Soarcery vs Cortex XSOAR. One agent that investigates, compared to a playbook platform you draw and maintain.
Cortex XSOAR, Palo Alto Networks' SOAR platform and formerly Demisto, unifies playbook automation, case management, collaboration, and threat intel. Soarcery is a single accountable agent, the Familiar, that investigates a case end to end, with automation that runs only after a human reviews the plan. Here is where each earns its place, sourced from Palo Alto Networks' own materials.
Where the two platforms actually diverge.
Playbooks you draw versus an agent that investigates
Cortex XSOAR is orchestration built around the playbook: a "visual playbook editor for code-free automation" over "900+ prebuilt integration and automation packs."2 It is a mature, capable model, but the reasoning is drawn ahead of time onto a canvas, and the platform runs the branch a human built for the situation they anticipated. Soarcery takes the opposite bet. The Familiar reasons through the Investigation itself when the alert arrives, following the evidence rather than a pre-drawn branch, and cites what it found. There is no library of playbooks to keep current for every tool and every case shape.
Where the go-forward intelligence lives, and on which product
Palo Alto's own answer to agentic AI is Cortex AgentiX, which it describes as "the next generation of Cortex XSOAR."6 That is a serious platform, but it is delivered on a different footing: Palo Alto states "Cortex AgentiX is available today in Cortex Cloud and Cortex XSIAM," while the standalone AgentiX platform "will be available in early 2026."6 A team standardizing on standalone XSOAR today is buying the current platform while its go-forward AI layer, AgentiX, is delivered first inside XSIAM and Cortex Cloud and reaches standalone availability on that timeline. Soarcery's intelligence is the agent, available now as its own platform: the Familiar investigates and recommends, and Spells are plan-first, proposed in plain language for a human to review before anything executes.
The default posture: automation-first versus approval-first
Cortex XSOAR leads with autonomous speed: a "90% reduction in remediation time" and "75% fewer incidents requiring manual interaction" are its own headline figures.2 How much runs unattended is a function of the playbooks each team builds and the automation they choose to enable. Soarcery starts from the other end. The Familiar investigates and recommends, but the Seal is the default gate on consequential actions, not a setting an admin has to remember to turn on, and every approval produces a receipt, every time, with no configuration required to get that behavior.
To be fair to a platform with real scale behind it.
- A large, verified content marketplace. Palo Alto states Cortex XSOAR "is the only SOAR platform that verifies all free and paid third-party content in the marketplace to be safe for immediate use," across a very large pack library.4
- Mature threat intel management and purpose-built case management. XSOAR TIM "ties threat information to incidents in real-time,"5 and its case management was "designed for security incident responders" rather than adapted from generic ticketing.3
- A large practitioner community and platform gravity. Palo Alto's marketplace cites a community of more than 20,000 incident responders, and XSOAR sits inside the broader Cortex platform that Palo Alto is investing in heavily.46
Fair fight
If your SOC already runs on Palo Alto Cortex, a built-out library of XSOAR playbooks, and its threat-intel management, that investment is real and moving off it has a cost. Soarcery is the better fit when what you want is one agent that reasons through a full Investigation end to end, a native multi-engine verdict spread informing that reasoning, and an approval gate that is the default behavior, not a setting someone has to remember to configure.
Watch the difference on a real case.
Three minutes, ungated. Then bring your own alerts and compare for real.
Where this comparison comes from.
Every claim about Cortex XSOAR above traces back to one of these, entirely Palo Alto Networks' own pages, confirmed by direct fetch where noted.
- 1Palo Alto Networks, "Cortex XSOAR" datasheet landing, paloaltonetworks.com/resources/datasheets/cortex-xsoar. "Cortex XSOAR helps simplify security operations by unifying automation, case management, real-time collaboration and threat intel management."
- 2Palo Alto Networks, "Cortex XSOAR" product page, paloaltonetworks.com/cortex/cortex-xsoar. "Visual playbook editor for code-free automation," "900+ prebuilt integration and automation packs," "90% reduction in remediation time," "75% fewer incidents requiring manual interaction," "machine learning to aid analysts," "auto-documentation for knowledge sharing and audit reporting."
- 3Palo Alto Networks, "Incident Case Management", paloaltonetworks.com/cortex/incident-case-management. "Each incident is associated with a war room where analysts can do investigations and collaborate in real time," "all actions performed by playbooks or analysts are auto-documented," "designed for security incident responders." Confirmed by direct fetch.
- 4Palo Alto Networks, "Cortex XSOAR Marketplace", paloaltonetworks.com/cortex/cortex-xsoar/marketplace. "The only SOAR platform that verifies all free and paid third-party content in the marketplace to be safe for immediate use," community of more than 20,000 incident responders.
- 5Palo Alto Networks, "Threat Intel Management", paloaltonetworks.com/cortex/threat-intel-management. XSOAR TIM "ties threat information to incidents in real-time, and automates the distribution of your threat intelligence at scale."
- 6Palo Alto Networks, "Palo Alto Networks Unveils Cortex AgentiX...", October 28, 2025, paloaltonetworks.com/company/press/2025. "As the next generation of Cortex XSOAR, AgentiX...", "Cortex AgentiX is available today in Cortex Cloud and Cortex XSIAM. Cortex XDR and the standalone AgentiX platform will be available in early 2026."
- 7Palo Alto Networks, "Cortex XSOAR 8 FAQs: Licensing and Pricing", docs-cortex.paloaltonetworks.com. User-based licensing; no public list pricing, sold through Palo Alto Networks and resellers.