# Palo Alto Cortex XSIAM vs Rapid7 InsightIDR

| Attribute | Palo Alto Cortex XSIAM | Rapid7 InsightIDR |
|---|---|---|
| **Vioscale score** | 61 (13% (low)) | 39.7 (29% (low)) |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"hybrid":true,"on_prem":true}` |
| description.long | A cloud-delivered platform that unifies security operations through AI-driven automation and machine learning, consolidating multiple SOC tools into one system to reduce manual processes, cut through noise, and accelerate threat investigation and response. | A multi-tier security platform that combines asset discovery and attack surface visibility with vulnerability management, cloud security, and incident detection. Delivers risk-based prioritization and automated response capabilities tailored to different organizational needs, from basic asset visibility to comprehensive threat detection. |
| features.capabilities | `{"siem":true,"soar":true,"deployment":"cloud","ml_detection":true,"threat_intel":true,"case_management":true,"mitre_attack_mapping":true}` | `{"siem":true,"soar":true,"ueba":false,"ml_detection":true,"threat_intel":true,"pricing_basis":"assets","case_management":true,"connector_breadth":"Enterprise security tools, cloud platforms, IT service management","open_core_available":false}` |
| integrations.count | - | 7 |
| integrations.list | - | `[{"name":"Jira"},{"name":"ServiceNow"},{"name":"Microsoft Defender"},{"name":"AWS"},{"name":"Azure"},{"name":"GCP"},{"name":"Kubernetes"}]` |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US","GB"],"availabilityScope":"global","availableCountries":["US","AU","BR","CA","CN","FR","DE","IN","IT","JP","KR","MX","SG","ES","TW","GB"],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":["US","EU"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"web":true}` |
| pricing | - | `{"type":"quote","plans":[{"free":false,"name":"Surface Command","features":["Asset discovery & unified inventory (CAASM)","Internal + external attack surface visibility (EASM)","Asset context, enrichment & relationships","Blast radius analysis","Exposure Management dashboard & remediation hub","Built-in automation & integrations"],"commitment":"annual","description":"Asset discovery and attack surface visibility","contactSales":true},{"free":false,"name":"Exposure Command Essentials","features":["Everything in Surface Command","Vulnerability management (agent-based and network scanning)","Risk-based prioritization with threat-aware scoring","Policy & configuration assessment","Remediation workflows, SLAs & reporting","Dynamic asset tagging & criticality","Integrations with security & IT tools"],"commitment":"annual","description":"Vulnerability management across hybrid environments with risk-based prioritization","contactSales":true},{"free":false,"name":"Exposure Command Ultimate","features":["Everything in Essentials","Multi-cloud & container security (AWS, Azure, GCP, K8s)","Cloud posture & compliance (CIS + frameworks)","Attack path analysis & contextual risk prioritization","Real-time cloud visibility & threat detection","Identity & access risk analysis (least privilege)","Infrastructure-as-code (IaC) security","Application & API security testing (DAST, API, LLM)","Automated cloud remediation"],"commitment":"annual","description":"Unified risk management across cloud, applications, and infrastructure","contactSales":true}],"summary":"Custom quote based on billable assets; annual subscriptions. Volume discounts available.","currency":"USD","freeTier":false,"sourceUrl":"https://www.rapid7.com/products/command/pricing/","retrievedAt":"2026-08-14T12:14:54.563Z","billingPeriods":["year"]}` |
| pricing.free_tier | - | no |
| pricing.model | commercial | quote |
| pricing.price_level | - | unknown |
| pricing.transparent | - | no |
| reliability.status_page | yes | yes |
| security.disclosure_policy | - | yes |
| security.gdpr | yes | yes |

## Capabilities (SIEM & SOAR Software)

| Capability | Palo Alto Cortex XSIAM | Rapid7 InsightIDR |
|---|:--:|:--:|
| **Core** |  |  |
| SIEM (log correlation & detection) | ✓ | ✓ |
| SOAR (playbooks / automated response) | ✓ | ✓ |
| **Detection** |  |  |
| UEBA (behavioural analytics) | - | ✗ |
| Built-in threat intelligence | ✓ | ✓ |
| ML / anomaly detection | ✓ | ✓ |
| MITRE ATT&CK detection mapping | ✓ | - |
| **Ops** |  |  |
| Case / incident management | ✓ | ✓ |
| **Pricing** |  |  |
| Pricing basis | - | Per-asset |
| **Deployment** |  |  |
| Deployment | Cloud | - |
| **Integration** |  |  |
| Connector / content-pack breadth | - | Enterprise security tools, cloud platforms, IT service management |
| **Licensing** |  |  |
| Open-core available | - | ✗ |

*Source: Vioscale. Generated 2026-09-01T16:49:31.248Z. "-" = undocumented, not absent.*
