Cortex XDR is an extended detection and response platform from Palo Alto Networks for enterprise endpoint protection, threat detection and incident response. Pricing is quote-only; MSPs require contacting sales for per-endpoint or per-user rates.
Listing updated . Checked by MSP Software .
Cortex XDR is an extended detection and response platform from Palo Alto Networks designed for enterprise security operations and cross-domain threat investigation. The platform combines endpoint detection and response with correlated threat data from network, cloud, identity and email sources to investigate and remediate cyberattacks across an organisation's entire attack surface. Cortex XDR delivers 99% threat prevention according to 2025 AV Comparatives testing and achieved 100% detection with zero false positives in MITRE ATT&CK evaluations round 6 for known and zero-day threats.
The platform runs on Windows, macOS, Linux, iOS and Android endpoints, deployable as cloud-based Software-as-a-Service or on-premises via Broker VM for restricted networks and air-gapped environments. Cortex XDR includes optional 24/7 managed detection and response through Unit 42, Palo Alto's threat research team with analysis of 30 million malware samples daily and access to 500 billion daily events. MSPs can add proactive threat hunting, dedicated incident response and guided remediation as managed services to supplement the self-service platform. The platform integrates with Palo Alto Networks firewalls and network security appliances, Prisma Access for zero trust connectivity and secure remote access, WildFire for sandbox malware analysis and detonation, and third-party security tools through RESTful API and Broker VM architecture for data collection from restricted network segments.
Cortex XDR uses AI-driven behavioral detection to identify threats including zero-day exploits, fileless malware and process hijacking. Automated remediation workflows coordinate response actions across multiple endpoints, and the Cortex AgentiX Assistant uses adaptive AI agents to automate threat investigation and reduce mean time to respond from hours to minutes. Rollback to pre-attack state allows organisations to restore systems after incident resolution. Pricing is quote-only and not published on Palo Alto's website; MSPs should contact sales to request per-endpoint or per-server pricing details and volume discounts. Cortex XDR is typically marketed to large enterprises and advanced security operations centres rather than small to mid-market MSPs, though larger MSPs managing high-security customer environments may adopt it for clients subject to strict compliance or incident response requirements.
Cortex XDR targets enterprise security operations and is quote-only pricing, which suits large MSPs with mature security practices rather than generalist MSPs. It stands apart from Defender for Endpoint and Crowdstrike Falcon through correlated data from network and cloud alongside endpoints, though that same breadth requires more infrastructure setup. Cortex XDR's strength is the managed MDR option through Unit 42 and the threat hunting console for organisations that want human-led investigation alongside automation. Confirm pricing per endpoint or per user on a sales call, and check whether your stack (RMM, SIEM, ticketing) has documented integrations before committing.
| Feature | Supported | Note |
|---|---|---|
| Behavioural detection | yes | AI-driven behavioral detection identifies zero-day exploits, fileless malware, and process hijacking |
| Automated remediation | yes | Automated remediation workflows and Cortex AgentiX adaptive agents for coordinated response |
| Rollback to pre-attack state | yes | Rollback to pre-attack state capability for incident recovery |
| USB and device control | yes | USB and device control policies enforced through Cortex XDR Agent |
| Application allow-listing | yes | Application allow-listing and application-level threat prevention |
| Offline protection | yes | Endpoints protected when offline with local threat prevention engine |
| Threat hunting console | yes | Dedicated threat hunting console for proactive investigation; additional human-led hunting available via Unit 42 managed service |
| Managed MDR add-on | yes | Managed detection and response available through Unit 42 with 24/7 SOC, threat hunting, and incident response |
| SIEM and SOAR integration | yes | Integrates with third-party SIEM and SOAR platforms via API and data connectors |
| RMM integration | unknown | No direct documented RMM integration; works alongside RMMs through API and Cortex ecosystem |
| macOS support | yes | Full macOS endpoint support via Cortex XDR Agent with dedicated iOS app |
| Linux support | yes | Full Linux endpoint support via Cortex XDR Agent with kernel module version compatibility guide |
Cortex XDR pricing is quote-only and not published on Palo Alto Networks' website. MSPs report that Cortex XDR is typically priced per endpoint for security operations. Exact per-endpoint rates, volume discounts, and whether server endpoints incur higher fees than workstation endpoints depend on your specific deal and must be discussed with a Palo Alto sales representative. Confirm the unit and ask whether the quote includes managed detection and response through Unit 42 or endpoint protection only.
Cortex XDR itself provides the detection and response platform, but 24/7 human monitoring and management is available as an add-on managed detection and response service through Unit 42, Palo Alto Networks' threat research team. The Unit 42 MDR service includes 24/7 SOC triage and monitoring, proactive threat hunting, and incident response support. This is typically sold as a separate managed service tier on top of the base Cortex XDR licence.
Cortex XDR runs on Windows and macOS endpoints through the main Cortex XDR Agent, with full support for recent kernel versions on Linux servers and workstations. The platform also includes dedicated agents for iOS and Android mobile endpoints, giving MSPs the ability to detect threats across employee devices. On-premises deployment is available via Broker VM for networks that require air-gapped or restricted connections to the cloud.
Cortex XDR integrates with Palo Alto Networks firewalls, Prisma Access for zero trust connectivity, and third-party security tools via API. Dedicated documented integrations with major RMM platforms such as NinjaOne or Datto RMM are not listed on Palo Alto's public integration pages; however, the platform's API and Broker VM architecture support custom integrations. MSPs should confirm with Palo Alto sales whether your specific RMM or PSA has a pre-built connector or requires API-level integration work.
Cortex XDR trials and demos are typically available through Palo Alto Networks' sales process. Contact a Palo Alto sales representative to discuss your organisation's security needs and request an evaluation environment or proof-of-concept deployment. Given Cortex XDR's enterprise focus and complex integration requirements, trial deployments are usually arranged on a case-by-case basis rather than self-service sign-ups.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review