What is our primary use case?
The solution is deployed in our computers in the company. However, I can't speak to the use cases, as I'm still quite new to the company.
After we apply some policies we will receive, for example, alerts. We'll look at the devices that have given us alerts and we'll look to see if there is an issue. Then we can prioritize the issues into high and low categories.
We try to know what is a malicious file or malicious application and we can investigate what's happening according to the alerts in Carbon Black. Many times we've found that our policies avoid false positives. That said, sometimes, we have false positives and we get many alerts. We're working with this in Carbon Black.
Carbon black is basically blocking my application. I cannot open files and I cannot install software without it passing the policies. Not just any application can be installed on our computers. They need to be pre-approved. If we need to, however, we can manually bypass to finish an installation.
What is most valuable?
The solution allows you to override it and manually install an application if you need it ti.
It's very good at alerting you to malicious content or unauthorized software.
We can access computers remotely if we need to.
What needs improvement?
Sometimes the solution blocks items that were previously approved and we don't know why.
It is sometimes hard when I attempt to investigate, to know the commands. It's not easy to do that. You need to upload the right information.
Occasionally, when we get alerts, we don't get all the information we need, such as the computer's serial number.
If I reveal an alert in a new window, I need to go back to the main link as it doesn't work.
Sometimes we need to close the solution and then open it up again.
Occasionally, we'll have issues with the latest version and they'll basically tell us that they will improve it in the next iteration. They need to work on their version release quality.
It would be good to have more information about the devices. If you get an alert that a malicious file is on your computer, Carbon Black really doesn't give you the full picture. We also need to wait for the user who owns the computer to be online before we can investigate everything. It's hard when you are working across time zones.
For how long have I used the solution?
I started using the solution two weeks ago. I don't have a lot of experience with it just yet.
What do I think about the stability of the solution?
The stability could be better. It changes from version to version and from day to day. Sometimes it works perfectly, and sometimes there are issues and we need to close it and re-open the application.
How are customer service and support?
We do have a person at Carbon Black that, if we have issues, we can reach out to. We let them know when we are having problems and they try to assist. I can't recall if it's email or some other type of internal support system that we go through.
Sometimes they have answers for us, and sometimes we have to wait for a new version. There's no guarantee our problems will be fixed immediately.
How was the initial setup?
By the time I joined the company, the solution was already deployed. I was not part of the implementation process. I can't speak to how easy or difficult the solution is to implement.
What other advice do I have?
We have deployed different versions of the solution. At this moment we have 3.5 or we have, for example, for Windows we have 3.1. We deploy it to many computers and in different countries. You need to upgrade or maybe you need to downgrade, depending on the device it's attached to. For example, we have many servers including 2016 and 2019 versions, and then we have different versions of Windows.
When we decide to deploy a new version we deploy it throughout the region. We have been in America, Asia, and Europe.
I'd advise other potential users that, like any solution, you need to know how to use it, you need to know how to implement, and you need to know how to do the best configuration and update that configuration. If you don't have a good configuration on any application, it will work not for you.
In general, the solution is good. I would rate it at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.