Palo Alto Networks Cortex XDR vs. Trellix Helix

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Palo Alto Networks Cortex XDR
Score 8.4 out of 10
N/A
Cortex XDR (formerly Traps) replaces traditional antivirus with multi-method prevention, a proprietary combination of malware and exploit prevention methods that protect users and endpoints from known and unknown threats.N/A
Trellix Helix
Score 7.0 out of 10
Enterprise companies (1,001+ employees)
Trellix Helix (formerly FireEye Helix) is a SIEM solution providing a non-malware threat detection solution.
$0
Events per second
Pricing
Palo Alto Networks Cortex XDRTrellix Helix
Editions & Modules
No answers on this topic
Helix Console
$0
Events per second
Helix Enterprise
$0
Events per second
Offerings
Pricing Offerings
Palo Alto Networks Cortex XDRTrellix Helix
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
Palo Alto Networks Cortex XDRTrellix Helix
Features
Palo Alto Networks Cortex XDRTrellix Helix
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Palo Alto Networks Cortex XDR
-
Ratings
Trellix Helix
8.5
Ratings
9% above category average
Centralized event and log data collection00 Ratings8.50 Ratings
Correlation00 Ratings8.00 Ratings
Event and log normalization/management00 Ratings8.50 Ratings
Deployment flexibility00 Ratings8.40 Ratings
Integration with Identity and Access Management Tools00 Ratings8.90 Ratings
Custom dashboards and workspaces00 Ratings8.10 Ratings
Host and network-based intrusion detection00 Ratings9.00 Ratings
Best Alternatives
Palo Alto Networks Cortex XDRTrellix Helix
Small Businesses
SentinelOne Singularity
SentinelOne Singularity
Score 8.7 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.7 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Palo Alto Networks Cortex XDRTrellix Helix
Likelihood to Recommend
9.0
(0 ratings)
9.0
(0 ratings)
Usability
7.0
(0 ratings)
-
(0 ratings)
Support Rating
10.0
(0 ratings)
9.0
(0 ratings)
Ease of integration
-
(0 ratings)
8.1
(0 ratings)
User Testimonials
Palo Alto Networks Cortex XDRTrellix Helix
Likelihood to Recommend
In a scenario where EDR is a requirement or necessity XDR performs well with or without a SIEM. There are millions of events and logs to parse through and XDR is capable of handling the large load. On top of the large data that is being parsed, features such as Live Terminal, File Retrieval, OS support, and general Metrics, the tool has room to grow and provide a lot for a Security team or organization. Incident Response is a great example of how XDR can shine
Read full review
Overall, we've had a great experience with FireEye Helix and would recommend it to organizations looking to improve their operational security. We've found Helix to be a great way to collect and analyze revenant security events and take action. Having a single pane of glass makes this process much more efficient. Prior to moving to FireEye Helix, we had different teams sending data to different applications, which resulted in confusion and critical data being missed.
Read full review
Pros
  • Great tool to help analyze and identify unknown malicious software on workstations, servers, and mobile devices.
  • Integration with Panorama help to quickly and efficiently identify potential malicious files.
  • Integration with Wildfire helps to quickly deploy signatures not only to endpoints but to firewalls as well.
Read full review
  • Detection of advanced threats.
  • Easy integration with cloud resources and our existing security tools thus enhancing performance.
  • Easy deployment with great threats intelligence capabilities.
Read full review
Cons
  • We encountered some glitch in a certain version of the agent. When we deployed newer version, the policy set on the previous version was white-listed/overwritten.
  • Moving to encrypted based connection (communication between agent to server) is troublesome, coz we need to uninstall the agent first.
  • Need to have a more flexible reports/dashboard where we can customize it
  • We feed Traps log to our SIEM, however the information sent to the SIEM was not complete, but we need to investigate more probably some faults are on us
Read full review
  • Overly complex platform
  • Multiple logins needed for various tools--leads to confusion
  • Costs can add up
Read full review
Usability
Cortex XDR does a very good job of blocking suspicious and threatening items. However, as with all software of this nature, it will sometimes block known-good items. The difficulty is in manually whitelisting these known-good items. The interface to whitelist is confusing even for a seasoned IT professional and has been the single most frustrating experience of using Cortex XDR
Read full review
No answers on this topic
Support Rating
The support we receive from Palo Alto is one of the best aspects of Traps. It is very easy to recommend their support. It seems much easier to connect directly with someone with a deep understanding of the product rather than other companies where you basically have to make an airtight case that it is some kind of non-standard issue that can't be solved with existing documentation. Palo Alto digs deep and helps with advanced troubleshooting to get things working.
Read full review
We've been fairly happy with FireEye Helix support overall. Most issues are resolved the same day the case is opened.
Read full review
Alternatives Considered
Traps provided us with a cloud-based platform that made our lives a lot simpler. Nothing like Traps exists in the market and I've never used anything like it. Others, on the other hand, were a lot slower to respond. Malwarebytes and other enterprise-level malware software are also available, but they do not fall under the same heading.
Read full review
It offers extensive visibility thus easy detection of threats and easy mitigation practices. Utilization of its threats intelligence capabilities thus early detection of incidents and maximization of security investments. Offers great integration of cloud resources with existing security tools thus ensuring seamless performance and all-time security for the organizational resources.
Read full review
Return on Investment
  • Traps has paid for itself in time saved re-imaging PCs to clean them
  • Traps gives us a lot of good insight on what's being run on our endpoints
  • Traps is a great extra layer of security for our end users and minimizes malware outbreaks, which in turn minimizes downtime
Read full review
  • Helix has had a significant impact on CSOC visibility efforts across the organization.
  • Helix fills the logging and alerting gaps that are missing across the infrastructure side.
  • Having a single pane of glass allows teams to more efficiently run incidents. Additionally, Helix is integrated with ServiceNow providing enhanced and efficient case management for all Helix alerts.
Read full review
ScreenShots

Palo Alto Networks Cortex XDR Screenshots

Screenshot of a Cortex XDR overviewScreenshot of a view of the Cortex XDR dashboardScreenshot of a view of the Cortex XDR dashboardScreenshot of a view of the Cortex XDR dashboard

Trellix Helix Screenshots

Screenshot of Helix Cloud IntegrationsScreenshot of Helix Asset Alert Correlation