Listing Thumbnail

    Cisco XDR

     Info
    Deployed on AWS
    Cisco XDR, an eXtended Detection and Response security solution, collects and correlates data across email, endpoints, servers, cloud workloads, and networks, enabling visibility and context into advanced, multi-vector threats. Cisco XDR integrates with AWS services and has 53 AWS-specific threat detections with new detections being introduced all the time. Threats can then be analyzed, prioritized, hunted, and remediated to prevent data loss and security breaches. Cisco XDR quickly identifies and stops the most complex attacks on AWS with an open XDR approach.
    4.4

    Overview

    Cisco XDR integrates data from multiple security technologies and leverages AI for enhanced threat detection, streamlined security operations, and improved efficiency to provide a unified defense approach. Designed to address the challenges faced by security practitioners, it offers a cloud-native, open approach that integrates data and telemetry generated from security tools across your stack and applies AI and analytics to arrive at correlated detections.

    Cisco XDR has developed an AWS-specific threat detection library to help users quickly identify attacks and remediate threats. Cisco XDR is the core component of Cisco Breach Protection Suite, which helps secure your business with simplified security operations and accelerated response through AI-powered defense.

    With Cisco XDR, security teams can detect threats across the environment by correlating multiple security vectors, including vital network, email, endpoint, application, and cloud insights. Cisco XDR provides unified threat detection and response by integrating the broad Cisco portfolio of solutions, along with several third-party vendor solutions (for the complete list, see Cisco XDR integrations). It enriches incidents with added context and asset insights using the underlying threat intelligence from Cisco Talos®, one of the most trusted private threat intelligence organizations in the world, as well as dozens of third-party threat intelligence tools. Through clear prioritization of incidents, Cisco XDR reduces false positives and provides the shortest path from detection to response.

    Highlights

    • Identify and stop even the most complex attacks, whether they originate on-premises or in AWS, with a network-centric open XDR approach powered by a simple, built-in Network Detection and Response (NDR) to gain comprehensive visibility.
    • Natively integrate network data from Meraki MX devices to gain clear visibility beyond what EDR-based tools provide, so defenders can take more informed and timely actions.
    • Remediate threats quickly and decisively with AI-guided response and automation that levels up the performance and effectiveness of your security operations team.

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. Request a private offer to receive a custom quote. Sign in to view any offers that have been extended to you.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    You can reach for the Cisco XDR support at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    10 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    10%
    80%
    10%
    0%
    0%
    0 AWS reviews
    |
    10 external reviews
    External reviews are from G2  and PeerSpot .
    Shourya TejReddy KSS

    Endpoint insights have improved incident investigations but performance still needs optimization

    Reviewed on Dec 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    As a security consultant, I use multiple SIEM  and XDR  solutions, so cumulatively, I can say I have used Cisco XDR  for around one year.

    What is most valuable?

    Cisco XDR  is built primarily for enterprise endpoint security, integrated onto endpoints with logs integrated into SIEM , and it is used for security investigations, malware impact investigation, and tracking particular security incidents through integration of different logs, where endpoint logs are very important, providing detail about processes run by potential malware and any call-outs made to command and control.

    The best features of Cisco XDR  include its ability to integrate with multiple SIEM platforms, with visibility coming from a lot of Cisco's devices, and it syncs well with other XDRs and endpoint defenses such as Microsoft Defender, SentinelOne, and CrowdStrike, integrating well with other vendor products.

    Cisco XDR helps prevent data loss during ransomware attacks by integrating with multiple levels of security, tying to identity management systems, and allowing placement of blocks at the endpoint level, which provides an additional layer of security, optimizing for detecting and preventing data loss based on how well the rules are placed and how well integrations are done for overall visibility of different stages of intrusion or data loss.

    What needs improvement?

    Improvements in Cisco XDR revolve around performance. The less performance it utilizes to run at high configuration levels, the better it becomes, so all vendors need to continue working on keeping resource utilization low while providing optimum performance, which is a defining point or deal breaker.

    For how long have I used the solution?

    I have used Cisco XDR for around one year.

    What do I think about the stability of the solution?

    Stability is dependent on integration, since product-wise it is very stable, but performance-wise it is acceptable, so I would give it a rating of six.

    What do I think about the scalability of the solution?

    In terms of scalability, I rate it as the best. For scalability, I would give it an eight out of ten.

    How are customer service and support?

    I would rate technical support as a seven to eight because it is very great in current times. If I had to decide between seven or eight, I would say a seven.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I mostly use the AI assistance and automation feature for reporting, not for analysis because I do not trust AI for conclusions, only for inputs and reporting, which is how the AI component is utilized.

    I do use the feature for prioritizing incidents across multiple security controls, but that needs to be configured, as I work mostly at the governance level for information security as a consultant, so the effectiveness depends on how well it is integrated and what the policy and operations are.

    Cisco XDR streamlines incident response through its functionalities, being top of the stack and comparing well with other providers such as Palo Alto or the recently developed open-source Wazuh , which makes it very good.

    I compare Cisco XDR with top-of-the-stack options available such as Palo Alto, Sophos XDR, and Secureye, an Indian company, and it lines up with all of them, providing a lot of other devices and software with Cisco's easy integration, making it one of the best for visibility.

    I would definitely suggest Cisco XDR for enterprises and MSMEs who have a specified budget to fortify their defenses, and it stacks up well against other offerings in the market, naming CrowdStrike as somewhat better due to its knowledge base and R&D, with Tanium  ranking just under it, making Cisco XDR probably number three in the XDR market.

    I rate this review overall as a seven out of ten.

    Joseph Houghes

    flexible reporting and analytics boost data-driven security responses

    Reviewed on Jun 11, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My primary use case for Cisco XDR  is log review from devices, and then doing analytics for quicker responses in the future to security incidents.

    What is most valuable?

    The feature I appreciate the most about Cisco XDR  is the flexibility for a user to be able to create their own reporting and dashboards. I would say I got to stop beta testing myself. I am testing what can be customized the most with it. Being able to ingest all the analytics and make it something that's either meaningful to them or to their own leadership is a big plus. It's not just what the product is at launch; you have the ability to customize and make it useful to your business to actually get real, purposeful information out of just a swamp of data.

    The features of Cisco XDR  have actually benefited the organization significantly by allowing us to do the outputs of specific data and even filtered subsets of the data. We can do the same reporting but only deliver in either reports or dashboards the information about the systems that a specific team is responsible for, or the larger teams that multiple departments or IT silos roll up into. We're basically able to just modify the filters and have the same reports in the same dashboards where it's all the same; 99% of the work is the same.

    What needs improvement?

    To improve Cisco XDR , I can't think of anything super meaningful because a couple of features I'm interested in are actually ones that integrate with Duo, but that's not widely used. I'm fine with the features that are on their way into the product based on the roadmap I've seen, so I can't suggest any other features from a user perspective.

    For how long have I used the solution?

    I have been using Cisco XDR for 18 months.

    What do I think about the stability of the solution?

    My assessment of the stability and reliability of Cisco XDR is positive. Any perceived performance issues were traced back to specific users attempting to process too much data at once. We clarified optimal procedures, which encouraged people to interact with the system more efficiently and avoided traditional outdated workflows.

    How are customer service and support?

    My experience with customer service and technical support has been fantastic. We've only needed to contact them twice for our security team, and each time was mainly to understand how something was functioning.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Prior to adopting Cisco XDR, we were using four products, three of which stayed in evaluation while dropping others. We recognized that Cisco XDR could replace multiple systems, making it an appealing choice.

    How was the initial setup?

    My experience with the deployment of Cisco XDR was that it was simple. During the proof of concept, the setup was straightforward, and for the most part, we provided systems access to the security team, allowing them to tie everything together without needing additional help.

    What was our ROI?

    I have expanded the usage of Cisco XDR. The process of expanding usage has been smooth and easy. Since we frequently work with Cisco, it makes it hassle-free to justify needing more and explaining why.

    Having proven its value and capability to quickly ramp up our operations has simplified expanding licensing and replacing systems. I know of several incidents that demonstrate Cisco XDR's return on investment (ROI). Two customers faced a network breach and a bad configuration incident, but unlike in the past where recovery took days, they managed to shut down access points quickly. Their ability to divert a crypto attack within 30 minutes saved them from a multi-day outage that previously had entire staff doing nothing but recovering systems.

    Within our teams, I absolutely see the ROI with Cisco XDR. We have effectively identified gaps in our incident response processes and what information we need. Security is one of the most cost-effective insurance policies, and Cisco XDR serves as our magnifying glass to understand our security contract better. It has provided us with a tool that enhances visibility and interactivity among our teams.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing has been intriguing. I used to work for a Cisco partner, and I still have friends there with whom I discuss comparisons regarding some hardware products we sold. The shift I've seen is the elimination of the need for professional service packages. Users can customize their use of Cisco XDR significantly from the onset, which has resulted in a lower total cost of ownership compared to when we sold hardware and multiple systems.

    Which other solutions did I evaluate?

    I don't recall every product we considered before selecting Cisco XDR, but we looked at about nine alternatives. Our security team discovered details about Cisco XDR through integration work as a partner, which led us to realize that it could address many features we were interested in but were not initially evaluating. The aspect that stood out most during the evaluation process of Cisco XDR was its ease of use. Seeing how quickly we set up a proof of concept, along with the internal demos we received, made me confident about its implementation. Once we allowed everyone hands-on experience, it further affirmed how much smoother and more intuitive it was compared to others.

    What other advice do I have?

    The impact of AI assistance and Cisco XDR on productivity is massive. We're no longer tied to just our reporting that was created for either looking at information specifically requested, or in response to a past event that we knew about. Now, security administrators can just go look and chat with the bot to get back a much more instant response and almost a live view of the data. They can navigate through breadcrumbs to get to the details of an event without causing hours of delays for someone to dig through that data or involve someone more conversationally versed in specific hardware products to look at the data.

    The feature for prioritizing incidents across multiple security controls in Cisco XDR has affected my incident management process significantly. Even on the vendor side, as a traditional IT shop, we have silos of excellence where all these teams don't necessarily work together until there is an incident. Having our security and specified incident response leads from each team be able to get this data quickly allows security to determine if an incident is a mistake, a script triggering alarms, or just a bad network change.

    My experience with using Cisco XDR to evaluate gaps in security coverage has been quite beneficial. Giving our security team and the first few end-user leads that own specific systems access to the AI chatbot has been crucial. We did reviews to determine what they are asking of the bot, how often they prompt it, and the types of responses they are getting back. This helped us identify that many of the teams in the middle that own connecting pieces did not realize that the security team was more responsive and concerned about certain issues than they thought.

    My advice for other organizations considering Cisco XDR is to evaluate if they're already using a platform that meets all their needs. Think about what additional capabilities you desire, and envision what could be possible if everyone had access to pertinent data. Engaging directly with someone at Cisco to demonstrate how XDR can meet those needs is crucial to instill excitement and clarity among teams about data, workflows, and security. On a scale of 1-10, I rate Cisco XDR a 9.

    Anonymous91798

    Highly reliable and easy to implement

    Reviewed on Jun 11, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We use Cisco XDR  for our network devices and data centers, as we are an internet provider. We deliver the internet to customers.

    What is most valuable?

    The feature I appreciate the most about Cisco XDR  is the reliability. The reliability of Cisco XDR  benefits my company by ensuring less downtime and less customer downtime, and it is also easier to keep everyone trained on Cisco because we are all more familiar with that than other vendors.

    What needs improvement?

    My only complaint about Cisco XDR is related to licensing, which is complicated.

    For how long have I used the solution?

    I have been using Cisco XDR for probably three years.

    What do I think about the stability of the solution?

    Cisco XDR  is very reliable, which is its big advantage.

    What do I think about the scalability of the solution?

    Cisco XDR scales effectively with the growing needs of my company.

    How are customer service and support?

    My experience with their technical support has been excellent. I would rate Cisco customer service a ten out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It is easy to implement.

    What was our ROI?

    The biggest return on investment when using Cisco XDR is the downtime aspect, specifically not having to roll out to sites and not having customers experience downtime.

    I don't have the metrics, but the downtime reduction is definitely a lot compared to the other vendors that we've used in the past.

    What's my experience with pricing, setup cost, and licensing?

    The licensing of Cisco XDR is a bit complicated. The cost can depend on what it is, and the process can be a little complicated.

    Which other solutions did I evaluate?

    We did consider other solutions before choosing Cisco XDR. We went for Cisco XDR because we're all already trained in Cisco. Reliability is also a big reason.

    What other advice do I have?

    I would rate Cisco XDR a nine out of ten. The only thing that could make it a ten is better licensing. That's my only complaint.

    Matthew Dean

    Granular insights enable quick troubleshooting and improved customer satisfaction

    Reviewed on Jun 09, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We are a small ISP, and it mainly use it just basically for routing and insights into wherever our traffic goes through.

    How has it helped my organization?

    My job is to put out fires all day. The features of Cisco XDR  benefit my company since time is money. When outages happen and when a customer can't reach the internet, they get agitated. Therefore, the quicker we can mitigate an issue, our customers get happier in a quicker fashion.

    What is most valuable?

    I appreciate the granularity of what I get from Cisco XDR  the most. It provides so much information that I can troubleshoot in a more detailed fashion. I get all this information and can comb through it to figure out exactly where the source of the trouble comes from.

    Between the clarity, the granularity, and the dashboard, it just works.

    It does its job by helping evaluate gaps and mitigating in a timely fashion.

    What needs improvement?

    Cisco XDR  can be improved by addressing the upfront cost. Everything matters for us since we're small, mom and pop, so every dollar counts.

    For how long have I used the solution?

    I have been using Cisco XDR for about two years, two and a half years.

    What do I think about the stability of the solution?

    The stability and reliability of Cisco XDR, similar to most Cisco products, are bulletproof. As long as I keep it with ramp patching and updates, they just work.

    What do I think about the scalability of the solution?

    Regarding scalability, since we're smaller, I don't know if we'll ever grow bigger than what we are now, being landlocked in Bixby, Oklahoma. However, if we were blessed to get bigger, it would be easy.

    How are customer service and support?

    My experience with customer service and technical support for Cisco XDR is that the tech support is excellent and easy to work with.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I considered other solutions before choosing Cisco XDR, such as FortiGate  and Juniper, and those were two that we had a proof of concept with. FortiGate  was good, but it was actually a blessing because Cisco XDR was technically cheaper than FortiGate.

    How was the initial setup?

    My experience with the deployment of Cisco XDR is that it was extremely easy. We worked with our VAR, Net Fabric .

    What about the implementation team?

    The representative we worked with helped us set it up and it just worked.

    What was our ROI?

    The biggest return on investment when using Cisco XDR is that, being a small company where everybody has multiple roles, the quicker I can mitigate something, the faster I can return to my scheduled tasks for that day.

    What's my experience with pricing, setup cost, and licensing?

    My experience with the costs, including setup costs and licensing for Cisco XDR, is that it's now a subscription base, with options for one year, three year, or five year terms.

    It would be preferable to return to the old model where you just buy it once without having to pay a renewing fee, however, I don't think they're going to implement that.

    Which other solutions did I evaluate?

    I considered other solutions before choosing Cisco XDR, such as FortiGate and Juniper, and those were two that we had a proof of concept with. FortiGate was good, however, it was actually a blessing because Cisco XDR was technically cheaper than FortiGate.

    What other advice do I have?

    Cisco XDR streamlines incident response through its provided functionalities because, based on the clarity of the dashboard and the granularity, it works effectively.

    I would rate Cisco XDR overall a nine out of ten, based on the price point.

    Adir B.

    CISO

    Reviewed on May 05, 2025
    Review provided by G2
    What do you like best about the product?
    I like the integration between Cisco's various tools.
    What do you dislike about the product?
    I think there is room for improvement with the reports for CISOs.
    What problems is the product solving and how is that benefiting you?
    addresses several critical challenges in cybersecurity by providing an integrated, cross-domain threat detection and incident response platform. Here's a detailed overview of the problems it solves and the benefits it delivers, especially from a CISO's perspective in a regulated environment like pharmaceutical manufacturing.
    View all reviews