Traps/Cortex XDR Review
Updated March 25, 2023

Traps/Cortex XDR Review

Jeff Nichols | TrustRadius Reviewer
Score 1 out of 10
Vetted Review
Verified User

Overall Satisfaction with Palo Alto Networks Cortex XDR

Traps/now Cortex XDR was being used to provide endpoint protection for our servers and desktops. Traps/Cortex XDR was being used organization wide.
  • It does nothing well
  • Traps/cortex XDR alerts on wide scale commercial apps that are clearly not malicious
  • the Cortex XDR console interface is 5 steps worse than simply bad
  • Frontline support reps are not fluent in spoken English although their written fluency is okay (at best)
  • Integration with our firewalls. What a mistake otherwise
  • Traps had an agent upgrade get "stuck" that required me to manually reboot servers into safe mode to remediate it. Traps/Cortex ROI is by far negative. I'm pretty well-paid. Requiring multiple hours of my time to remediate your [bad] product entirely destroys any benefit.
  • Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)
traps/cortex xdr is inferior in every respect

Do you think Palo Alto Networks Cortex XDR delivers good value for the price?

No

Are you happy with Palo Alto Networks Cortex XDR's feature set?

No

Did Palo Alto Networks Cortex XDR live up to sales and marketing promises?

No

Did implementation of Palo Alto Networks Cortex XDR go as expected?

No

Would you buy Palo Alto Networks Cortex XDR again?

No

If I could give a zero, I would. This is a [bad] product with a bad interface. Support is awful and the product doesn't even come close to living up to the sales pitch. Avoid.

Palo Alto Networks Cortex XDR Feature Ratings

Using Palo Alto Networks Cortex XDR

Day to day, Cortex is easy to use when you have no alerts and when an agent upgrade doesn't go south.

Alerts are far too "clicky", there's too many steps to drilling down to what actually happened to trigger an alert. Investigating alerts in Cortex takes about 5x longer than it should.
ProsCons
Technical support not required
Familiar
Do not like to use
Not well integrated
Inconsistent
Cumbersome
  • When nothing goes wrong with agents and there are no alerts, it's a breeze
  • Agent updates hang which also kills the uninstall password. The only solution is to boot to safe mode to run an uninstall utility
  • The number of steps it takes to drill into an alert is annoying