Try our new research platform with insights from 80,000+ expert users
Ricardo Franco Mahecha - PeerSpot reviewer
VMware Consultant at V2S Corporation
Real User
Top 5Leaderboard
Integrates with different software's log servers and easy to scale
Pros and Cons
  • "For Carbon Black Endpoint, the possibility of integration with different other software's log servers is the important thing. Having just one point of view is more interesting so you don't need to go to different places to see all the information."
  • "The initial setup is complex."

What is our primary use case?

We need it to secure some PCs and virtual machines inside the company.

How has it helped my organization?

We have a single point of view of all the security systems, and it has some interesting tools.

What is most valuable?

For Carbon Black Endpoint, the possibility of integration with different other software's log servers is the important thing. Having just one point of view is more interesting so you don't need to go to different places to see all the information.

What needs improvement?

There is room for improvement in the proxy servers. The implementation and management of those servers are difficult.

The proxy servers have proxy servers in place to not connect directly to the Internet, and the implementation and management of those servers are difficult.

Moreover, some customers request disabling Bluetooth in endpoints, but Carbon Black doesn't do that. So, there should be some flexibility for customization.

Buyer's Guide
VMware Carbon Black Endpoint
February 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.

For how long have I used the solution?

I have been using this solution for a couple of months. 

What do I think about the stability of the solution?

I would rate the stability a nine out of ten.

What do I think about the scalability of the solution?

It is easy to scale. I would rate the scalability a ten out of ten.

How are customer service and support?

The customer service and support are solid.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is complex. 

What was our ROI?

It's a good return on investment. The single point of view is very important for the client.

What's my experience with pricing, setup cost, and licensing?

The solution has almost the same price as other different kinds of infrastructures, but it offers a lot of different features.

What other advice do I have?

I would recommend trying it first. Overall, I would rate the solution a nine out of ten. It's a great product. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2173167 - PeerSpot reviewer
Cyber Security Manager Senior Specialist at a university with 501-1,000 employees
Real User
A scalable and easy-to-deploy EDR solution that offers its users a good customer support
Pros and Cons
  • "It is a scalable solution...The initial setup was straightforward."
  • "Right now, Carbon Black CB Defense doesn't support cloud computing and Kubernetes."

What is our primary use case?

I am associated with the incident response team, and we use Carbon Visibility for converged networks.

What needs improvement?

Right now, Carbon Black CB Defense doesn't support cloud computing and Kubernetes. However, if it does support them, then it would be better.

For how long have I used the solution?

I have been using Carbon Black CB Defense since 2019.

What do I think about the stability of the solution?

It is mostly a stable solution, but sometimes there are stability issues.

What do I think about the scalability of the solution?

It is a scalable solution.

How are customer service and support?

The technical support is nice. We can reach them 24/7. I rate technical support a seven out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was straightforward. We use it for the environment server, clients like end users, and competitors. We use some automation tools like SCCM for Windows, Linksys, and some other automation tools, and we use a lot of them to deploy. So, it depends since it is a circle and because every day, there is a new server that joins the environment. And when your server line client enters the server environment, they automatically install blockings.

But the environment contains over twenty thousand clients. It may take three or three months, depending on whether the employee works in their home. They can only join the network once they log in to VPN. So as a result of that, sometimes deployment time takes too much time. We have very big environments, but a lot of the domain is managed by some administration. Less than ten people were required for the deployment.

What about the implementation team?

We used local support to deploy it.

What's my experience with pricing, setup cost, and licensing?

There are more expensive products than Carbon Black CB Defense, so we are using the solution for its availability.

What other advice do I have?

I recommend the solution to others planning to use it. I rate the overall solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
VMware Carbon Black Endpoint
February 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.
Ashish Dubey - PeerSpot reviewer
Lead Security Analyst at SecurityHQ
Real User
Manages multiple endpoints from a central location and detects alerts on the basis of AI
Pros and Cons
  • "The solution has a library where we can have multiple threat intels onboarded. We just have to subscribe to a particular site intel and they'll provide us with all of the truncated details so that we can create IOCs and alerts on the basis of those IOCs."
  • "A search bar in the investigation page and some AI-related tasks like outgoing alerts, or recent tactics that are being used in the market, must be embedded in the tool so that it's easier to find alerts."

What is our primary use case?

Carbon Black is an EDR solution and a Next Generation AV. It works on the basis of machine learning and artificial intelligence. It's used to manage multiple endpoints from a central location and detects alerts on the basis of AI. If we have any custom alerts, they can be triggered or flagged. In that case, we can have a centralized alerting system. It can also be used to isolate, repair, or remediate a machine when it is taken by an attack.

We aren't responsible for managing the infrastructure of this particular tool. We're using it for investigation purposes and to monitor products that are being used by our clients.

It's deployed on a public cloud.

What is most valuable?

The solution has a library where we can have multiple threat intels onboarded. We just have to subscribe to a particular site intel and they'll provide us with all of the truncated details so that we can create IOCs and alerts on the basis of those IOCs. 

It's one of the best features because there are multiple third-party vendors who can provide us with site intel in one location. You just have to subscribe to them, and they'll start providing you with IOCs. If a new attack starts, you will have all the basic IOCs on that list, which can be used to identify if the same attack is happening in your environment.

We can isolate devices in just two clicks. That's also a great feature. We can remediate and repair devices from a central location. It's not too difficult to use that particular tool. The user interface is very easy to understand. You are not required to roam around the console to find where the alert went. It's easy to resolve that.

When we onboarded Carbon Black, there weren't many EDR solutions available in the market. It was one of the best tools when it was launched. We don't have any complaints with the tool. The tool is very good. It highlights many of the alerts and events.

What needs improvement?

When you're investigating an alert, you will get a graph and will see the details related to the process that triggered the alert. Below the graph, there are network connections, file modifications, industry modifications, and multiple other activities. If you want to specifically find which additional modification has been performed, you will have to find the log you're searching for. There isn't a search bar to check for file modifications or network connections. In that case, you don't have a search bar, so you have to check each and every event, which could be more than 1,000.

You would have to check 1,000 events manually, or you would have to export sheets to view what you are searching for. If they added a search bar, it would reduce the time it takes to do investigations.

If you want to log into a device, there's a process named winlogon.exe, which is supposed to be initiated. If I'm using Carbon Black, I will have to check where winlogon.exe is being observed or at what time it was being observed. Because there's no search bar, I will have to check for the event in all the device events.

A search bar in the investigation page and some AI-related tasks like outgoing alerts, or recent tactics that are being used in the market, must be embedded in the tool so that it's easier to find alerts. The AI must be stronger so it can identify activity that is actually malicious.

For how long have I used the solution?

I have used this solution for a year and a half.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

It's scalable because it's based on the cloud.

How was the initial setup?

It's sensor-based, so you have to install the machine associated with your application. You will have the configuration file and the agent installation file. You'll have to run the configuration file, and then you'll be onboarded to Carbon Black. It's easy.

Deployment was fast. It took 15 minutes.

We have a group of about eight people for maintenance and supervision.

What other advice do I have?

I would rate this solution as eight out of ten.

It's a good tool, but it requires some updates. It doesn't have new features like multi-tactics, which other EDR products are providing.

My advice is to acknowledge or resolve a particular alert because once they resolve, it will be very difficult for you to find that alert. Handle it with care because with just a click, the device will be isolated. It could be a server, host, or network device. If you click the wrong button out of curiosity, it will destroy the machine. It has multiple accesses and won't ask if you're sure if you want to do an activity or not.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Luciano Batalha - PeerSpot reviewer
Systems Engineer at EVONICEVONIC
Real User
Top 5Leaderboard
A simple tool that offers good performance and stability
Pros and Cons
  • "The most valuable feature of the solution stems from the fact that it is one of the best EDR tools in the market."
  • "The product's reporting capabilities are an area of concern where improvements are required."

What is our primary use case?

I use VMware Carbon Black Endpoint for its capabilities related to EDR and antivirus support. The tool offers protection to me with its advanced antivirus technology. The tool also protects me from threats.

How has it helped my organization?

My company does benefit from the use of the solution since it detects live threats, malware threats, possible ransomware attacks, and other such areas.

What is most valuable?

The most valuable feature of the solution stems from the fact that it is one of the best EDR tools in the market.

What needs improvement?

The product's reporting capabilities are an area of concern where improvements are required.

From an improvement perspective, the price of the product needs to be lowered.

For how long have I used the solution?

I have been using VMware Carbon Black Endpoint for two years. I use the solution's latest version.

What do I think about the stability of the solution?

The performance and stability of the product is very good and simple. The tool is very fast to analyze issues. It is a very stable tool. Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. Scalability-wise, I rate the solution a ten out of ten.

Around 22 people in my organization use the solution.

My company does have plans to increase the use of the solution.

How are customer service and support?

The solution's technical support was simple and good. The technical support team responds quickly to my queries.

How was the initial setup?

The product's initial setup phase was easy.

The version of the tool that I use is a cloud-based one, so in our company, we needed to create the policies and then use the tool for the endpoints on the desktops.

The solution is deployed on the cloud.

The solution can be deployed in half a day.

What about the implementation team?

I did seek the help of an integrator to help with the implementation process.

What's my experience with pricing, setup cost, and licensing?

My company needs to make yearly payments towards the licensing costs attached to the product. The product is expensive. There are some additional costs apart from the standard licensing charges attached to the solution.

What other advice do I have?

I recommend the product to those who plan to use it since it is a stable solution.

I rate the overall tool a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Consultant at Palsys
Consultant
Top 20
Easy-to-scale product with a straightforward installation process
Pros and Cons
  • "The product's most valuable feature is its ability to be fully integrated with the VMware environment."
  • "The product's stability could be improved."

What is most valuable?

The product's most valuable feature is its ability to be fully integrated with the VMware environment.

What needs improvement?

The product's stability could be improved.

For how long have I used the solution?

I have been using VMware Carbon Black Endpoint for one or two years as a system integrator.

What do I think about the stability of the solution?

Stability-wise, the product could be better. 

What do I think about the scalability of the solution?

The platform is very easy to scale. It is suitable for small and medium businesses.

How are customer service and support?

The technical support services are good.

How would you rate customer service and support?

Positive

How was the initial setup?

VMware Carbon Black Endpoint's installation is easy. The deployment takes one or two days, but the training administrator takes more time.

What other advice do I have?

I rate VMware Carbon Black Endpoint a ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
reviewer1439934 - PeerSpot reviewer
Infrastructure and support manager at a healthcare company with 51-200 employees
Real User
Amazing EDR that is responsive but there is no support for MAC and Linux
Pros and Cons
  • "The EDR and reports were helpful in improving our organization."
  • "Based on all the security roles and the release privilege, it could take time for an application to be whitelisted and approved for use."

What is our primary use case?

We used it for EDR, as well as endpoint protection, the whitelisting feature.

How has it helped my organization?

The EDR and reports were helpful in improving our organization.

What is most valuable?

The EDR was amazing. It was very responsive. It did an excellent job of providing us the information we needed in a timely fashion, as long as the latest agent was up-to-date on the client.

What needs improvement?

The whitelisting system, and the concept of it, overall, is pretty decent. The problem with the whitelisting capability is that it's pretty archaic. Based on all the security roles and the release privilege, it could take time for an application to be whitelisted and approved for use.

The Mac support needs improvement, as it had next to none.

The biggest problem we had was the Mac support. It had very little, and my C-suite is almost exclusively Mac, as is my marketing and development department.

For how long have I used the solution?

We had used the Carbon Black CB Defense for two years. We changed to another solution approximately nine months ago.

We were using the latest version at the time.

What do I think about the stability of the solution?

The stability of the on-premises servers had no issues but the resource allocation on the clients was a bit high, especially with having to run two agents. The detection agent, the Whitelist, and the control agent.

What do I think about the scalability of the solution?

We didn't have any problems scaling this solution.

It did the job. It was great for Windows, but it had no Mac support and had nothing for Linux, which makes it hard.

We had 150 users in our organization. Their roles varied from CSF departments through to my C-suite.

How are customer service and technical support?

Technical support seemed pretty good and I didn't have any problems with it. 

If we had a problem or a question, and they would get back to us in a reasonable amount of time. 

The only place that we ran into trouble was with Macs. That's my general theme here with Carbon Black, unfortunately.

I would rate them an eight or a nine. They were good for the most part.

Which solution did I use previously and why did I switch?

Previously, we were on the Kaspersky Enterprise Solution for a couple of years. It was a signature-based system. Signature-based systems are getting easier to get around by the attackers these days, so we swapped over to something that is a little closer to attack vectors, which says, don't run anything that we don't approve.

How was the initial setup?

The initial setup was moderate.

What other advice do I have?

For others who are interested in using Carbon Black, I would recommend checking your use case. If your use case is Linux and Mac, then it will be problematic, based on my experience.

These days, with VMware taking them over, I'm willing to bet that that's going to change.

I see some redemption in their future, with VMware owning them. VMware is a very strong player in the workspace, and especially with their workspace tool that VMware's building to work with Windows, Mac, and Linux clients, in order to do VDI.

For the Windows endpoints, it was incredibly useful, nothing got through it, which is a bad thing in some cases because we hadn't tagged the certificate platform appropriately. So, it's a bit of an improvement needed there, but the biggest complaint is around the operating systems not being available.

I would rate Carbon Black CB Defense a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1344240 - PeerSpot reviewer
IT Infrastructure - Global Head at a comms service provider with 10,001+ employees
Real User
Good security with a straightforward setup but requires better compatibility with other solutions
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "The solution needs better overall compatibility with other products."

What is our primary use case?

We primarily use the solution as endpoint security.

What is most valuable?

The security, specifically the endpoint security that the solution provides, is its most valuable aspect.

The initial setup is pretty straightforward.

What needs improvement?

The solution needs better overall compatibility with other products.

For how long have I used the solution?

I've been using the solution for less than a year. I've only really been using it for the last one or two quarters of this fiscal year. It hasn't been a very long time yet.

What do I think about the stability of the solution?

The solution is quite stable. We find it to be a reliable product. There aren't bugs or glitches. It doesn't crash or freeze.

What do I think about the scalability of the solution?

The solution can scale if you need it to. That's not a problem at all.

We have more than 10,000 people using the solution currently.

How are customer service and technical support?

When it comes to technical support, so far it's been good. We've been pretty satisfied with their level of support. They are responsive and knowledgeable and we know we can get help when we need it.

Which solution did I use previously and why did I switch?

We were not using any other product before we started using this solution. That said, we registered for other products too and finally decided to go with Carbon Black after trying out other options.

How was the initial setup?

The initial setup isn't really complex. It's pretty straightforward. Those implementing the solution shouldn't have a problem getting it up and running.

The deployment only really took a few months. It was an okay process.

You need very little maintenance on the product. We have about two people here who manage it without any issues.

What other advice do I have?

We're just a customer. We don't have any business affiliation with Carbon Black.

We're currently using the latest version of the solution.

Overall, I would rate the solution seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Ramesh RP - PeerSpot reviewer
Security Analyst at Halian
Real User
Has An Easy Setup In Place; However, Adding Certain Integration Features Would Make It A More Useful Solution
Pros and Cons
  • "I feel that the initial setup was straightforward and not complex."
  • "I am not sure whether Carbon Black CB Defense can be considered as a stable solution or not."

What is our primary use case?

Our primary use case for this solution involves addressing incidents related to malware outbreaks and malicious signatures.

What is most valuable?

Sandboxing is one of the features I found to be the most valuable in Carbon Black CB Defense.

What needs improvement?

It would be good if Splunk integration or something similar to Splunk integration is available for this solution.

For how long have I used the solution?

I have been using the latest version of Carbon Black CB Defense for the past year.

What do I think about the stability of the solution?

I am not sure whether Carbon Black CB Defense can be considered to be a stable solution or not.

What do I think about the scalability of the solution?

I feel that this is a scalable solution. There are around 80 to 90 employees at our organization who are using Carbon Black CB Defense.

How are customer service and support?

I have never contacted the tech support team of Carbon Black CB Defense.

Which solution did I use previously and why did I switch?

In our organization, we have used CTF365 and iZOOlogic in the past. We didn't switch from those since we have a multiple-client setup. One client uses one EDR, while the other one uses the other EDR. So, the intention of having a multiple-client setup at our end is to help our clients, and it is not for the benefit of our company.

How was the initial setup?

I feel that the initial setup was straightforward and not complex. The deployment of the tool is carried out by our engineering team, consisting of 10 members. With the addition of the manager and the other management team members, the total number of individuals involved in the deployment comes to around 25. The engineering team, who are responsible for this activity, ensures the successful deployment of the solution with their expertise.

What other advice do I have?

I would like to see more integration with other platforms. I rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.