Palo Alto Networks vs SentinelOne

Palo Alto Networks — Application · Public · $302.9B mkt cap · 4 of 4 figures sourced  |  SentinelOne — Application · Public · $7.5B mkt cap · 4 of 4 figures sourced

Relationship

10-K Item 1 Competition names Palo Alto Networks as a direct rival across endpoint/XDR. SentinelOne's endpoint product and Palo Alto's Cortex XDR both carry detect-security-threats.

4 of 7 capabilitiesShared product typeSmaller scaleNamed in filingDetect and respond to security threats

4 of 7 capabilities — Shares data analysis, data security, guardrails and safety and 1 more.

Ludbee capability tags · from the product records

Shared product type — Both ship application and platform.

Ludbee product records

Smaller scale — SentinelOne: $7.5B market cap, against Palo Alto Networks's $302.9B market cap.

Ludbee scale figures · valuation, market cap or revenue estimate

Named in filing — “Palo Alto Networks, Inc. (Palo Alto Networks)”

sec.gov · checked 2026-09-19

Detect and respond to security threats — Rivals on this job — Spot attacks across endpoints, email, cloud and identity, then triage and contain them.

Ludbee needs vocabulary · the scope on the sourced edge

Aligned comparison

FieldPalo Alto NetworksSentinelOne
Market cap$302.9B$7.5B SentinelOne has 41× smaller
Employees16,0682,900 SentinelOne has 5.5× fewer
Founded20052013 8 yrs later
StatusPublicPublic match
CategoryApplicationApplication match
Stack layerApplication, PlatformAI agent, Application, Data service, Platform
HeadquartersSanta Clara, USAMountain View, USA

Capability overlap

Shared · 4

Data analysisData securityGuardrails and safetyThreat detection and response

Not verified for SentinelOne · 3

Agent orchestrationEvaluation and observabilityWorkflow automation

Recorded for Palo Alto Networks. SentinelOne’s product records say nothing either way — a missing record is not a missing capability.

SentinelOne has no capability Palo Alto Networks lacks, among the 4 recorded here.

Products, side by side

Hand-checked pairing

Palo Alto Networks

Application

AI Access SecurityApplication

A cloud-delivered service within Prisma SASE that discovers shadow AI usage and applies access controls and data loss prevention to generative AI applications.

Platform

Cortex XDRPlatform

Endpoint detection and response platform marketed as "the foundation of the AI-driven SOC," with an AI agent assistant (Cortex AgentiX) for investigation and response.

Cortex XSIAMPlatform

An AI-driven security operations platform that unifies SIEM, SOAR and detection-and-response data with automation and AI agents to run a security operations centre.

Precision AIPlatform

Palo Alto Networks' proprietary AI system combining machine learning, deep learning and generative AI to automate threat detection, prevention and remediation across its Strata, Prisma Cloud and Cortex security platforms.

Prisma AIRSPlatform

An AI security platform that discovers, scans and protects AI models, agents, applications and data against runtime and posture threats.

Prisma AIRS AI GatewayPlatform

Runtime gateway component of Prisma AIRS that inspects and governs traffic to and from AI models and agents.

Strata Cloud ManagerPlatform

"The first AI-powered, unified solution for network security management and operations," with an AI assistant (Strata Copilot) and purpose-built AI agents for policy optimization, threat detection and remediation.

SentinelOne

Application

Prompt SecurityApplication

Discovers and governs employee and developer use of AI services, redacts sensitive data in prompts, controls autonomous agents and MCP servers, and defends custom AI applications against prompt injection, jailbreaks and data poisoning.

Singularity Cloud SecurityApplication

Cloud-native application protection platform that defends production workloads, cloud and AI infrastructure and the data stores feeding models, detecting and responding to threats autonomously across the cloud estate.

Singularity EndpointApplication

AI-powered endpoint security that combines endpoint protection, detection and response, and automated remediation and rollback in a single agent across Windows, macOS, Linux and cloud workloads.

Singularity IdentityApplication

Identity-security module of the Singularity Platform that protects against credential misuse and identity-based attacks.

Singularity MobileApplication

On-device mobile threat defense for iOS, Android and ChromeOS that stops phishing, malware and risky apps with an on-device model and needs no cloud connection to detect.

Wayfinder TDRApplication

Managed AI-assisted threat detection and response (MDR-style) service delivered by SentinelOne's global services team.

Platform

Singularity AI SIEMPlatform

A security information and event management platform that ingests and normalizes cloud, identity, endpoint and third-party telemetry, correlates signals into incidents via Purple AI, and executes containment from the investigation console.

Singularity PlatformPlatform

Umbrella platform that runs SentinelOne's endpoint, cloud, identity and mobile protection on one agent and console with autonomous detection, response and rollback; the modules a buyer licenses are recorded separately.

No counterpart

SentinelOne sells these in a stack layer with no product recorded for Palo Alto Networks yet — nothing on the other side to compare them against.

AI agent

Purple AIAI agent

An agentic AI security analyst embedded in the Singularity Platform that auto-triages alerts, runs investigations and threat hunts, and recommends or executes response actions over OCSF-normalized SentinelOne and third-party telemetry.

Data service

Singularity AI Data PipelinesData service

A security telemetry pipeline service that filters low-value logs, normalizes heterogeneous sources into OCSF, and enriches events before they reach a SIEM, built on technology from SentinelOne's acquisition of Observo AI.