All tools
EDR/XDRUses AI for security

Cortex XDR

By Palo Alto Networks

Palo Alto Networks' detection and response platform, one of the earliest products marketed as XDR. Correlates endpoint agent telemetry with network, cloud, and identity data for AI-driven detection and automated root-cause analysis, with Unit 42 available as a managed option.

Verified Sources: paloaltonetworks.com, docs-cortex.paloaltonetworks.com, paloaltonetworks.com

Product type
Software
Deployment
SaaSAgent
Organization size
Mid-marketEnterprise
Pricing tier
$$$

AI security profile

Uses machine learning and analytics to detect anomalous behavior, correlate cross-domain attack stories, and support automated investigation and response.

Behavioral AI detectionAI-assisted investigationAutonomous response
New to EDR/XDR? The flight recorder for every laptop and server — a beginner lesson on how this kind of tool works.

Capability checklist

EDR/XDR

How Cortex XDR measures up against the full Endpoint & Extended Detection and Response taxonomy.

Behavioral detection — supported
Flags malicious behavior patterns rather than known file signatures.
Threat hunting — supported
Lets analysts query historical endpoint telemetry for signs of compromise.
Remote response actions — supported
Isolate a host, kill a process, or pull files from an endpoint remotely.
Ransomware rollback — not supported
Restores files encrypted or modified by detected ransomware.
Cross-surface correlation (XDR) — supported
Correlates endpoint signals with identity, email, and cloud telemetry.
Managed detection option — supported
Vendor-operated 24/7 monitoring available (MDR).

Alternatives

Other Endpoint & Extended Detection and Response tools with overlapping capabilities, sized for similar teams.

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.