TrustRadius: an HG Insights company

Palo Alto Networks Cortex XDR

Score8.4 out of 10

80 Reviews and Ratings

What is Palo Alto Networks Cortex XDR?

Cortex XDR (formerly Traps) replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.

Read more details.

Media

Screenshot of a Cortex XDR overview
Screenshot of a view of the Cortex XDR dashboard
Screenshot of a view of the Cortex XDR dashboard
Screenshot of a view of the Cortex XDR dashboard

1 / 4

Screenshot of a Cortex XDR overview

Who Buys & Uses Palo Alto Networks Cortex XDR

Palo Alto Networks Cortex XDR The Next-Gen Security Backbone for Modern Enterprises

Use Cases and Deployment Scope

Palo Alto Networks Cortex XDR is used in our organization to gain the better visibility in terms of networks, cloud, endpoint. it provide the single pane of glass visibility where user don't have to go tab by tab for multiple tool, rather than that they get the visibility from a single console. It reduce the mean time to detect and respond. Before we are facing the challenge that in a single day analyst are getting more than 500 alerts. The analyst not able to identicy which one is false positive and which one true positive this bring that a single analyst is busy on a single incident for 1-2 hour. Meanwhile the most important and priority aleert get breached. So Palo Alto Networks Cortex XDR bring the feature of case which bring same type of incidents into a single case which reduce the alert noise as well as analyst do not have to focus on a single alert rather than that they investigate a case and that investigation can solve 15 or more alerts from a single case. It also provides the RBAC which help admin to provide the necessary permission to analyst, admin, investigator etc. Previously if we have to get the visibility of application, autoruns, registry etc then we have to check individual endpoint on by one but from Palo Alto Networks Cortex XDR host insights model we get all this type of visibility from a single console. its also providing the Vulnerability management platform which help admin to get visibility of vulnerability of assets, OS even of application. It is the one solution which provides GUI based live terminal where admin can get the visibility of drive, folders, file and can also download it over from console of specific endpoint. Even we can also run python code, script and also get visibility of task manager and we can end process from task manager from Live terminal only. So we do not need to go one by one on every endpoint rather we can manage and get visibility of all this thing from a single console.

Pros

  • GUI based live terminal which provides visibility of task manager, Drive, folder, file. Even we can execute python code, command in PowerShell and cmd.
  • Incident / alert grouping into a Case. It minimize the mean time to respond. before analyst focus on every alert and some of them great breached and lasty they find its false positive. But with case they can focus on multiple alert which is grouped in a single case based on behavioural, hostname, Ip, incident type. this reduce time to respond and identify the alert whether its false positive or true positive.
  • Vulnerability Management - Now organization can get visibility of Vulnerability over their assets, OS, application which is running on endpoint. even they get remediation suggestion and what CVE is getting over that vulnerability.
  • Automatic Sandbox analysis- on every detection or prevention done by Palo Alto Networks Cortex XDR agent you will get analysis report for it over the console from the Wildfire. It provides the sandbox and analysis report so that admin or analyst can get better visibility what it can impact on their organization and how.

Cons

  • Within a short time period if same time of malware is executing again and again it provides the timeline of first execution but as a analyst if we think we need all the time whether it should be in second.
  • Malware Title for alerts- It provides the malware name as wildfire malware rather than it can provide the exact malware name which can help analyst to identify the alert based on name only then they can go for deep analysis.
  • ZIP file Quarantine- Now Palo Alto Networks Cortex XDR is blocking execution of malware but it should quarantine the ZIP file also but now its quarantining the file file after extracting from Zip and when we try to execute it. No ZIP file quarantine is available now.

Return on Investment

  • Before investing money on multiple product now from a single product its done.
  • Too much resources we need previously, now less resources can do the same work in less time.
  • Reduce the MTTR, MTTD which reduced the chance of get attacked and hacked.

Usability

Alternatives Considered

SentinelOne Singularity, CrowdStrike Falcon and Trend Micro Deep Security

Other Software Used

VirusTotal, Forcepoint DSPM, Microsoft 365

Palo Alto Networks Cortex XDR a Winner (if you can overcome the management interface)

Use Cases and Deployment Scope

Palo Alto Networks Cortex XDR is one of several layers we use to secure our endpoint devices. Harnessing the power of AI and machine learning, Palo Alto Networks Cortex XDR quickly recognizes and stops threats that may have otherwise gone unnoticed. It also offers the ability to remotely take systems offline while still giving you some level of access to perform forensics or repairs.

Pros

  • Endpoint Protection
  • Detect and Response
  • Antivirus

Cons

  • Interface can be confusing
  • An "Admin Bypass" feature to proceed with a false detection would be nice
  • Better out-of-the-box reporting

Return on Investment

  • Saves IT time by blocking the installation of many apps that would have otherwise gone unnoticed
  • Multi-year contracts allow for more consistent budgeting

Usability

Alternatives Considered

Bitdefender Managed Detection and Response (MDR) and SentinelOne Singularity

Other Software Used

SolarWinds Service Desk (SSD), N-able N-central, KnowBe4 PhishER/PhishER Plus, KnowBe4 Security Awareness Training, Wasp Inventory

Traps/Cortex XDR Review

Use Cases and Deployment Scope

Traps/now Cortex XDR was being used to provide endpoint protection for our servers and desktops. Traps/Cortex XDR was being used organization wide.

Pros

  • It does nothing well

Cons

  • Traps/cortex XDR alerts on wide scale commercial apps that are clearly not malicious
  • the Cortex XDR console interface is 5 steps worse than simply bad
  • Frontline support reps are not fluent in spoken English although their written fluency is okay (at best)

Most Important Features

  • Integration with our firewalls. What a mistake otherwise

Return on Investment

  • Traps had an agent upgrade get "stuck" that required me to manually reboot servers into safe mode to remediate it. Traps/Cortex ROI is by far negative. I'm pretty well-paid. Requiring multiple hours of my time to remediate your [bad] product entirely destroys any benefit.

Alternatives Considered

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)

Other Software Used

Microsoft Defender for Endpoint

Usability

Excellent Threat Hunting Capabilities And Endpoint Security Products For Next Gen

Pros

  • Some zero-day exploits, malicious child processes, and maliciously hashed files have been successfully blocked by it.
  • Analyzing and identifying unknown malicious software on workstations, servers, and mobile devices are made easier with the help of tracking file behavior.
  • Panorama's integration helps us detect malicious files and traps more quickly and efficiently than other products we've tried, protecting us from zero-day attacks.

Cons

  • Traps, like all advanced endpoint protection, need to grow in machine learning/baseline protection.
  • Sometimes, exceptions were made because of legacy or custom software issues, and we encountered a bug in an older version of the agent.
  • Traps are best for IT environments using COTS reports/dashboards. In environments where custom software and applications are used, Traps necessitate a great deal of tweaking.

Most Important Features

  • Tracking file behavior and the ability to prevent the use of zero-day exploits are two of its many strengths.
  • Monitoring that is both cloud-based and has a low environmental impact.
  • Convenient console operation, as well as quick and painless setup.

Return on Investment

  • It's less expensive than an onsite server, but it puts more work on the endpoint security teams.
  • It adds an extra layer of security for our users and reduces malware outbreaks, which reduces downtime.
  • Faster, and Traps give us a lot of information about what processes are running on our endpoints.

Alternatives Considered

CrowdStrike Falcon Endpoint Protection, Kaspersky Endpoint Security and Symantec Advanced Threat Protection

Other Software Used

Kaspersky Endpoint Security, Cisco ASA, MS SharePoint, N-able N-central (formerly Solarwinds N-Central)

Palo Alto Networks Cortex XDR--best fit as an endpoint protection suite

Use Cases and Deployment Scope

Palo Alto Networks Cortex XDR is used for our in-house as well as roaming users, and we have procured around 200 licenses. With Palo Alto Networks Cortex XDR, we are enabling security controls and also getting insights and deep visibility on our users' suspicious activities and behaviors and securing them from advanced attacks like file-less malware, ransomware, etc.

Pros

  • Malware prevention
  • Exploit prevention
  • EDR and XDR
  • Ransomware protection
  • Disk encryption (with Bit Locker and File Vault)
  • Device control features
  • Analytics
  • Investigation
  • Incident management
  • Forensics
  • NTA--network traffic analysis
  • UBA/UEBA--user entity behavior analysis

Cons

  • Inventory management
  • Web controls
  • DLP features

Return on Investment

  • After putting Palo Alto Networks Cortex XDR on a user's system, users came back with a positive response that there are no performance issues now.
  • We are able to track and control granular suspicious and malicious activities.
  • Web controls are missing, which if they would have been there would have been very helpful.

Alternatives Considered

CrowdStrike Falcon Endpoint Protection, Trend Micro Apex One (formerly OfficeScan), SonicWall Capture Advanced Threat Protection (ATP) and Sophos Intercept X

Other Software Used

CrowdStrike Falcon Endpoint Protection, Sophos Intercept X, Trend Micro Apex One (formerly OfficeScan)