Listing Thumbnail

    Cisco XDR

     Info
    Deployed on AWS
    Cisco XDR, an eXtended Detection and Response security solution, collects and correlates data across email, endpoints, servers, cloud workloads, and networks, enabling visibility and context into advanced, multi-vector threats. Cisco XDR integrates with AWS services and has 53 AWS-specific threat detections with new detections being introduced all the time. Threats can then be analyzed, prioritized, hunted, and remediated to prevent data loss and security breaches. Cisco XDR quickly identifies and stops the most complex attacks on AWS with an open XDR approach.
    4.3

    Overview

    Cisco XDR integrates data from multiple security technologies and leverages AI for enhanced threat detection, streamlined security operations, and improved efficiency to provide a unified defense approach. Designed to address the challenges faced by security practitioners, it offers a cloud-native, open approach that integrates data and telemetry generated from security tools across your stack and applies AI and analytics to arrive at correlated detections.

    Cisco XDR has developed an AWS-specific threat detection library to help users quickly identify attacks and remediate threats. Cisco XDR is the core component of Cisco Breach Protection Suite, which helps secure your business with simplified security operations and accelerated response through AI-powered defense.

    With Cisco XDR, security teams can detect threats across the environment by correlating multiple security vectors, including vital network, email, endpoint, application, and cloud insights. Cisco XDR provides unified threat detection and response by integrating the broad Cisco portfolio of solutions, along with several third-party vendor solutions (for the complete list, see Cisco XDR integrations). It enriches incidents with added context and asset insights using the underlying threat intelligence from Cisco Talos®, one of the most trusted private threat intelligence organizations in the world, as well as dozens of third-party threat intelligence tools. Through clear prioritization of incidents, Cisco XDR reduces false positives and provides the shortest path from detection to response.

    Highlights

    • Identify and stop even the most complex attacks, whether they originate on-premises or in AWS, with a network-centric open XDR approach powered by a simple, built-in Network Detection and Response (NDR) to gain comprehensive visibility.
    • Natively integrate network data from Meraki MX devices to gain clear visibility beyond what EDR-based tools provide, so defenders can take more informed and timely actions.
    • Remediate threats quickly and decisively with AI-guided response and automation that levels up the performance and effectiveness of your security operations team.

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. Request a private offer to receive a custom quote. Sign in to view any offers that have been extended to you.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    You can reach for the Cisco XDR support at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.3
    14 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    57%
    43%
    0%
    0%
    0%
    1 AWS reviews
    |
    13 external reviews
    External reviews are from G2  and PeerSpot .
    Ananda Deb

    Security operations have strengthened data center protection and build lasting client confidence

    Reviewed on Mar 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are system integrators working in a consultancy mode with a team of implementation engineers. Over the last two years, we have worked on several Cisco XDR  cases. In data centers, Cisco XDR  is definitely the primary requirement. Our first choice is always Cisco, and while one or two other solutions have come our way, Cisco cases primarily come to us. In a certain segment, Cisco XDR  is definitely the first priority. I would say that about 80% of my customer base relies on Cisco XDR . We are partners of Cisco and we focus particularly on the implementation aspect, while also taking care of services.

    What is most valuable?

    Cisco XDR is one of the most matured systems available. It is quite user-friendly. The system has been very effective, and our customers receive sufficient reports demonstrating visible benefits. This helps maintain customer confidence, particularly in secure data center implementations. With the implementation we have deployed, our customers gain confidence in having their data center secure. The reporting capabilities are pretty extensive. Cisco XDR is keeping our customers protected.

    What needs improvement?

    It would be difficult for me to identify specific improvements at this moment. We have not really foreseen exactly what additional benefits might be needed. Given more thought, something could potentially come out, but we have not found any requirements for additional features.

    For how long have I used the solution?

    The solution is working well for our needs.

    What do I think about the stability of the solution?

    There were some challenges initially, but with the technical support provided, we were able to resolve them and move forward successfully.

    What do I think about the scalability of the solution?

    Scalability has been a consideration for our implementations.

    How are customer service and support?

    The technical support has been very helpful. During implementation, we receive assistance from the technical support team and have obtained proper support from their side.

    How would you rate customer service and support?

    Negative

    How was the initial setup?

    In a certain segment, Cisco XDR is definitely the first priority. I would say that about 80% of my customer base relies on Cisco XDR as the way to go.

    What about the implementation team?

    We are partners of Cisco and focus particularly on the implementation aspect. We also take care of the services.

    What was our ROI?

    Cisco XDR has helped our customers achieve positive returns on their investment.

    Which other solutions did I evaluate?

    I strongly feel that Cisco XDR is more proactive rather than reactive compared to alternate solutions.

    What other advice do I have?

    It would be difficult for me to provide additional advice at this moment. I would give Cisco XDR a nine out of ten. I would definitely recommend it. I

    Pranav Salian

    Unified threat detection has strengthened visibility and reduced response time across all environments

    Reviewed on Feb 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Cisco XDR  serves as the main platform for threat detection and threat response in my organization.

    We have integrated all of our internal devices including firewalls, servers, EDRs, and endpoints into Cisco XDR . In typical scenarios, we find blacklisted IP communication detected by our firewall, and Cisco XDR  blocks these particular attempts made by blacklisted IPs, thereby helping us secure our environment from potential cyber threats.

    We focus on the alerts generated by Cisco XDR  and the threat intelligence reports available on the platform. Our security team reads through those reports and proactively blocks those IPs and the IOCs on our firewall rather than waiting for Cisco XDR to raise an alert about a particular IP or IOC attempting to communicate with the environment. The threat intelligence information available on the platform is quite useful for us to proactively take actions to better secure our environment and reduce our attack surface for potential cyber threats.

    What is most valuable?

    Cisco XDR offers a wide range of integrations and connectors where we can integrate a whole range of devices available in our on-premises environment as well as cloud sources which we have primarily on AWS  and Azure . Those environment log sources are integrated with Cisco XDR and it helps provide a single pane of glass view in terms of our security posture, giving us visibility within a single platform rather than focusing on individual security devices such as firewalls or EDRs which would typically be working in silos.

    These integrations are straightforward. Cloud workloads are easier to integrate compared to on-premises devices, primarily because the cloud workloads have readymade connectors and integration standard operating procedures for us to integrate with Cisco XDR. We have typically not faced challenges with integrations with Cisco XDR. There may be certain OEMs which are not well known and cannot be directly integrated without the help of vendor support or OEM support, which we were able to connect with and ensure they are integrated with Cisco XDR.

    From the reporting perspective, the dashboards offer quite a lot of predefined and useful options which help with live threat monitoring and provide a high-level view of the current threats, incident reporting metrics, mean time to detect, and mean time to respond. These sorts of dashboards are available on the platform and help provide a good view even for someone at the leadership level.

    Cisco XDR has definitely improved our security posture and our visualization, ensuring that we are protected and providing greater visibility for our SOC team.

    Cisco XDR has definitely reduced our mean time to respond. Previously it used to be more than 24 hours, but we have been able to reduce it to less than 16 hours due to all the various integrations and automation capabilities.

    Cisco XDR has been useful for us to gain visibility into gaps in our security posture and how those can be improved by conducting analysis on the platform itself. We have utilized the platform to improve our security posture and reduce blind spots.

    What needs improvement?

    Cisco XDR can be improved in terms of out-of-the-box integrations and standard operating procedures available on the platform where we would not have to refer to documents outside of the platform to integrate. Having these standard operating procedures or integration methods available within the platform for most devices will help improve our experience with Cisco XDR.

    The primary area for improvement is the integrations itself.

    For how long have I used the solution?

    I have been working in my current field for about ten plus years.

    What do I think about the stability of the solution?

    Cisco XDR is stable in our environment and we have not found major issues in terms of downtime or lack of monitoring coverage.

    What do I think about the scalability of the solution?

    In terms of scalability, Cisco XDR is quite scalable in terms of a licensing model and the number of assets we have integrated with it. It is seamless.

    How are customer service and support?

    The customer support has been quite good. When we raise a ticket on technical support, they reach out to us within a couple of hours to listen to our issue and provide us with solutions. I would rate customer support at nine out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We used IBM QRadar  before we switched to Cisco XDR primarily because IBM QRadar  was more a legacy system and customizations, connector building, parser building, and integrations were taking a long time where we had to reach out to IBM for support. With Cisco XDR, we found a quicker turnaround time.

    What about the implementation team?

    Our team required extra training and onboarding support during the initial phase, but as of now they are using it seamlessly. I would rate it at approximately eight out of ten.

    What was our ROI?

    We have experienced return on investment since we have been utilizing this platform for the last five years. Over time as the platform has evolved and more automations have been put in place, the number of human resources required has drastically reduced. Previously, we used to require four people in each shift to manage all of the incidents and workloads, which would essentially be about twelve people per day. We have been able to cut them down to six people per day, which is roughly half the team size required as of now. This helps in saving cost and time.

    What's my experience with pricing, setup cost, and licensing?

    In terms of licensing and support cost, it is quite seamless. Based on the number of users we require, we have purchased as many licenses, and the setup is also a one-time cost which we received support for from Cisco's technical support team.

    Which other solutions did I evaluate?

    Before choosing Cisco XDR, we evaluated Splunk, IBM QRadar which was already existing in the environment, and Microsoft Sentinel . Cisco XDR was the best option in terms of overall feature capabilities and pricing.

    What other advice do I have?

    In terms of DLP , Cisco XDR is quite useful. We are using a different DLP  as well within our organization, so we are not extensively relying upon Cisco XDR for DLP, but it is a good solution to fall back upon. In terms of pricing, it is not the cheapest but it is also not the most expensive compared to other products we have experienced in the past.

    Cisco XDR is hosted on private cloud.

    We are typically deployed on AWS  and have utilized automation workflows to improve our mean time to respond, reducing it from over 24 hours to less than 16 hours.

    We prioritize incidents based on its criticality in terms of which devices or environments are affected that we have integrated with this platform. This has definitely helped in prioritizing incidents and ensuring that we have good coverage twenty-four hours a day, seven days a week across business hours and non-business hours by looking at the trend of what incident types occur and how often they occur, as well as what kind of team support is required across multiple shifts during the day and night.

    The platform helps our SOC team access the platform across the entire shifts. We follow three shifts, and it helps with the shift handover when we transition from the morning shift to the afternoon shift or from the afternoon shift to the night shift. The platform helps seamlessly hand over from the previous analyst in the previous shift to the new analyst in the next shift.

    My advice to other potential buyers of Cisco XDR would be to always conduct an evaluation or a proof of concept before actually purchasing because each environment is different and while Cisco XDR may be useful in most environments, there are potentially some environments where it may not be useful. It is always good to try before you buy. I would rate this product an eight out of ten.

    Sanjay Gaiswal

    Unified detection has reduced response times and improves protection across endpoints and network

    Reviewed on Jan 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Cisco XDR  is used for endpoint security, data protection across endpoints, network protection, advanced persistent threat (APT) detection, ransomware attack mitigation, and advanced threat detection. We use Data Loss Prevention (DLP)  because it integrates with Cisco Secure Access  and Cisco Umbrella , helping to protect sensitive data. Cisco XDR  is the extended detection and response solution we have implemented.

    What is most valuable?

    Cisco XDR  is appreciated as a SaaS-based platform for its user-friendliness with simple management tools that are easy for configuration. Its ability to reduce the Mean Time to Respond (MTTR) from hours to minutes and the option to use a customized dashboard are highly valued features.

    The platform's AI-driven architecture, especially in Advanced Persistent Threat (APT) detection, is praised. Automation features streamline security operations by replacing manual and repetitive tasks.

    Cisco XDR  offers comprehensive security by identifying visibility across the network and protecting cloud endpoints. It has significant performance metrics and scalability, designed to handle a large number of endpoints and sessions.

    What needs improvement?

    While Cisco XDR is robust, it could benefit from improvements on the AI side. More features could be added to prioritize and automate traffic.

    For how long have I used the solution?

    We have been using Cisco XDR for more than two to three years.

    What do I think about the stability of the solution?

    We have not found any stability issues or received complaints from customers, so as of now, there is no improvement needed.

    What do I think about the scalability of the solution?

    Cisco XDR is designed to handle significant scaling of endpoints, allowing management of a large scale of environments with thousands of sessions. It is rated nine out of ten for scalability.

    How are customer service and support?

    The customer service response time is very good, with a strong technical team providing proper solutions when support is needed.

    Which solution did I use previously and why did I switch?

    We previously used Cortex XDR  for Palo Alto. While the features are similar, Cisco XDR's AI-driven feature is more advanced, making it a better choice.

    How was the initial setup?

    The deployment is considered simple and very user-friendly.

    What about the implementation team?

    Cisco XDR has benefits on the user end and is easy to manage and deploy a large number of endpoints in a short time.

    Which other solutions did I evaluate?

    Alternate XDR solutions include Forcepoint and Zscaler.

    What other advice do I have?

    As of now, there are no gaps identified, so I am not able to provide further advice. The review rating for Cisco XDR is nine out of ten.

    AjenthanAiyathurai

    Centralized incident visibility has strengthened email security and proactive threat response

    Reviewed on Dec 23, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Cisco XDR  primarily for emails and endpoints. I use Cisco XDR  features for prioritizing incidents across multiple security controls, mainly focusing on emails but also on threat analysis such as phishing and malware. This enables rapid investigations and automated responses, blocking senders and isolating endpoints from threats collectively.

    What is most valuable?

    The best feature about Cisco XDR  is that when it comes to email security, the centralized visibility is superb. For example, it gathers email data from various gateways, offering a centralized view of threats, which is very useful.

    I assess the effectiveness of the DLP  (Data Loss Prevention) capabilities in Cisco XDR  as very useful. For example, it analyzes outbound and inbound web traffic and provides unified control. I have centralized control over data going out of the organization, so I can control what to send and what not to send. Such functionalities are very useful.

    The main benefits I see from using Cisco XDR include its proactive security measures. For example, it allows advanced threat hunting and analysis, working proactively instead of just focusing on reactive measures. If a threat comes, it blocks the threat, but this solution proactively activates and alerts me, so it is very helpful in terms of security. Another benefit is that the integration is very good with third-party security tools or other Cisco products; I can integrate this very easily.

    Cisco XDR has streamlined incident response by quickly notifying me, even through emails. I have set up phone messages, so normally I get alerts through my service provider if any threats arise. It is quick to send notifications if anything occurs, even notifying me of the preventive measures taken, such as blocking IPs and isolating devices.

    What needs improvement?

    If I could see improvements in Cisco XDR in the future, I would like to see a stronger focus on AI-driven solutions. For example, it has a feature called advanced threat detection, and if it can capture threats from worldwide new threats and publish them into a particular database linked with an AI-driven system that can immediately alert people, that would be very good for zero-day threats. The second improvement I suggest is reducing the subscription price a bit more.

    I would like to see enhanced features in Cisco XDR, such as demo sessions with the product, and supporting multiple languages would be great.

    Regarding the pricing aspect of Cisco XDR, I think the price is a bit expensive.

    For how long have I used the solution?

    I have been working with Cisco XDR for almost one year.

    How are customer service and support?

    I would rate Cisco technical support as extended, but their service is very unresponsive. It is very difficult to get in touch with them, so I would rate it a four out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before Cisco XDR, I did not use any other products for XDR purposes.

    How was the initial setup?

    The deployment aspect of Cisco XDR is smooth. Since I was new to this product, I did not do it in-house; I had a third party do it for me. My contribution was about 40 percent, and they did 60 percent of the work, so it went smoothly.

    What about the implementation team?

    The deployment aspect of Cisco XDR is smooth. Since I was new to this product, I did not do it in-house; I had a third party do it for me. My contribution was about 40 percent, and they did 60 percent of the work, so it went smoothly.

    What was our ROI?

    I find it does bring a return on investment, but that will take a long period. I would say it is not in a short span; probably two to three years or more.

    Which other solutions did I evaluate?

    I thought of going with Check Point intrusion prevention system, but that product needs more technical knowledge, so I skipped it because it is also a bit more expensive than Cisco XDR.

    What other advice do I have?

    My advice for other organizations considering Cisco XDR is that it offers proactive security measures that are really very helpful. It is also a unified control system where all emails and endpoints are visible on one dashboard, making it easy to understand, even for a non-technical person to quickly grab information by just seeing that. I would rate Cisco XDR as a product an eight out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Shourya TejReddy KSS

    Endpoint insights have improved incident investigations but performance still needs optimization

    Reviewed on Dec 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    As a security consultant, I use multiple SIEM  and XDR  solutions, so cumulatively, I can say I have used Cisco XDR  for around one year.

    What is most valuable?

    Cisco XDR  is built primarily for enterprise endpoint security, integrated onto endpoints with logs integrated into SIEM , and it is used for security investigations, malware impact investigation, and tracking particular security incidents through integration of different logs, where endpoint logs are very important, providing detail about processes run by potential malware and any call-outs made to command and control.

    The best features of Cisco XDR  include its ability to integrate with multiple SIEM platforms, with visibility coming from a lot of Cisco's devices, and it syncs well with other XDRs and endpoint defenses such as Microsoft Defender, SentinelOne, and CrowdStrike, integrating well with other vendor products.

    Cisco XDR helps prevent data loss during ransomware attacks by integrating with multiple levels of security, tying to identity management systems, and allowing placement of blocks at the endpoint level, which provides an additional layer of security, optimizing for detecting and preventing data loss based on how well the rules are placed and how well integrations are done for overall visibility of different stages of intrusion or data loss.

    What needs improvement?

    Improvements in Cisco XDR revolve around performance. The less performance it utilizes to run at high configuration levels, the better it becomes, so all vendors need to continue working on keeping resource utilization low while providing optimum performance, which is a defining point or deal breaker.

    For how long have I used the solution?

    I have used Cisco XDR for around one year.

    What do I think about the stability of the solution?

    Stability is dependent on integration, since product-wise it is very stable, but performance-wise it is acceptable, so I would give it a rating of six.

    What do I think about the scalability of the solution?

    In terms of scalability, I rate it as the best. For scalability, I would give it an eight out of ten.

    How are customer service and support?

    I would rate technical support as a seven to eight because it is very great in current times. If I had to decide between seven or eight, I would say a seven.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I mostly use the AI assistance and automation feature for reporting, not for analysis because I do not trust AI for conclusions, only for inputs and reporting, which is how the AI component is utilized.

    I do use the feature for prioritizing incidents across multiple security controls, but that needs to be configured, as I work mostly at the governance level for information security as a consultant, so the effectiveness depends on how well it is integrated and what the policy and operations are.

    Cisco XDR streamlines incident response through its functionalities, being top of the stack and comparing well with other providers such as Palo Alto or the recently developed open-source Wazuh , which makes it very good.

    I compare Cisco XDR with top-of-the-stack options available such as Palo Alto, Sophos XDR, and Secureye, an Indian company, and it lines up with all of them, providing a lot of other devices and software with Cisco's easy integration, making it one of the best for visibility.

    I would definitely suggest Cisco XDR for enterprises and MSMEs who have a specified budget to fortify their defenses, and it stacks up well against other offerings in the market, naming CrowdStrike as somewhat better due to its knowledge base and R&D, with Tanium  ranking just under it, making Cisco XDR probably number three in the XDR market.

    I rate this review overall as a seven out of ten.

    View all reviews