Skip to main content
TrustRadius
Palo Alto Networks Cortex XDR

Palo Alto Networks Cortex XDR
Formerly Traps

Overview

What is Palo Alto Networks Cortex XDR?

Traps replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.

Read more
Recent Reviews

TrustRadius Insights

Palo Alto Networks Traps is a highly regarded cybersecurity software that offers robust protection against malware, zero-day exploits, and …
Continue reading

Traps will trap malware

10 out of 10
February 26, 2020
Incentivized
Traps are used by all of the endpoints (notebook & VDI) in our organization. This is done to mitigate the risk from malware attack, zero …
Continue reading

Trap that malware!

8 out of 10
February 27, 2019
Incentivized
Traps was purchased as a response to a virus outbreak that kept cropping up due to still infected systems popping up days or weeks after …
Continue reading
Read all reviews
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Palo Alto Networks Cortex XDR?

Traps replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

97 people also want pricing

Alternatives Pricing

What is CrowdStrike Falcon?

CrowdStrike offers the Falcon Endpoint Protection suite, an antivirus and endpoint protection system emphasizing threat detection, machine learning malware detection, and signature free updating. Additionally the available Falcon Spotlight module delivers vulnerability assessment with no…

What is Kaspersky EDR Optimum?

Kaspersky Endpoint Detection and Response (EDR) Optimum helps identify, analyze and neutralize evasive threats by providing easy-to-use advanced detection, simplified investigation and automated response. It is a basic EDR tool for mid-market organizations who are just starting to build their…

Return to navigation

Product Details

What is Palo Alto Networks Cortex XDR?

Traps replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.

Palo Alto Networks Cortex XDR Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(53)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Palo Alto Networks Traps is a highly regarded cybersecurity software that offers robust protection against malware, zero-day exploits, and advanced persistent threats. Its seamless integration with the Palo Alto Suite has made it a popular choice among users. The software can be easily installed and used on various devices, including laptops and virtual desktops. Users have praised Traps for its ability to detect grayware, serious malware, and exploit attempts that may be missed by other antivirus solutions like Windows Defender. One of the standout features of Traps is its ability to prevent the execution of malware without requiring a file to be downloaded, providing enhanced protection for users. This next-gen capability, coupled with its ease of use and strong protection, has prompted many customers to replace their existing antivirus solutions with Palo Alto Networks Traps.

Traps has proven itself invaluable in identifying and quarantining threats, as well as isolating future malware and preventing its spread across the network. By integrating Wildfire and host AV, Traps adds additional layers of security to hosts and aids in detecting unknown and zero-day malware. The inclusion of Traps functionality in Palo Alto Networks Cortex XDR further enhances security controls and provides deep visibility into suspicious activities and behaviors exhibited by users. Cortex XDR serves as an Endpoint Response tool that enables organizations to quickly identify and respond to events and incidents across multiple devices.

Users have reported that Palo Alto Networks Traps offers advanced anti-malware detection and prevention with a low false-positive rate, minimizing user annoyance while effectively mitigating the risk of malware attacks, zero-day attacks, and APTs. Its organization-wide deployment ensures comprehensive protection for servers, desktops, and roaming users. With Traps seamlessly integrated into the Palo Alto Suite, manual whitelisting and server updates are no longer necessary. Overall, Palo Alto Networks Traps is widely recognized for its ease of installation, seamless integration capabilities, next-gen features, and robust protection against advanced threats.

Attribute Ratings

Reviews

(1-3 of 3)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
It is important to note that the functionality of Palo Alto Network Traps is being subsumed into the larger CortexXDR product. Traps has been a good way for our organization to implement advanced anti-malware detection and prevention with a low false-positive rate and a minimum of user annoyance. It is able to catch things that are missed by Windows Defender, both grayware and more serious malware, and exploit attempts. Palo Alto Network Traps can even prevent file-less malware from running.
  • Malware detection without existing signatures
  • Test detonation of unknown files in the cloud and locally
  • Prevention of threats that traditional AV can't block
  • Deployment of the agent via SCCM can have downstream consequences.
  • The agent installer occasionally has issues, especially if it is being used for a manual upgrade.
  • Kernel permissions issues on Mac may require user interaction (true for most AV).
Normal levels of antivirus are basically good enough at the free tier. But they won't stop the sorts of threats that are becoming increasingly common online. Even if one isn't the target of an APT, file-less malware is becoming commoditized and anyone who can afford it should implement a technology to stop it. Folks who aren't ready for full-on application whitelisting (including scripts) will find Palo Alto Network Traps a great fit with the relative ease of configuration and low user annoyance rate.
  • Audit compliance
  • Ransomware protection
  • Productivity from system availability
We looked at Dell's Cylance product and decided against it for two reasons. The first is that it cost a lot more than what we eventually paid for Traps. The second was because initial configuration was very involved and prone to generating user issues until fine-tuning was completed. Palo Alto Network Traps was cheaper and easier to get up and running. We didn't need professional services to help.
The support we receive from Palo Alto is one of the best aspects of Traps. It is very easy to recommend their support. It seems much easier to connect directly with someone with a deep understanding of the product rather than other companies where you basically have to make an airtight case that it is some kind of non-standard issue that can't be solved with existing documentation. Palo Alto digs deep and helps with advanced troubleshooting to get things working.
February 26, 2020

Traps will trap malware

Score 10 out of 10
Vetted Review
Verified User
Incentivized
Traps are used by all of the endpoints (notebook & VDI) in our organization. This is done to mitigate the risk from malware attack, zero day attack and APT. Previously we utilized a typical anti-virus agent for protection from known malware. However since Q1 last year and based on the threat trends, we discovered it's not enough just to rely on the known malware/traditional anti-virus solution.
  • Able to block malicious child-process run on the endpoint
  • Able to block executed files which hashes are malicious
  • Able to block process that employs malicious behaviour
  • Proven to be able to block zero-day exploits
  • We encountered some glitch in a certain version of the agent. When we deployed newer version, the policy set on the previous version was white-listed/overwritten.
  • Moving to encrypted based connection (communication between agent to server) is troublesome, coz we need to uninstall the agent first.
  • Need to have a more flexible reports/dashboard where we can customize it
  • We feed Traps log to our SIEM, however the information sent to the SIEM was not complete, but we need to investigate more probably some faults are on us
If protection from known and unknown malware or suspicious process / files are the target, than Traps will address that. It has been proven by us numerous times that Traps are able to block malicious behaviours being run in the files, as well it can prevent zero-day exploits from hitting our organization.
  • No ransomware has sucessfully impact our endpoints, this has saved us hundreds if not millions of dollars lost
  • Users are now more aware of what files/processes that are malicious are being run, this give a good education on to the users
  • the cost of implementation is relatively average, compares to competitor
At that time, we could not find other solutions that could compete with Traps. Most of the solutions presented to us are traditional anti-virus. While traps do not rely on the signature of malware but more on the suspicious behaviour or method used. This gave Traps a lot of advantage that we fine could address our needs. Even now, we are reviewing to replace completely the traditional anti virus.
The team that supports us are tremendous, they have helped us in upgrading the versions. The upgrade didn’t go on smoothly however their support to fix the issues are great. And lots of help from them to advice us on better use the Traps. Exceptional supports have been given to us by the team.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We had previously used a local server-based agent before Traps. We have a Palo Alto firewall with subscriptions to URL filtering, Wildfire, and threat prevention so the systems were separated. Traps was an incredibly easy install that integrates with the rest of the Palo Alto Suite. I no longer have to whitelist our old agent and update that server. Everything is cloud-based so updates are seamless.
  • Cloud-based.
  • Simple to install.
  • Email alerts when issues are found not just a daily summary report.
Great for employees that have devices off-site frequently. Easy for a small IT staff to use. Integrates great with the rest of Palo Alto. Works great for Windows and Macs.
  • Cheaper than an on-premise server.
  • Takes less time.
Traps provided us a cloud-based solution that makes life much easier.
Simple, easy, and efficient
Return to navigation