Article

Cortex XDR: Leader in endpoint securityaccording to MITRE ATT&CK® Enterprise Evaluations

Palo Alto Networks is the first vendor in history to achieve: 

    100% technician-level detection with no latency or configuration changes.
    100% detection of macOS and Linux attacks on extended attack surfaces.
    Highest attack prevention rate among all vendors with zero false positives that could disrupt critical business processes.

Cortex XDR® achieved an unprecedented result of 100% detection with technician-level detail

Technician-level detection is the highest quality in MITRE tests. It reveals what happened during the attack and how it unfolded in the environment. This gives security analysts the key information they need to stop the breach.

Notably, Cortex XDR achieved this result without any configuration changes or delays, detecting every stage of the attack in real time without manual intervention. In contrast to Palo Alto Networks, two-thirds of vendors detected less than 50% of the attack stages. This shows that the 2024 assessment was more thorough.

Illustration
Illustration

Cortex XDR showed the lowest false positive rate

MITRE ATT&CK evaluates attack detection and prevention because endpoint security aims to prevent as many attacks as possible and then detect the rest as quickly as possible. Cortex XDR does an excellent job of both.

In the sixth round, Cortex XDR prevented 8 out of 10 stages of the attack without any false positives, which can lead to the risk of stopping critical business processes and significant financial losses. Cortex XDR has demonstrated an unmatched combination of efficiency and accuracy, making it the ideal endpoint security solution for the world's largest and most demanding organizations.

By combining detection and prevention scenarios into a single view of full attack coverage in the 2024 evaluation, Cortex XDR delivered the best security results across the enterprise. This enables security teams to stay ahead of attacker tactics and techniques.

Illustration

About MITRE ATT&CK® Enterprise Evaluations  

The MITRE ATT&CK® Enterprise Evaluations are the most rigorous tests in the endpoint security industry. They measure the products’ ability to withstand advanced threats by simulating real-world attacks.

MITRE ATT&CK Enterprise Evaluations raises the bar. By simulating real-world attacker tactics and introducing false positive testing, the evaluation now challenges security solutions to demonstrate accuracy in detecting and preventing attacks across platforms.

Key features of the updated assessment:

    Focus on ransomware: a detailed examination of ransomware-as-a-service (RaaS) tactics.
    DPRK threats for macOS: simulation of modular malware and credential theft techniques.
    Realism of attackers' actions: testing the abuse of legitimate tools and privilege escalation methods.
    False-positive testing: assessing the accuracy of distinguishing real threats from noise.

Do you want to get consultation on this solution? Fill in the form below

Thank you!

We'll contact you.

Can't send form.

Please try again later.