Cortex XDR logo

Cortex XDR is an extended detection and response platform from Palo Alto Networks for enterprise endpoint protection, threat detection and incident response. Pricing is quote-only; MSPs require contacting sales for per-endpoint or per-user rates.

Listing updated . Checked by MSP Software .

From the vendor

Cortex XDR is an extended detection and response platform from Palo Alto Networks designed for enterprise security operations and cross-domain threat investigation. The platform combines endpoint detection and response with correlated threat data from network, cloud, identity and email sources to investigate and remediate cyberattacks across an organisation's entire attack surface. Cortex XDR delivers 99% threat prevention according to 2025 AV Comparatives testing and achieved 100% detection with zero false positives in MITRE ATT&CK evaluations round 6 for known and zero-day threats.

The platform runs on Windows, macOS, Linux, iOS and Android endpoints, deployable as cloud-based Software-as-a-Service or on-premises via Broker VM for restricted networks and air-gapped environments. Cortex XDR includes optional 24/7 managed detection and response through Unit 42, Palo Alto's threat research team with analysis of 30 million malware samples daily and access to 500 billion daily events. MSPs can add proactive threat hunting, dedicated incident response and guided remediation as managed services to supplement the self-service platform. The platform integrates with Palo Alto Networks firewalls and network security appliances, Prisma Access for zero trust connectivity and secure remote access, WildFire for sandbox malware analysis and detonation, and third-party security tools through RESTful API and Broker VM architecture for data collection from restricted network segments.

Cortex XDR uses AI-driven behavioral detection to identify threats including zero-day exploits, fileless malware and process hijacking. Automated remediation workflows coordinate response actions across multiple endpoints, and the Cortex AgentiX Assistant uses adaptive AI agents to automate threat investigation and reduce mean time to respond from hours to minutes. Rollback to pre-attack state allows organisations to restore systems after incident resolution. Pricing is quote-only and not published on Palo Alto's website; MSPs should contact sales to request per-endpoint or per-server pricing details and volume discounts. Cortex XDR is typically marketed to large enterprises and advanced security operations centres rather than small to mid-market MSPs, though larger MSPs managing high-security customer environments may adopt it for clients subject to strict compliance or incident response requirements.

Our take

Cortex XDR targets enterprise security operations and is quote-only pricing, which suits large MSPs with mature security practices rather than generalist MSPs. It stands apart from Defender for Endpoint and Crowdstrike Falcon through correlated data from network and cloud alongside endpoints, though that same breadth requires more infrastructure setup. Cortex XDR's strength is the managed MDR option through Unit 42 and the threat hunting console for organisations that want human-led investigation alongside automation. Confirm pricing per endpoint or per user on a sales call, and check whether your stack (RMM, SIEM, ticketing) has documented integrations before committing.

Read the EDR and XDR buying guide

How this listing is researched

Alternatives in EDR and XDR

All EDR and XDR software
SentinelOne Autonomous endpoint detection and response with one-click rollback, per-endpoint annual pricing. No reviews yet · from US$179.99 Trend Vision One Endpoint Security Endpoint protection with EDR, XDR and threat hunting under credit-based licensing. No reviews yet FortiEDR Endpoint detection and response integrated with the Fortinet Security Fabric, quote-only pricing. No reviews yet ESET PROTECT Prevention-focused endpoint detection and response with cloud or on-premises deployment. No reviews yet All alternatives to Cortex XDR

Products that integrate with Cortex XDR

Vulnerability and compliance

More from Palo Alto Networks

Advanced DNS Security Cloud DNS security for Palo Alto firewalls, blocking 157 million malicious domains daily.Idira Privileged access management for human, machine and AI identities with threat detection.

Features

EDR and XDR features
FeatureSupportedNote
Behavioural detectionyesAI-driven behavioral detection identifies zero-day exploits, fileless malware, and process hijacking
Automated remediationyesAutomated remediation workflows and Cortex AgentiX adaptive agents for coordinated response
Rollback to pre-attack stateyesRollback to pre-attack state capability for incident recovery
USB and device controlyesUSB and device control policies enforced through Cortex XDR Agent
Application allow-listingyesApplication allow-listing and application-level threat prevention
Offline protectionyesEndpoints protected when offline with local threat prevention engine
Threat hunting consoleyesDedicated threat hunting console for proactive investigation; additional human-led hunting available via Unit 42 managed service
Managed MDR add-onyesManaged detection and response available through Unit 42 with 24/7 SOC, threat hunting, and incident response
SIEM and SOAR integrationyesIntegrates with third-party SIEM and SOAR platforms via API and data connectors
RMM integrationunknownNo direct documented RMM integration; works alongside RMMs through API and Cortex ecosystem
macOS supportyesFull macOS endpoint support via Cortex XDR Agent with dedicated iOS app
Linux supportyesFull Linux endpoint support via Cortex XDR Agent with kernel module version compatibility guide

FAQ

How much does Cortex XDR cost?
Cortex XDR does not publish a list price. No MSP price reports have been approved yet.
Does Cortex XDR offer a free trial?
There is no free version.
What does Cortex XDR integrate with?
Cortex XDR lists integrations with Palo Alto Networks Firewalls, Prisma Access, WildFire Malware Analysis, Unit 42 Threat Intelligence and Microsoft 365.
What integrates with Cortex XDR?
CyberStrong lists an integration with Cortex XDR.
Is Cortex XDR cloud or on-premises?
Cortex XDR can be run in the cloud or on-premises. Cortex XDR supports a hybrid deployment.
Who is Cortex XDR for?
MSPs report using Cortex XDR at sizes of 51-200 and 200+ technicians.
Is Cortex XDR priced per endpoint, per user, or per server?

Cortex XDR pricing is quote-only and not published on Palo Alto Networks' website. MSPs report that Cortex XDR is typically priced per endpoint for security operations. Exact per-endpoint rates, volume discounts, and whether server endpoints incur higher fees than workstation endpoints depend on your specific deal and must be discussed with a Palo Alto sales representative. Confirm the unit and ask whether the quote includes managed detection and response through Unit 42 or endpoint protection only.

Does Cortex XDR include 24/7 threat monitoring or is that a separate add-on?

Cortex XDR itself provides the detection and response platform, but 24/7 human monitoring and management is available as an add-on managed detection and response service through Unit 42, Palo Alto Networks' threat research team. The Unit 42 MDR service includes 24/7 SOC triage and monitoring, proactive threat hunting, and incident response support. This is typically sold as a separate managed service tier on top of the base Cortex XDR licence.

What operating systems does Cortex XDR support?

Cortex XDR runs on Windows and macOS endpoints through the main Cortex XDR Agent, with full support for recent kernel versions on Linux servers and workstations. The platform also includes dedicated agents for iOS and Android mobile endpoints, giving MSPs the ability to detect threats across employee devices. On-premises deployment is available via Broker VM for networks that require air-gapped or restricted connections to the cloud.

Can Cortex XDR integrate with our existing RMM or PSA?

Cortex XDR integrates with Palo Alto Networks firewalls, Prisma Access for zero trust connectivity, and third-party security tools via API. Dedicated documented integrations with major RMM platforms such as NinjaOne or Datto RMM are not listed on Palo Alto's public integration pages; however, the platform's API and Broker VM architecture support custom integrations. MSPs should confirm with Palo Alto sales whether your specific RMM or PSA has a pre-built connector or requires API-level integration work.

Is there a free trial or demo available for Cortex XDR?

Cortex XDR trials and demos are typically available through Palo Alto Networks' sales process. Contact a Palo Alto sales representative to discuss your organisation's security needs and request an evaluation environment or proof-of-concept deployment. Given Cortex XDR's enterprise focus and complex integration requirements, trial deployments are usually arranged on a case-by-case basis rather than self-service sign-ups.

Cortex XDR reviews

Reviews are moderated. How reviews work.

Be the first MSP to review Cortex XDR

Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.

Write the first review

Sign in or create an account

Use your work email to review tools, share pricing and manage your vendor profile.

By continuing, you agree to our terms and acknowledge our privacy policy.