.2 out of 10
SentinelOne Singularity
SentinelOne Singularity
Score 9.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cofense TriagePalo Alto Networks Cortex XDR
Likelihood to Recommend
8.2
(36 ratings)
8.5
(12 ratings)
Likelihood to Renew
10.0
(1 ratings)
-
(0 ratings)
Usability
10.0
(1 ratings)
-
(0 ratings)
Availability
10.0
(1 ratings)
-
(0 ratings)
Performance
10.0
(1 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
10.0
(5 ratings)
In-Person Training
10.0
(1 ratings)
-
(0 ratings)
Implementation Rating
10.0
(1 ratings)
-
(0 ratings)
Configurability
10.0
(1 ratings)
-
(0 ratings)
Product Scalability
10.0
(1 ratings)
-
(0 ratings)
Vendor post-sale
10.0
(1 ratings)
-
(0 ratings)
Vendor pre-sale
10.0
(1 ratings)
-
(0 ratings)
User Testimonials
Cofense TriagePalo Alto Networks Cortex XDR
Likelihood to Recommend
Cofense
Cofense Triage is well suited for large companies which are receiving large amounts of emails. It makes it easy for users to report suspicious emails and makes it easy for security staff to review, analyze and investigate these emails to avoid having them delivered in the future in case any other security tool fails to detect them.
Read full review
Palo Alto Networks
Malware that doesn’t leave files behind has become widely available. Anyone who can afford to reverse this trend should purchase technology. Application whitelisting isn’t for everyone, and Palo Alto Networks Traps can help. Enterprises looking for a low-affected, next-generation solution with high protection should consider it. PAN Traps is a great product at a reasonable price, and I highly recommend it.
Read full review
Pros
Cofense
  • Separating links and attachments contained in the email, and checking to see if they are known malicious.
  • Clustering like emails to save time when responding.
  • Providing risks scores with each cluster to give an estimate on which clusters should be addressed first.
Read full review
Palo Alto Networks
  • Direct Access to devices via Live Terminal which provides operations with scripting, triage, and preservation of artifacts.
  • Behavioral Indicators of Compromise which provides alerts on events regarding groups of hosts and their signatures.
  • Querying complex data sets involving a variety of devices for network connections, hashes, DNS, etc.
Read full review
Cons
Cofense
  • There are too many interdependent pieces which you have to acquire separately.
  • I think Cofense has a lot of capabilities and usefulness, but I think it's too a la carte.
  • We own Cofense and PhishMe currently and there are some gaping holes that require additional licensing to close.
Read full review
Palo Alto Networks
  • Traps doesn't seem to function as a traditional A/V very well, so it's better as another layer to your endpoint protection
  • Traps can cause issues with some legacy or custom programs, so exceptions may have to be made
  • Traps falsely identifies things as malicious at times, this is not often though
Read full review
Likelihood to Renew
Cofense
Cofense is stable and provides easy to use solution to aid the investigation of emails as well as managing simulated phishing campaigns.
Read full review
Palo Alto Networks
No answers on this topic
Usability
Cofense
The interface is easy and intuitive.
Read full review
Palo Alto Networks
No answers on this topic
Reliability and Availability
Cofense
We've experienced zero downtime.
Read full review
Palo Alto Networks
No answers on this topic
Performance
Cofense
No slowness seen.
Read full review
Palo Alto Networks
No answers on this topic
Support Rating
Cofense
No answers on this topic
Palo Alto Networks
The support we receive from Palo Alto is one of the best aspects of Traps. It is very easy to recommend their support. It seems much easier to connect directly with someone with a deep understanding of the product rather than other companies where you basically have to make an airtight case that it is some kind of non-standard issue that can't be solved with existing documentation. Palo Alto digs deep and helps with advanced troubleshooting to get things working.
Read full review
In-Person Training
Cofense
Training was through, relevant and easy to follow.
Read full review
Palo Alto Networks
No answers on this topic
Alternatives Considered
Cofense
The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did not like the user interface.
Read full review
Palo Alto Networks
Traps is the slickest interface, easy to use and intuitive rule making, and the rest just didn't quite stack up to the performance level of Traps. McAfee and Kaspersky just hog processor and RAM power. I didn't like the interface and functionality of SentinelOne as much as Traps. Palo Alto really put a lot of time into the development of this software, and had some of the founding fathers of IT Security heading the development process. Can't beat that.
Read full review
Scalability
Cofense
We've experienced zero downtime
Read full review
Palo Alto Networks
No answers on this topic
Return on Investment
Cofense
  • Due to the integration potential, large amounts of time are saved on a daily basis.
  • Incident response time has dropped due to the increased information available by having access to phishing emails directly.
  • Staff are able to effectively learn how multiple tools in our environment are used by mastering Triage. This has decreased training time greatly and increased the effectiveness of each associate.
Read full review
Palo Alto Networks
  • After putting Palo Alto Networks Cortex XDR on a user's system, users came back with a positive response that there are no performance issues now.
  • We are able to track and control granular suspicious and malicious activities.
  • Web controls are missing, which if they would have been there would have been very helpful.
Read full review
ScreenShots

Cofense Triage Screenshots

Screenshot of Triage DashboardScreenshot of Triage Dashboard Cluster DetailsScreenshot of Triage Cluster DetailsScreenshot of Triage Cluster Malicious AttachmentScreenshot of Triage Cluster HeadersScreenshot of Triage Reporter Details