The product is an endpoint security product. It's kind of like a replacement for a traditional antivirus.
Information Security Specialist at a comms service provider with 5,001-10,000 employees
Scalable, lightweight, and easy to deploy
Pros and Cons
- "The visibility provided has been great."
- "The solution needs expanded endpoint query tools."
What is our primary use case?
How has it helped my organization?
One of the strong features of the product is its endpoint visibility. It gives you more visibility than a traditional antivirus would give you.
What is most valuable?
The visibility provided has been great.
The ease of deployment is definitely a great selling feature.
The stability is good and the product is pretty lightweight.
The solution scales well.
What needs improvement?
The reporting could be improved. Some of the built-in reporting isn't ideal. They have an API and everything you need that you can kind of hook into the product pretty easily, however, it'd be nice to have some built-in reports instead of having to seek them elsewhere.
The solution needs expanded endpoint query tools.
Buyer's Guide
VMware Carbon Black Endpoint
February 2025

Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for about a year.
What do I think about the stability of the solution?
The stability of the solution is good. There are no bugs or glitches. It doesn't crash or freeze. It seems to be a little bit lighter on resources than our previous antivirus.
What do I think about the scalability of the solution?
The product can be scaled pretty high. We have about 3000 sensors deployed. However, it can go a lot higher than that. It depends on your internet connection for the reporting or the information, basically.
We have kind of a desktop security team that is about five individuals that administer the product part-time, and that can access the console. A couple of them are the ones that spend the most time in it.
We use the solution extensively and we may look at expanding the EDR - stepping up to one of the other products and adding capabilities. Therefore, we're likely to increase usage in some form in the future.
How are customer service and support?
Technical support needs some improvement. They don't seem to respond so well to technical help. The good thing is we don't need that much, however, they need to probably improve that a little bit for others who might require more assistance.
Which solution did I use previously and why did I switch?
We had McAfee antivirus and it was difficult to tune the policy without compromising security, I would say. Its footprint was a little high. Its performance wasn't that great in terms of end-point performance.
How was the initial setup?
The solution is easy to deploy. The implementation process is simple. It's not overly complex or difficult.
While the rollout is pretty easy, you have to kind of tune it a little bit for applications as it discovers them.
To deploy a sensor, it takes just a couple of minutes or so. Then, to kind of tune the policy itself, you are probably looking at a couple of weeks.
What about the implementation team?
Initially, we use the services provided by the vendor, like an on-ramp kind of service. They were great. The team was pretty helpful.
What's my experience with pricing, setup cost, and licensing?
We pay about $15 a node. It's just a standard licensing fee and that's it.
What other advice do I have?
I'm just a customer and an end-user.
I've been using the latest version of the solution.
The sensors are on-premises, however, the console is in the cloud. It's a VMware product that runs on Amazon.
I'd advise those considering the solution to seek out some of the training to see if you can get it bundled in with the deployment. The more advanced training, to kind of how to tune the policy and stuff like that, would be helpful to have.
I'd rate the solution at an eight out of ten as there's still room for improvement in things like reporting. However, the impact on performance and the ability to have greater visibility were pluses in my book.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: I am a real user, and this review is based on my own experience and opinions.

We can instantly respond if a false positive occurs
Pros and Cons
- "The product allows us to focus on endpoint and antivirus protection."
- "The GUI and reporting should be addressed and the product's administration features need fine tuning."
What is our primary use case?
While there is an IR team that is responsible for managing EDR or deep analytics, our focus is on endpoint and antivirus protection. This is where we encounter signature updates. We look for false positives in their relation to file interpretation. Should anything occur, we can instantly respond. Instead of sending a sample and getting coverage, we can put a policy and place an immediate stop on the false positives.
What needs improvement?
While I consider the product to be top notch and am happy with it, its reporting aspects need to be addressed.
I would definitely recommend Carbon Black CB Defense to others who are contemplating using it, but its administration features need fine tuning. I believe this is already being addressed so that gaps can be filled as these relate to other leading technologies on the market.
The GUI and reporting should also be addressed.
For how long have I used the solution?
We have been using Carbon Black CB Defense for the past seven to eight months.
How are customer service and technical support?
I have not had occasion to make use of technical support, although I may have in the future, as I am the product person who is working with another experienced team and there is a process under way to migrate from McAfee to Carbon Black CB Defense.
How was the initial setup?
The initial setup was a bit difficult since we had to do it manually or through the use of a script.
What's my experience with pricing, setup cost, and licensing?
The price for the solution is completely at government level, meaning one which is very high, although it is up to management to consider this criteria.
What other advice do I have?
Our company has over a thousand people who utilize the product. Going forward, everything will be managed by Carbon Black CB Defense.
I would rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
VMware Carbon Black Endpoint
February 2025

Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.
Vice President of Sales (previously Sales Engineer) at a computer software company with 11-50 employees
Easy to scale, technical support is good, and the product stops spyware, malware, and viruses in their tracks
Pros and Cons
- "It has intelligent learning behind it and we have been very successful in preventing attacks."
- "At this point, we're test-bedding several other providers right now to see if there's anything that does equally or better and that comes at a better price point."
What is our primary use case?
The primary use case is for stopping spyware, malware, and viruses in their tracks.
It's very good at doing that. It has intelligent learning behind it and we have been very successful in preventing attacks.
How has it helped my organization?
We had a six-figure revenue stream knowing that we would be cleaning up viruses, malware, and spyware on PCs, every year. That was a revenue stream that we could just budget we were going to get. When we implemented Carbon Black, that revenue stream went to zero. That means that it's doing its job.
From a business perspective, we've been able to virtually eliminate cyber attacks from spyware, malware, and virus perspectives.
What is most valuable?
It has intelligent learning behind it and we have been very successful in preventing attacks.
For how long have I used the solution?
I have been using Carbon Black CB Defense for approximately three years.
We are using the most recent version.
What do I think about the stability of the solution?
The stability is fantastic!
What do I think about the scalability of the solution?
The scalability is pretty easy.
Their offer to add to a tenant or spin up a new tenant, given the client sizes is large enough, has been pretty easy management so far.
I'm a managed service provider, and within my organization we only have between 40 and 50 employees managing endpoints for several thousand. My perspective will be slightly different. So, even though we use it as a company, we use this for our clients as well.
100% of our staff is trained on the use of Carbon Black because from the technical perspective, we need to be able to handle that as technicians and engineers.
As far as our clients, they don't know the difference. They don't see issues, they don't have attacks.
How are customer service and technical support?
My interaction over the phone has been mostly on the business side of Carbon Black and they're fantastic over the phone. They're fantastic to deal with.
As far as the support side, I've never had to make a call to them.
I'm sure our lead engineer has had to make some calls for various reasons.
How was the initial setup?
The initial setup is straightforward. It's super easy.
What about the implementation team?
Our staff deployed this solution. We did not use an integrator or reseller, it was in-house.
Which other solutions did I evaluate?
I am currently reviewing Cylance and products from other vendors as part of our processes. We want to see what price points and feature sets and things like that, to see what would be better.
We want to know how Carbon Black compares to others; we've seen a little bit of that. I've got some documentation to review that. At this point, we're test-bedding several other providers right now to see if there's anything that does equally or better and that comes at a better price point.
What other advice do I have?
We have the cloud center, however, the application's installed on each endpoint individually.
Each client machine has it installed, locally, so it's off-premises for us. I'm assuming that they would be running on individual client PC.
The software is run here, we manage it within the cloud atmosphere.
We were an authorized reseller or we were an authorized business associate of Carbon Black. Since that's moved under Dell, I don't think that's a thing anymore. I would state that as we are mainly a Dell shop, we're an all in Dell shop. And so that's just a business decision we've made.
We were a Dell VMware Carbon Black client and we had a relationship with them that preexisted our Dell partnership. Before Dell acquired Carbon Black, we were a partner of Carbon Black's. We had acquired this technology and we were utilizing this technology for several years in advance of that acquisition.
I'd recommended Carbon Black CB Defense 100%.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Manager, IT Security and Compliance / CISO at Superior Energy Services, Inc.
Detects and protects against malicious executable files, allows investigation using CLI
Pros and Cons
- "The most valuable feature is that it detects and stops malicious executables."
- "This solution works well but needs lots of tuning and optimization."
What is our primary use case?
We use this solution for endpoint security and protection.
What is most valuable?
The most valuable feature is that it detects and stops malicious executables.
Admins can use the portal to obtain a command shell on an endpoint to perform further investigation.
What needs improvement?
This solution works well but needs lots of tuning and optimization.
For how long have I used the solution?
We have been using this solution for two months.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Administrator at a manufacturing company with 501-1,000 employees
Puts very little load on the servers, does an excellent job, and has very good pricing
Pros and Cons
- "I found it very valuable as a whole. It is good at detecting anything and has kept us very safe. It is also very easy to use."
- "I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others."
What is our primary use case?
It is used for protecting our file servers. Its version is kept up to date, so it should be fairly current.
How has it helped my organization?
We found that Trend Micro was producing a little bit more load on our servers than what we wanted. So, we went to Carbon Black because it was integrated with VMware. It is great on the servers. It puts very little load, and it does an excellent job.
What is most valuable?
I found it very valuable as a whole. It is good at detecting anything and has kept us very safe. It is also very easy to use.
What needs improvement?
I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others.
For how long have I used the solution?
I have been using it for close to a year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
I believe it is very scalable. In terms of its users, for the most part, there are only two of us using it. I am the IT administrator and primary user, and we have an IT support person who handles PCs and backs me up on servers. We are taking care of its deployment and maintenance.
We are looking at the possibility of expanding its usage in the future to include desktops.
How are customer service and support?
I've never had to call technical support.
Which solution did I use previously and why did I switch?
We were using Trend Micro Apex One on our servers, and we found that Trend Micro tended to load the servers up a little bit. That's why we switched to Carbon Black.
How was the initial setup?
It was very straightforward. It was very easy to set up.
Its deployment didn't take that long at all. We purchased it and then just installed it on different servers, one at a time.
What about the implementation team?
We did it ourselves.
What was our ROI?
I've never calculated an ROI on it.
What's my experience with pricing, setup cost, and licensing?
Its pricing was very good, which is one of the reasons I went to it as an alternative. It is on a yearly basis. There are no additional fees.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
If you're running a VMware environment, you can definitely go ahead and use it.
I would rate it a 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior NOC Security Engineer at a wholesaler/distributor with 51-200 employees
Implementation and upgrading difficult but operates well
Pros and Cons
- "Once the solution is installed and configured correctly it does not require a lot of hands-on attention until you need upgrading."
- "There are many different controls that are needed to be put into place for upgrading that makes it difficult. Having to re-engineer your IT infrastructure to match their software, as opposed to having it integrate and work independently causes difficulties. When there is an update to any software everyone has to be involved."
What is our primary use case?
My clients are using this solution for security as their frontline defense. They are using a whitelist that has all known software allowed.
What is most valuable?
Once the solution is installed and configured correctly it does not require a lot of hands-on attention until you need upgrading.
What needs improvement?
There are many different controls that are needed to be put into place for upgrading that makes it difficult. Having to re-engineer your IT infrastructure to match their software, as opposed to having it integrate and work independently causes difficulties. When there is an update to any software everyone has to be involved.
For how long have I used the solution?
I have been using this solution for approximately six years.
What do I think about the stability of the solution?
The solution has been working well, nothing stands out as an issue.
What do I think about the scalability of the solution?
I have found this solution to be highly scalable. We have clients that are large-size companies using this solution.
How are customer service and technical support?
The technical support was great when we used them.
I rate the technical support of Carbon Black CB Defense a nine out of ten.
How was the initial setup?
The solutions provider has made great strides in the last four years making it easier to implement. However, the way their architecture is makes it difficult, the installation is quite a cumbersome process to integrate everything together.
What other advice do I have?
My advice to those wanting to implement this solution is it not easy and it takes time and money.
I rate Carbon Black CB Defense a five out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Consultant at a healthcare company with 10,001+ employees
Easy to install, stable, with good historical features and integration
Pros and Cons
- "I like the historical features, interface, and integration."
- "The feature set for the firewall needs improvement."
What is our primary use case?
We are using the Carbon Black CB Defense for endpoint security.
What is most valuable?
I like the historical features, interface, and integration.
What needs improvement?
The feature set for the firewall needs improvement.
I am looking forward to learning more about the integration with VMware at the hypervisor layer.
For how long have I used the solution?
I dealt with Carbon Black CB Defense approximately seven years ago, but have recently dealt with them again in the last six months.
What do I think about the stability of the solution?
At this stage, we have not experienced any issues.
How are customer service and technical support?
We have not raised the case at this point with technical support.
How was the initial setup?
The initial setup was straightforward.
We are still deploying this solution but it will probably take four to six weeks.
What's my experience with pricing, setup cost, and licensing?
It's reasonable in price. We got a good price.
Which other solutions did I evaluate?
We were looking at either keeping our Symantec Endpoint, and evaluating Trend Micro, and CrowdStrike.
We chose Carbon Black because of Its integration, features, and usability.
What other advice do I have?
I would recommend Carbon Black CB Defense for anyone who is interested in implementing this solution.
I would rate Carbon Black CB Defense and eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Has good technical support, but it is challenging to check the status of ongoing scans
Pros and Cons
- "It has the best live response feature."
- "It is difficult to extract reports for ongoing scans"
What is our primary use case?
We use the solution for threat detection and endpoint protection. It generates alerts in case of invalid signatures while installing software.
What is most valuable?
The solution's most valuable feature is live response. We can verify and view the task list and the processes. Also, we can create policies with its help.
What needs improvement?
It is challenging to extract a report on the status of ongoing scans. They should work on this particular area of the solution.
How are customer service and support?
The solution's customer service team responds quickly.
How would you rate customer service and support?
Positive
What other advice do I have?
I rate the solution as seven.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Protection Platform (EPP) Security Incident Response Endpoint Detection and Response (EDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
ESET Endpoint Protection Platform
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What Is The Biggest Difference Between BigFix And Carbon Black Cb Defense?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
- Running Carbon Black Defense Along with Windows Defender
- What Is The Biggest Difference Between Carbon Black Cb Defense And ESET Endpoint Security?
- Which product has better reputation: Carbon Black CB Defense or CrowdStrke Falcon?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?