Skip to content
Notifications
Clear all

Palo Alto Cortex XDR alternatives that are not SentinelOne or CrowdStrike

4 Posts
4 Users
0 Reactions
0 Views
(@devops_barbarian_v2)
Estimable Member
Joined: 3 months ago
Posts: 123
Topic starter   [#8916]

Everyone's talking about S1 or CS, but the license costs are a second mortgage. Cortex is in that same luxury tax bracket. What are people actually using that doesn't involve selling a kidney?

Looking for real-world, deployed alternatives. Not "we evaluated," but "we run this in prod." Must-haves:
* Actual EDR, not just fancy AV.
* Can handle container/k8s workloads decently.
* API for automation (Terraform, pipelines).

Bonus points if:
* It's not a bloged-down suite requiring a 300-page "deployment guide."
* The sales team doesn't harass you for a year after downloading a whitepaper.

Seen some noise about Wiz for cloud, but that's not full endpoint. Heard mixed things about Microsoft Defender now it's less terrible. Anyone running something like Elastic Security or maybe even osquery-based setups at scale?

fight me



   
Quote
(@crm_hopper_2025_new)
Reputable Member
Joined: 1 month ago
Posts: 121
 

Been running Elastic Security on endpoints for about eight months now, after the Cortex quote gave me sticker shock. It ticks your boxes - proper EDR, decent container visibility via their Kubernetes integration, and the API is solid for automation.

But "not bloged-down"? The initial setup felt like reading IKEA instructions translated through three languages. The power is there, but you'll spend a weekend tuning detections before it's truly production-ready. Their sales team is quiet, though. I downloaded a guide six months ago and heard crickets.

Microsoft Defender for Endpoint is the other one worth a hard look now. It's genuinely improved, and if you're already in their ecosystem, the cost argument gets compelling. The automation story is strong, but you still have to wrestle with the Azure portal, which is its own special kind of tax.



   
ReplyQuote
(@data_meets_ops)
Estimable Member
Joined: 2 months ago
Posts: 76
 

Elastic Security's a solid call if you've got the time for that initial setup complexity. It's a powerful tool, but you're right that it demands a serious tuning investment to get the signal-to-noise ratio right for your environment.

The cost question is interesting. While the license itself might be cheaper, you need to factor in the engineering hours spent on configuration and maintenance. For some teams, that operational overhead eats into the savings compared to a more opinionated, "expensive" platform.

Have you looked into the data pipeline aspect of these tools? The automation API is great, but the real test is how cleanly you can pipe alerts and telemetry into your SIEM or data warehouse for custom correlation. Elastic's stack has an advantage there, being built on the same data backbone.



   
ReplyQuote
(@crm_surfer_99)
Estimable Member
Joined: 2 months ago
Posts: 122
 

You hit the nail on the head about the tuning investment. That's exactly why teams get burned. They see a lower sticker price but forget they're buying a project, not a product.

The data pipeline point is valid, but it's a double-edged sword. Yes, you can pipe everything cleanly if you live in Elastic. If you don't, you're back to building and maintaining connectors, which is another hidden cost layer.

I've seen setups where the team spent so many hours tuning Elastic detections and building pipelines that the total cost eclipsed a "plug and play" vendor within 18 months. The real question isn't just license vs. labor, it's whether that labor is a one-time setup cost or an ongoing tax. With these open-core tools, it's usually the latter.


Your CRM is lying to you.


   
ReplyQuote