Palo Alto Networks Inc.

09/23/2025 | News release | Distributed by Public on 09/23/2025 07:10

Cortex XDR is the Only Endpoint Security Market Leader to Achieve 99% in Bo...

In today's cybersecurity landscape, achieving superior protection doesn't have to come at a premium. The AV-Comparatives 2025 EPR Product Validation Report1 demonstrates that Palo Alto Networks Cortex XDR, using only our lowest-cost, prevention-focused license (XDR Prevent), delivers exceptional results. We're excited to share that among endpoint security market leaders2, Palo Alto Networks was the only vendor to achieve 99% in both threat prevention and response, all while offering a lower total cost of ownership (TCO). Read the full report here3.

The product was resilient against various attack vectors, including executables, scripts, installers, add-ins, and USB-propagated payloads. According to AV-Comparatives, Cortex XDR is a user-friendly and intuitive platform that gives security analysts the rich, contextual data they need to prioritize threats quickly.

A Multi-Layered Defense That Prevails

The test was conducted in three phases, aligning with the MITRE ATT&CK Framework, which simulates a complete cyberattack from start to finish in three stages. This structured approach provides a holistic view of a security solution's effectiveness across the entire attack chain.

  • Phase 1: Compromise & Foothold assessed a product's ability to prevent an attacker from gaining initial access and executing malicious code.
    • Cortex XDR provided an active response to 98% of scenarios and a passive response for the remaining 2%. It automatically stops threats at the very beginning of an attack chain, which is a critical capability for preventing attacks before they move laterally to other systems.
  • Phase 2: Internal Propagation measured how well the product detects and stops the attacker as they try to move laterally within the network.
    • Out of 50 scenarios, only one scenario progressed from Phase 1 to Phase 2, but Cortex XDR detected and blocked it in this phase. Cortex XDR acts as a strong initial barrier, and even when a threat manages to get past that barrier, it can still detect and neutralize it before the adversary can achieve their objective.
  • Phase 3: Asset Breach evaluated whether the product can prevent the attacker from achieving their ultimate objective, such as stealing data or sabotaging systems.
    • Cortex XDR prevented all threats from reaching Phase 3, so adversaries could not reach their ultimate goal of exfiltrating or encrypting data.

Operational Accuracy and Workflow Delays

AV-Comparatives also assessed costs related to operational accuracy and workflow delays.

  • Operational Accuracy Costs: Cortex XDR's high operational accuracy translates to minimal hidden costs for a business. In the report's financial model, Cortex XDR was assigned "Low" costs for this metric, demonstrating its ability to protect against real threats while avoiding the productivity and overhead penalties associated with false alerts.
  • Workflow Delay Costs: Costs arise when an end user's activity is stalled because a security product is analyzing a file, for example, by sending it to a vendor's online sandbox for further analysis. The AV-Comparatives report states that Palo Alto Networks had no costs related to workflow delays. The product's efficiency and speed meant it did not cause significant delays when analyzing scenarios.

Uncompromising Protection, Unmatched Value

Ultimately, the AV-Comparatives 2025 EPR Product Validation Report offers irrefutable evidence that Palo Alto Networks Cortex XDR is a top-tier endpoint security solution, redefining the balance of superior protection and cost-effectiveness. The product's consistent excellence in the AVC EDR Test and Anti-Tampering Test further solidifies its position as a market leader, proving that its defenses are not only effective but also highly resilient.

For a SecOps team, this translates directly to a significant reduction in alert volume, minimized manual investigations, and the confidence that advanced threats are stopped long before they can impact the business. This validation proves that choosing Cortex XDR is an investment in both uncompromising security and streamlined operational excellence.

For a deeper dive into our performance in the AVC EDR and AVC Anti-Tampering tests, we encourage you to read our detailed blog post: Cortex XDR is the Only Endpoint Security Market Leader Certified in Both AVC EDR Detection and Anti-Tampering Tests.

Reference:

1 EPR Comparative Report 2025

2 Market leader is defined as vendors who were named leaders in the 2025 Gartner EPP Magic Quadrant

3 EPR Product Validation Report 2025-Palo Alto Networks

Palo Alto Networks Inc. published this content on September 23, 2025, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 23, 2025 at 13:10 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]