Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Choosing a platform

Soarcery vs Cortex XSOAR. One agent that investigates, compared to a playbook platform you draw and maintain.

Cortex XSOAR, Palo Alto Networks' SOAR platform and formerly Demisto, unifies playbook automation, case management, collaboration, and threat intel. Soarcery is a single accountable agent, the Familiar, that investigates a case end to end, with automation that runs only after a human reviews the plan. Here is where each earns its place, sourced from Palo Alto Networks' own materials.

Cortex XSOAR
Soarcery
Core idea
A playbook-driven SOAR platform. Palo Alto describes it as unifying "automation, case management, real-time collaboration and threat intel management,"1 with a "visual playbook editor for code-free automation" and "900+ prebuilt integration and automation packs."2
One agent, the Familiar, investigates a case end to end. Spells are plan-first automations a human reviews before they run.
The thinking
The intelligence lives in the playbooks a team draws and in machine learning that assists analysts, listed as "machine learning to aid analysts."2 The reasoning is encoded ahead of time into the workflow you build.
The Familiar reasons through the full Investigation itself and cites its evidence, informed by a native multi-engine verdict spread rather than a single scan result.
The acting
Playbooks orchestrate response across integrated tools. Palo Alto's product page claims a "90% reduction in remediation time" and "75% fewer incidents requiring manual interaction."2 How much runs on its own is set by the playbooks a team builds.
The Seal is the default gate: consequential actions wait on explicit human approval, every time, with a receipt. It is not an opt-in setting.
Maintenance
Playbooks are drawn on a visual canvas and bound to integrations a team installs and configures.2 Cortex AgentiX, which Palo Alto calls "the next generation of Cortex XSOAR," ships inside Cortex XSIAM and Cortex Cloud, with "the standalone AgentiX platform" set to arrive "in early 2026."6
Spells are described in plain language. There is no flowchart to redraw when a connected tool changes shape.
Auditability
Each incident has a War Room where analysts "do investigations and collaborate in real time," and "all actions performed by playbooks or analysts are auto-documented."3 The product page lists "auto-documentation for knowledge sharing and audit reporting."2
The Seal's approval receipts form one replayable trail per Investigation: evidence, reasoning, the approver, and the action, in one place.
Where it wins
A very large, verified content marketplace, mature Threat Intel Management, purpose-built security case management, a large practitioner community, and the gravity of the broader Palo Alto Cortex platform.45
Investigation depth from a single accountable agent, a native multi-engine verdict spread, and an approval gate that ships as the default rather than a configuration choice.
Honest risk
Pre-authored playbooks are yours to draw and maintain, and that upkeep shifts each time a connected tool changes. The go-forward AI layer is AgentiX, which Palo Alto positions as the next generation and delivers today inside XSIAM and Cortex Cloud, with the standalone platform set for early 2026.6 Pricing is not published; XSOAR uses a user-based license sold through Palo Alto and its resellers.7
Soarcery is a newer platform. It has not run at Cortex XSOAR's scale, marketplace breadth, or community size yet, and that gap is real.
The architectural difference

Where the two platforms actually diverge.

Playbooks you draw versus an agent that investigates

Cortex XSOAR is orchestration built around the playbook: a "visual playbook editor for code-free automation" over "900+ prebuilt integration and automation packs."2 It is a mature, capable model, but the reasoning is drawn ahead of time onto a canvas, and the platform runs the branch a human built for the situation they anticipated. Soarcery takes the opposite bet. The Familiar reasons through the Investigation itself when the alert arrives, following the evidence rather than a pre-drawn branch, and cites what it found. There is no library of playbooks to keep current for every tool and every case shape.

Where the go-forward intelligence lives, and on which product

Palo Alto's own answer to agentic AI is Cortex AgentiX, which it describes as "the next generation of Cortex XSOAR."6 That is a serious platform, but it is delivered on a different footing: Palo Alto states "Cortex AgentiX is available today in Cortex Cloud and Cortex XSIAM," while the standalone AgentiX platform "will be available in early 2026."6 A team standardizing on standalone XSOAR today is buying the current platform while its go-forward AI layer, AgentiX, is delivered first inside XSIAM and Cortex Cloud and reaches standalone availability on that timeline. Soarcery's intelligence is the agent, available now as its own platform: the Familiar investigates and recommends, and Spells are plan-first, proposed in plain language for a human to review before anything executes.

The default posture: automation-first versus approval-first

Cortex XSOAR leads with autonomous speed: a "90% reduction in remediation time" and "75% fewer incidents requiring manual interaction" are its own headline figures.2 How much runs unattended is a function of the playbooks each team builds and the automation they choose to enable. Soarcery starts from the other end. The Familiar investigates and recommends, but the Seal is the default gate on consequential actions, not a setting an admin has to remember to turn on, and every approval produces a receipt, every time, with no configuration required to get that behavior.

Where Cortex XSOAR wins

To be fair to a platform with real scale behind it.

  • A large, verified content marketplace. Palo Alto states Cortex XSOAR "is the only SOAR platform that verifies all free and paid third-party content in the marketplace to be safe for immediate use," across a very large pack library.4
  • Mature threat intel management and purpose-built case management. XSOAR TIM "ties threat information to incidents in real-time,"5 and its case management was "designed for security incident responders" rather than adapted from generic ticketing.3
  • A large practitioner community and platform gravity. Palo Alto's marketplace cites a community of more than 20,000 incident responders, and XSOAR sits inside the broader Cortex platform that Palo Alto is investing in heavily.46

Fair fight

If your SOC already runs on Palo Alto Cortex, a built-out library of XSOAR playbooks, and its threat-intel management, that investment is real and moving off it has a cost. Soarcery is the better fit when what you want is one agent that reasons through a full Investigation end to end, a native multi-engine verdict spread informing that reasoning, and an approval gate that is the default behavior, not a setting someone has to remember to configure.

Settle it with evidence

Watch the difference on a real case.

Three minutes, ungated. Then bring your own alerts and compare for real.

Sources

Where this comparison comes from.

Every claim about Cortex XSOAR above traces back to one of these, entirely Palo Alto Networks' own pages, confirmed by direct fetch where noted.

  1. 1Palo Alto Networks, "Cortex XSOAR" datasheet landing, paloaltonetworks.com/resources/datasheets/cortex-xsoar. "Cortex XSOAR helps simplify security operations by unifying automation, case management, real-time collaboration and threat intel management."
  2. 2Palo Alto Networks, "Cortex XSOAR" product page, paloaltonetworks.com/cortex/cortex-xsoar. "Visual playbook editor for code-free automation," "900+ prebuilt integration and automation packs," "90% reduction in remediation time," "75% fewer incidents requiring manual interaction," "machine learning to aid analysts," "auto-documentation for knowledge sharing and audit reporting."
  3. 3Palo Alto Networks, "Incident Case Management", paloaltonetworks.com/cortex/incident-case-management. "Each incident is associated with a war room where analysts can do investigations and collaborate in real time," "all actions performed by playbooks or analysts are auto-documented," "designed for security incident responders." Confirmed by direct fetch.
  4. 4Palo Alto Networks, "Cortex XSOAR Marketplace", paloaltonetworks.com/cortex/cortex-xsoar/marketplace. "The only SOAR platform that verifies all free and paid third-party content in the marketplace to be safe for immediate use," community of more than 20,000 incident responders.
  5. 5Palo Alto Networks, "Threat Intel Management", paloaltonetworks.com/cortex/threat-intel-management. XSOAR TIM "ties threat information to incidents in real-time, and automates the distribution of your threat intelligence at scale."
  6. 6Palo Alto Networks, "Palo Alto Networks Unveils Cortex AgentiX...", October 28, 2025, paloaltonetworks.com/company/press/2025. "As the next generation of Cortex XSOAR, AgentiX...", "Cortex AgentiX is available today in Cortex Cloud and Cortex XSIAM. Cortex XDR and the standalone AgentiX platform will be available in early 2026."
  7. 7Palo Alto Networks, "Cortex XSOAR 8 FAQs: Licensing and Pricing", docs-cortex.paloaltonetworks.com. User-based licensing; no public list pricing, sold through Palo Alto Networks and resellers.