shouldiuse.io

Categories

VERDICT

Cortex XSOAR Review

Depends

Should I use Cortex XSOAR?

Security orchestration, automation and response (SOAR) platform by Palo Alto Networks - xsoar.pan.dev

· 23 hours ago

Buy only if you run a large SOC with dedicated automation engineers and Palo Alto-sized budget. Small teams or anyone wanting transparent pricing and easy exit paths should look elsewhere.

Confidence

Medium. Based on 40+ public sources; no public rating averages or price figures found.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo usable evidence in sources
  • Security posture

Pricing

Enterprise subscription (XSOAR, XSOAR-TIM variants)

Not publicly listed; quoted via partners and marketplace points

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Large SOCs with dedicated automation engineers
  • Enterprises already committed to the Palo Alto stack
  • Compliance-driven breach-notification workflows (HIPAA, US state laws)
  • Teams consolidating case management and orchestration

Not for

  • Small security teams without automation engineers
  • Startups needing simple alerting — massively overkill
  • Buyers wanting self-serve, transparent pricing
  • Anyone unwilling to maintain sprawling, multi-hundred-node playbooks

Gotchas - check before you buy

high

Migration out is hard — a single phishing playbook had 250 nodes

medium

Pricing is opaque: marketplace points, partner quotes, consulting SKUs; expect procurement friction

medium

Palo Alto pushes XSIAM as the successor; classic SOAR buyers face roadmap risk

low

Support quality unverified; independent reviews of support experience are sparse

Pros and cons

Pros

  • Deep integration marketplace with prebuilt compliance, breach-notification, and CVE-response playbooks
  • Combines case management with orchestration in one platform
  • Proven at enterprise scale in telecom, utility, and developer case studies
  • 2,013 companies detected using it in market data
  • Broad partner ecosystem: Mimecast, Thales, XM Cyber, SecurityScorecard integrations

Cons

  • Public case studies show Lennar and others migrating to Torq
  • One phishing playbook spanned 250 nodes — heavy maintenance burden
  • No transparent public pricing; sold via points and partner quotes
  • Recent CVEs including path traversal and improper validation (2026)
  • Reddit users question real-world success in some deployments

Sources & method

- 16 sources - Actively patched enterprise product, but four cited CVEs since 2021 including path traversal and improper validation in 2026.

official x4review x5security x2news x5
  • CVE-2026-0270 — path traversal, Palo Alto advisory, June 2026.
  • CVE-2026-0274 — improper validation, Palo Alto advisory, June 2026.
  • CVE-2026-0234 — improper verification, Palo Alto advisory, April 2026.
  • CVE-2024-9470 — improper authorization, Authorization flaw tracked publicly; patched by vendor.

Key stats

  • Value for money: 2/5

    Rating

  • Not publicly listed; quoted via partners and marketplace points

    Starting price

  • 16

    Sources

  • Analyzed

  • Value for money: 2/5. Opaque pricing; public exit case studies to rivals
  • Ease of use: 2/5. Cited as legacy SOAR with complexity limits
  • Feature depth: 5/5. Huge marketplace; compliance and CVE playbooks built in
  • Support quality. No usable evidence in sources
  • Security posture: 2/5. Multiple CVEs including unauthenticated command execution (2024)
  • 2,013 companies Detected deployments Bloomberry tech tracking
  • 4 Recent CVEs cited Palo Alto advisories, 2021–2026
  • $10M Largest cited deal US DOT contract, 2023

Pricing

Enterprise subscription (XSOAR, XSOAR-TIM variants)

Not publicly listed; quoted via partners and marketplace points

  • Consumption-style marketplace points model
  • UK G-Cloud listing routes through resellers

Security

Actively patched enterprise product, but four cited CVEs since 2021 including path traversal and improper validation in 2026.

  • CVE-2026-0270 — path traversalPalo Alto advisory, June 2026.⁹
  • CVE-2026-0274 — improper validationPalo Alto advisory, June 2026.
  • CVE-2026-0234 — improper verificationPalo Alto advisory, April 2026.
  • CVE-2024-9470 — improper authorizationAuthorization flaw tracked publicly; patched by vendor.

What users say

Review sites and Reddit call it a capable SOC monitoring and automation tool, while several documented teams have migrated away citing complexity.

“Xsoar is decent.”
Reddit, r/blueteamsec

Companies that use it

  • Sitecore
  • Esri
  • US Department of Transportation15

Companies that could

  • Lennar Corp.12 Uses Torq instead
Full analysis

Based on 40+ public sources; no public rating averages or price figures found.

Enterprise SOAR with deep integrations, opaque pricing, and real migration pain. Big SOC fit; small-team overkill.

Methodology

Based on 40+ public sources; no public rating averages or price figures found.

Read how a report is made.

Sources

  1. review
  2. review
  3. review
  4. review
  5. official
  6. official
  7. ITogether G-Cloud pricing document — XSOAR, XSOAR-TIMassets.applytosupply.digitalmarketplace.service.gov.uk
    official
  8. official
  9. security
  10. security
  11. news
  12. news
  13. news
  14. news
  15. news
  16. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.