Try our new research platform with insights from 80,000+ expert users
IT Cybersecurity at a manufacturing company with 10,001+ employees
Real User
Good alerts, easy to manually override, and allows remote access to machines
Pros and Cons
  • "We can access computers remotely if we need to."
  • "Occasionally, we'll have issues with the latest version and they'll basically tell us that they will improve it in the next iteration. They need to work on their version release quality."

What is our primary use case?

The solution is  deployed in our computers in the company. However, I can't speak to the use cases, as I'm still quite new to the company.

After we apply some policies we will receive, for example, alerts. We'll look at the devices that have given us alerts and we'll look to see if there is an issue. Then we can prioritize the issues into high and low categories.

We try to know what is a malicious file or malicious application and we can investigate what's happening according to the alerts in Carbon Black. Many times we've found that our policies avoid false positives. That said, sometimes, we have false positives and we get many alerts. We're working with this in Carbon Black.

Carbon black is basically blocking my application. I cannot open files and I cannot install software without it passing the policies. Not just any application can be installed on our computers. They need to be pre-approved. If we need to, however, we can manually bypass to finish an installation.

What is most valuable?

The solution allows you to override it and manually install an application if you need it ti.

It's very good at alerting you to malicious content or unauthorized software. 

We can access computers remotely if we need to.

What needs improvement?

Sometimes the solution blocks items that were previously approved and we don't know why.

It is sometimes hard when I attempt to investigate, to know the commands. It's not easy to do that. You need to upload the right information.

Occasionally, when we get alerts, we don't get all the information we need, such as the computer's serial number.

If I reveal an alert in a new window, I need to go back to the main link as it doesn't work.

Sometimes we need to close the solution and then open it up again.

Occasionally, we'll have issues with the latest version and they'll basically tell us that they will improve it in the next iteration. They need to work on their version release quality.

It would be good to have more information about the devices. If you get an alert that a malicious file is on your computer, Carbon Black really doesn't give you the full picture. We also need to wait for the user who owns the computer to be online before we can investigate everything. It's hard when you are working across time zones.

For how long have I used the solution?

I started using the solution two weeks ago. I don't have a lot of experience with it just yet.

Buyer's Guide
VMware Carbon Black Endpoint
June 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability could be better. It changes from version to version and from day to day. Sometimes it works perfectly, and sometimes there are issues and we need to close it and re-open the application.

How are customer service and support?

We do have a person at Carbon Black that, if we have issues, we can reach out to. We let them know when we are having problems and they try to assist. I can't recall if it's email or some other type of internal support system that we go through.

Sometimes they have answers for us, and sometimes we have to wait for a new version. There's no guarantee our problems will be fixed immediately.

How was the initial setup?

By the time I joined the company, the solution was already deployed. I was not part of the implementation process. I can't speak to how easy or difficult the solution is to implement.

What other advice do I have?

We have deployed different versions of the solution. At this moment we have 3.5 or we have, for example, for Windows we have 3.1. We deploy it to many computers and in different countries. You need to upgrade or maybe you need to downgrade, depending on the device it's attached to. For example, we have many servers including 2016 and 2019 versions, and then we have different versions of Windows.

When we decide to deploy a new version we deploy it throughout the region. We have been in America, Asia, and Europe. 

I'd advise other potential users that, like any solution, you need to know how to use it, you need to know how to implement, and you need to know how to do the best configuration and update that configuration. If you don't have a good configuration on any application, it will work not for you.

In general, the solution is good. I would rate it at an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Engineer at a retailer with 1,001-5,000 employees
Real User
Top 5
Integrates easily with our existing security infrastructure, but the technical support services need improvement
Pros and Cons
  • "It significantly speeds up incident response times by alerting analysts immediately upon detecting potential issues."
  • "The product cannot perform an on-demand scan. They could add this particular feature."

How has it helped my organization?

The solution has significantly improved our organization by providing fast detection and protection management. It enables us to conduct various queries and manage vulnerabilities effectively, ensuring our systems are protected against known threats.

What is most valuable?

The platform's capability to protect endpoints, conduct live analysis, and detect system communication with malicious domains was valuable. 

What needs improvement?

The product cannot perform an on-demand scan. They could add this particular feature. 

For how long have I used the solution?

I have had experience using VMware Carbon Black Endpoint for about three years.

How are customer service and support?

The support services required having a billable account, which presented some challenges.

How would you rate customer service and support?

Neutral

How was the initial setup?

The ease of setup depends on the mobile device management (MDM) solution. Generally, it is straightforward to deploy, similar to Webex.

What about the implementation team?

Security engineers, IT analysts, and system administrators conducted the deployment process. It was maintained by our managed security service provider (MSSP), Azure.

What's my experience with pricing, setup cost, and licensing?

The platform is expensive. 

What other advice do I have?

Carbon Black Endpoint is effective but very expensive. The behavioral EDR feature is effective for data analysis and aids in incident response by providing quick alerts to analysts. It significantly speeds up incident response times by alerting analysts immediately upon detecting potential issues. It integrates easily with our existing security infrastructure. 

I recommend it despite its high cost and some decline in quality post-acquisition. I rate it a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
VMware Carbon Black Endpoint
June 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.
Ricardo Franco Mahecha - PeerSpot reviewer
VMware Consultant at V2S Corporation
Real User
Top 5Leaderboard
Integrates with different software's log servers and easy to scale
Pros and Cons
  • "For Carbon Black Endpoint, the possibility of integration with different other software's log servers is the important thing. Having just one point of view is more interesting so you don't need to go to different places to see all the information."
  • "The initial setup is complex."

What is our primary use case?

We need it to secure some PCs and virtual machines inside the company.

How has it helped my organization?

We have a single point of view of all the security systems, and it has some interesting tools.

What is most valuable?

For Carbon Black Endpoint, the possibility of integration with different other software's log servers is the important thing. Having just one point of view is more interesting so you don't need to go to different places to see all the information.

What needs improvement?

There is room for improvement in the proxy servers. The implementation and management of those servers are difficult.

The proxy servers have proxy servers in place to not connect directly to the Internet, and the implementation and management of those servers are difficult.

Moreover, some customers request disabling Bluetooth in endpoints, but Carbon Black doesn't do that. So, there should be some flexibility for customization.

For how long have I used the solution?

I have been using this solution for a couple of months. 

What do I think about the stability of the solution?

I would rate the stability a nine out of ten.

What do I think about the scalability of the solution?

It is easy to scale. I would rate the scalability a ten out of ten.

How are customer service and support?

The customer service and support are solid.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is complex. 

What was our ROI?

It's a good return on investment. The single point of view is very important for the client.

What's my experience with pricing, setup cost, and licensing?

The solution has almost the same price as other different kinds of infrastructures, but it offers a lot of different features.

What other advice do I have?

I would recommend trying it first. Overall, I would rate the solution a nine out of ten. It's a great product. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ramesh RP - PeerSpot reviewer
Security Analyst at Halian
Real User
Has An Easy Setup In Place; However, Adding Certain Integration Features Would Make It A More Useful Solution
Pros and Cons
  • "I feel that the initial setup was straightforward and not complex."
  • "I am not sure whether Carbon Black CB Defense can be considered as a stable solution or not."

What is our primary use case?

Our primary use case for this solution involves addressing incidents related to malware outbreaks and malicious signatures.

What is most valuable?

Sandboxing is one of the features I found to be the most valuable in Carbon Black CB Defense.

What needs improvement?

It would be good if Splunk integration or something similar to Splunk integration is available for this solution.

For how long have I used the solution?

I have been using the latest version of Carbon Black CB Defense for the past year.

What do I think about the stability of the solution?

I am not sure whether Carbon Black CB Defense can be considered to be a stable solution or not.

What do I think about the scalability of the solution?

I feel that this is a scalable solution. There are around 80 to 90 employees at our organization who are using Carbon Black CB Defense.

How are customer service and support?

I have never contacted the tech support team of Carbon Black CB Defense.

Which solution did I use previously and why did I switch?

In our organization, we have used CTF365 and iZOOlogic in the past. We didn't switch from those since we have a multiple-client setup. One client uses one EDR, while the other one uses the other EDR. So, the intention of having a multiple-client setup at our end is to help our clients, and it is not for the benefit of our company.

How was the initial setup?

I feel that the initial setup was straightforward and not complex. The deployment of the tool is carried out by our engineering team, consisting of 10 members. With the addition of the manager and the other management team members, the total number of individuals involved in the deployment comes to around 25. The engineering team, who are responsible for this activity, ensures the successful deployment of the solution with their expertise.

What other advice do I have?

I would like to see more integration with other platforms. I rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Andrew Nai - PeerSpot reviewer
Lead Infrastructure Engineer at Government of Singapore
MSP
Well priced with a good visualization tree but doesn't allow for high availability configuration
Pros and Cons
  • "The solution is stable."
  • "There's some disparity between the on-premise and the cloud type of application."

What is our primary use case?

We're providing this product to our customers. The main intention of using this product is to detect small malware and for vulnerabilities and scanning detection in real-time.

What is most valuable?

The Intel fit was very extensive and comprehensive enough. The visualization tree product feature in this CB defense is quite good. These are the two more notable product features.

The pricing is excellent.

The solution is stable.

What needs improvement?

There's some disparity between the on-premise and the cloud type of application. We basically manage applications versus SaaS-based ones. We were hoping that some of the more advanced features that they offer in the SaaS actually could be similarly offered for the on-premise managed applications. We find that cloud-based solutions are particularly more advanced in product roadmaps compared to on-prem.

There should be more roles in support. There needs to be support for multi-tenancy, the likes of multiple names space. When you use that in a very large organization, you have many departments. It doesn't really provide grouping by department, et cetera. 

There's actually a lagging feature that we saw in the SaaS, yet not on the on-premise setup. It seems like the on-premise one was really, really meant for a single department setup rather than for multiple departments.

The solution doesn't allow for high availability configuration. That's also a negative impact relating to the product.

For how long have I used the solution?

We have been using this solution for about two years.

What do I think about the stability of the solution?

Stability-wise, the product has been quite stable. There's no issue. The maintenance was quite straightforward, and if you don't really touch it, you won't have stability problems. 

What do I think about the scalability of the solution?

Medium to large companies will be selecting Carbon Black solutions mainly due to the fact that they needed this to better the security posture checks in the environment, typically in the more regulated environment. Regulatory, regulated environments or companies that are more security-centric will go for this type of product.

While it can scale, it only supports non-HA. Scalability is quite limited. You can only scale vertically - not horizontally.

How are customer service and support?

Technical support can be much improved. They're quite lagged in terms of their support and post-sales. In terms of the roadmap to sell, they tend to sell more towards endpoints and very large enterprises. For a server base, it would lose itself. That's not really their main focus at this point in time. Therefore, it's not as good there.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I'm also familiar with Trend Micro. Trend Micro is advancing the product, keeping it fairly up to date, and covering some aspects of the EDR over time and they're doing a lot of catching up. They actually have caught up. The technology now is quite fairly similar - it's just that the initial focus was in different areas, however, they are filling this gap. It's actually a very strong competitor. In terms of user, features-wise, et cetera, this solution is quite on par. Trend Micro is a security-focused company, so from an enterprise point, probably they are more focused than Carbon Black nowadays being bought over by VMware. Security is probably not their main area of focus at this point in time. 

How was the initial setup?

The initial setup is a bit of a mix. It is simple in the sense the setup was quite straightforward, however, when it comes to configuring for other supports, like emails, notifications, Syslog, et cetera, this identity provider's power integration, which we did for our SML 2.0, is powered based, rather than supported directly through the GUI. That was not so user-friendly, or more complex in terms of configuration.

On a scale from one to five in terms of ease of setup, it'll be about three. It probably takes about half a day just to complete the configuration setup.

The maintenance so far has been quite fairly straightforward. We don't really have any issues with the maintenance. Obviously, I didn't want the downside of the product side, maybe one of the cons is that it doesn't really support HA high availability setup configuration. 

What's my experience with pricing, setup cost, and licensing?

We have a contract, we have actually a BOT tender contract where our different customers from different departments actually purchase their licensing. Generally, the pricing is from a unique cost perspective. I wouldn't know exactly how much they buy typically, as they procure their licenses on their own. Typically, if you compared the pricing to Trend Micro, it's probably about half the cost.

What other advice do I have?

We're not quite a partner. We are a systems integrator and reseller. 

We do not have the latest update. We integrate that into our Azure AD itself.

We have the solution deployed both on the cloud and on-premises. 

I'd recommend the solution based on the cost. It's really subjective to the organization's needs. If it's for a single, small department, it's fine. If it's for a large organization itself, some of it lacks. Enterprise capabilities are probably a hindrance for a large organization to take up such a product. The limitations of supporting multiple departments with different roles and users, for them to configure what they need, would be a problem. When you talk about alerts et cetera, and also certain tracks, different departments actually probably they have their own different needs, so they wanted something to be a little bit independent, where the configuration settings are unique to the department, rather than something that can only be common for all departments in the current setup.

I'd rate the solution six out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Senior Director, Information Technology at C.E. Niehoff & Co.
Real User
Has an ongoing monitoring feature that emails updates when endpoint threats are detected
Pros and Cons
  • "The feature I found most valuable in Carbon Black CB Defense is the ongoing monitoring feature that works by emailing updates about any detections found."
  • "What was rolled out to my company are mixed versions of Carbon Black CB Defense, so what I'd like to see in the next release is more synchronization, where it can detect the endpoint that's running an old version and suggest updates."

What is our primary use case?

Carbon Black CB Defense is a sensor for ongoing monitoring. It was deployed and is being used in conjunction with a cloud product called Red Canary.

What is most valuable?

The feature I found most valuable in Carbon Black CB Defense is the ongoing monitoring, though I'm not sure if it's because of the solution, or if it's because of Red Canary. The ongoing monitoring feature works by emailing updates about any detections found.

What needs improvement?

Currently, it's hard to comment on areas for improvement, because I haven't used Carbon Black CB Defense long enough.

What was rolled out to my company are mixed versions of Carbon Black CB Defense, so what I'd like to see in the next release is more synchronization, where it can detect the endpoint that's running an old version and suggest updates. That's the only thing I can think of right now.

For how long have I used the solution?

I've been using Carbon Black CB Defense since October of last year.

What do I think about the stability of the solution?

I haven't had any major degradation in the performance of Carbon Black CB Defense, so I find it stable. It's holding up very well.

What do I think about the scalability of the solution?

I have no comment on the scalability of Carbon Black CB Defense at this point.

How are customer service and support?

I haven't even had to reach out to the technical support team of Carbon Black CB Defense at this point, so no comment.

Which solution did I use previously and why did I switch?

I did not use a different solution. This was the first time I used this type of solution.

How was the initial setup?

In terms of initial setup, rolling out Carbon Black CB Defense was pretty straightforward. It wasn't that big of a deal.

What about the implementation team?

The deployment of Carbon Black CB Defense was done in-house, and took two weeks total, because it was a hybrid deployment, which means that it was done on a one-on-one basis.

What was our ROI?

In terms of ROI from Carbon Black CB Defense, it's a little early to see it.

What's my experience with pricing, setup cost, and licensing?

In terms of licensing costs, Carbon Black CB Defense was all associated with CROW and the services my company is using with them, so it came all-inclusive.

Which other solutions did I evaluate?

My company didn't evaluate other options, because Carbon Black CB Defense was suggested by CROW. My company just went with what they suggested.

What other advice do I have?

I have experience with Carbon Black CB Defense. My company has already adopted a solution that uses Carbon Black CB Defense, particularly with a company called CROW.

Carbon Black CB Defense was deployed hybrid in terms of what my company does. The cloud provider used was CROW.

My company has 200 users of Carbon Black CB Defense. It's being used in the whole environment. Three people from IT are in charge of the maintenance and full deployment of the solution.

In terms of increasing usage, the solution is being used in the entire environment, and usage will be increased if there's growth in personnel.

At this junction, I'm rating Carbon Black CB Defense an eight.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
RizwanAlam - PeerSpot reviewer
AVP - Information Security Governence & Risk Management at Allied Bank Limited
Real User
An easy-to-use solution that has a live response which is really tailored to our needs, but needs a lot of time to record all of the behaviors
Pros and Cons
  • "The best feature of this solution is that we have a live response, which is really tailored to our needs."
  • "The solution would be more effective if there was a way to block automatically based on behavior."

What is our primary use case?

We have a dedicated team using this solution. They create incidents, escalate the incidents, and then respond to the events detected by the EDR.

What is most valuable?

The best feature of this solution is that we have a live response, which is really tailored to our needs. 

What needs improvement?

There is no option for the solution to block automatically based on behavior. First, the solution needs a lot of time to record all the behaviors. Then, we manually have to create a behavior analysis rule to detect any malicious activity. The solution would be improved and be more effective if there was a way for this process to be done automatically.

For how long have I used the solution?

We have been using this solution for six to seven months. 

What do I think about the stability of the solution?

The solution is not always ideal, but it is pretty stable. We did face a few issues, in the response feature for example, but they were resolved.

What do I think about the scalability of the solution?

At this point we have not encountered any issues with scalability, but time will tell how much scaling is feasible for us.

How are customer service and support?

The customer support is average. At times I feel like they should have responded to us immediately because we had some issues that needed an immediate reply, but their response was a bit slow. However, overall, they're good and the support is acceptable.

How would you rate customer service and support?

Neutral

How was the initial setup?

It was not easy and we faced challenges, but it was okay. We're also dealing with an issue involving multiple unsupported OS's because we have so many Linux products in our infrastructure. I would rate the initial setup as a three out of five, with one being difficult and five being easy.

What other advice do I have?

This is a good solution, but there are a lot of improvements needed. I am overseeing the project part of the solution, not the deep technical side. As far as my knowledge is concerned, it's an easy-to-use solution and it has many good features, but it also has many features that require improvement. I would rate the solution as a six out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ICT Manager at SecurEyes
Real User
A stable solution which can be flexibily configured

What is our primary use case?

Carbon Black CB Defense is a multi-purpose solution. We can use it for XDR ADF. This way, if someone is trying to attack one's end point, in which there is a script such as PowerShell, but without a signature, the solution will be aware of such an attack and respond accordingly. It will detect the behavior and respond to the SOC.

What is most valuable?

The solution will prevent communication of one compromised device with another. 

What needs improvement?

In the month-long evaluation of the solution that we conducted, we found the POC to not be helpful, owing to the issue the client encountered with the platform, the operating system, which did not lend adequate support. 

While we paid for both on-cloud and on-premises deployment, the issue is not with the entrepreneur's upload, but with the end point. 

And do you have already some customers regarding Carbon Black?

Syed Faisal:
No, even Carbon Black, everyone has this solution for Windows IoT and Linux environment. But this is something called the product called Dell. This is a Dell based, [inaudible 00:02:31]. More or less the Dell [inaudible 00:02:33] which is running Dell customer OS, [inaudible 00:02:39]. But unfortunately we cannot install the agent on it.

The licensing price is a bit expensive when compared with other solutions. 

For how long have I used the solution?

We've been using Carbon Black CB Defense for just a month. 

What do I think about the stability of the solution?

The solution is scalable. 

What do I think about the scalability of the solution?

The solution is stable and the policy can be configured with flexibility. The solution comes with its own pre-built standard policy. Yet, we can write our own, which means the solution serves us going forward. 

How are customer service and technical support?

The tech support is mostly okay. 

How was the initial setup?

The solution is very easy to install.

Full deployment takes no more than an hour. 

What about the implementation team?

Installation can be done on one's own. 

What's my experience with pricing, setup cost, and licensing?

The licensing is a bit pricier than other solutions. 

We pay for the license annually. 

What other advice do I have?

While I do not know the exact number of customers making use of the solution, my understanding is that most of the MNC, multinational companies, and the majority of the banking sector are doing so. 

I would recommend the solution to others.

I rate Carbon Black CB Defense as a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.