CB Defense could be more compatible with Linux, and its cloud provision could be improved.
Sales Operations Specialist at ADEO IT Consulting Services
Shows the whole process of events but has compatibility problems with Linux
Pros and Cons
- "The initial setup was fairly easy."
- "CB Defense could be more compatible with Linux, and its cloud provision could be improved."
What needs improvement?
For how long have I used the solution?
I've been using CB Defense for two years.
What do I think about the scalability of the solution?
CB Defense is scalable so long as the deployment has been done correctly.
How are customer service and support?
Carbon Black's support team are very slow to answer questions.
Buyer's Guide
VMware Carbon Black Endpoint
February 2025

Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.
How was the initial setup?
The initial setup was fairly easy. Deployment will take one to two weeks, depending on how many endpoints there are.
What's my experience with pricing, setup cost, and licensing?
CB Defense is available on a yearly subscription and is priced by the number of endpoints.
What other advice do I have?
I would recommend CB Defense for users who want an on-prem solution that lets them see the whole process of any event. I would give CB Defense a rating of six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

CEO at Haniya Technologies
Quick to deploy with a very powerful antivirus engine and and helpful technical support
Pros and Cons
- "The product is pretty strong in terms of security and their features are very good in that respect."
- "The pricing could be more reasonable."
What is our primary use case?
We primarily leverage the product for its security functionality.
What is most valuable?
The product is pretty strong in terms of security and their features are very good in that respect. Their research engine, the antivirus engine, it's very strong compared to any other product on the market right now.
The solution is stable.
They do have options on the market that can scale.
Technical support is great.
It's not too difficult to set up and the deployment is fast.
What needs improvement?
Carbon Black does not have a big market in Pakistan right now. They are actually trying to penetrate the region right now. They don't have many customers. Even we are new to the Carbon Black as well, in that we knew about Carbon Black for a long time, however, as far as implementing it and giving it to our customers, we are still new to it.
The pricing could be more reasonable.
For how long have I used the solution?
I've been dealing with the solution for six to seven years or so. It's been a while.
What do I think about the stability of the solution?
The stability has been excellent. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. The performance is good.
What do I think about the scalability of the solution?
There are versions of the product that can scale.
We have about three customers that use the product at this time. It's not that many as it's not a well-known product in our region.
How are customer service and support?
Normally they have pretty good technical support. Specifically, if you purchase the technical support directly from Carbon Black, then they are very responsive and very quick.
Which solution did I use previously and why did I switch?
I also deal with McAfee and Kaspersky.
How was the initial setup?
The initial setup is pretty straightforward, and the deployment is fairly quick. Of course, it depends on the environment. However, it shouldn't take more than a day or two to set up and to have everything up and running.
We have one person, an engineer, that can handle deployment and maintenance tasks as necessary.
What about the implementation team?
We are able to implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
The pricing could always be a bit better. They could work to make it less expensive. Right now, they are far and above more expensive than other similar options on the market.
The license costs are paid yearly.
What other advice do I have?
We are resellers.
The solution can be deployed both on-premises and in the cloud.
I would definitely advise new users of just this one thing: that before thinking about Carbon Black or purchasing it, they should look for other solutions as well. As far as the cost is concerned, Carbon Black is much more expensive than any other product. That's something that needs to be taken into account.
I would rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
VMware Carbon Black Endpoint
February 2025

Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
839,422 professionals have used our research since 2012.
ICT/Systems Application Engineer at Honeywell
Works well and instantly, responsive technical support, with high scalability
Pros and Cons
- "The whole purpose of the product, like application control, is very good, and also if you need to update some policies, it works well and instantly."
- "I would like to see the user credentials feature improved. I would also like to see more reporting features and better ways to roll the reports out."
What is our primary use case?
Our primary use case is for application control.
What is most valuable?
The whole purpose of the product, like application control, is very good, and also if you need to update some policies, it works well and instantly.
What needs improvement?
I would like to see the user credentials feature improved. I would also like to see more reporting features and better ways to roll the reports out.
For how long have I used the solution?
I have been using Carbon Black CB Defense for more than a year.
What do I think about the stability of the solution?
I would say the stability is high a nine on a scale of one to ten.
What do I think about the scalability of the solution?
On a scale of one to ten, I would give it a nine for being highly scalable.
How are customer service and support?
Technical support is pretty responsive. I have not had to use them a lot and when we need them we route them through our team.
How was the initial setup?
The initial setup was straightforward I had some minor issues with the web application I logged in and fixed them. The initial deployment only took about half a day. We have deployed to around one hundred systems.
What about the implementation team?
The deployment was done in-house.
What's my experience with pricing, setup cost, and licensing?
The pricing is annually based and operates through another department than mine.
What other advice do I have?
I would rate Carbon Black CB Defense an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
IT Manager - System Administration at a pharma/biotech company with 501-1,000 employees
Easy to set up and offers good protection but the on-premises deployment has a lot of issues
Pros and Cons
- "The initial setup is very easy."
- "With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue."
What is our primary use case?
We primarily use the solution for operations and also security. On the security front, we have a specific project that's ongoing right now. We are moving away from the on-prem Carbon Black to the cloud one.
We primarily use the solution for endpoint protection.
What is most valuable?
The protection of the user machines has been great. For example, if a laptop gets stolen, or let's say, an employee gets let go, the product provides us with the ability to actually lock people out of the network and handle remote wipes and stuff like that.
The initial setup is very easy.
What needs improvement?
The on-prem one was very problematic, especially version 7.2, which did not play nice with Symantec at all. The last upgrade of the client actually triggered a block to the networking, to our active directory domain controllers.
There was a bug that we found was in Macs. It was triggering false positives as it wasn't able to figure out the right parent upon login. With the Carbon Black Cloud, we just got it two to three weeks ago. So far, I haven't seen any false positives. The cloud seems to be a much better product.
With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue.
I need more time to explore the cloud deployment, as we've only had it for three weeks at this point.
For how long have I used the solution?
It's been at least four years since we started using the solution. Four or five years.
We started with the on-prem one and now we're in yet another project with a cloud deployment.
What do I think about the stability of the solution?
While the on-prem has some bugs we have been dealing with, so far, after using the could for three weeks, it's like night and day. It's been very stable. There are no bugs or glitches.
What do I think about the scalability of the solution?
I'm not aware of the scalability capabilities yet, as I don't have the entire company on it yet. We are still in testing mode. We just got the cloud deployment three weeks ago. So I can't really answer that truthfully.
Right now, we have seven people on the solution currently.
How are customer service and technical support?
We haven't yet used the technical support. I can't speak to how helpful or responsive they would be.
That said, we did use technical support when we were on the on-premises version, and they were terrible. We would ask for bug fixes and new versions would come and yet they would not actually fix the problems that were highlighted.
Which solution did I use previously and why did I switch?
We also use Red Cloak, which is a completely different prody=uct and something that we still use.
How was the initial setup?
The initial setup is very simple. The cloud version in particular is very simple. It's not overly complex or difficult.
What's my experience with pricing, setup cost, and licensing?
I'm not dealing with the pricing. I can't speak to the costs involved.
What other advice do I have?
There are two versions of Carbon Black that VMware has, one of them is the on-prem one and the endpoint clients are in the user machines and servers, so AWS and data center and VSS.
I'd advise those interested in the solution to go with the cloud deployment model. We've had a lot of issues with the on-premises version.
I'd rate the solution at a seven out of ten. There seems to be quite a disparity between the cloud and on-premises versions.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Systems engineer at SAT
Identifies endpoint and infrastructure loopholes
Pros and Cons
- "Carbon Black Cb Defense improved our endpoint level security. It helped to identify endpoint and infrastructure loopholes."
- "Carbon Black Cb Defense has a nice component called Alert Triage. It contains full details of the process execution "kill chain" and "go live" for immediate remediation."
- "It would be a better solution if Carbon Black Cb Defense had an on-promise solution and a virus auto delete or quarantine."
What is our primary use case?
This product would help any organization to increase its detection and prevention with event investigations and immediate response to data infiltration.
How has it helped my organization?
Carbon Black Cb Defense improved our endpoint level security. It helped to identify endpoint and infrastructure loopholes.
What is most valuable?
Carbon Black Cb Defense has a nice component called Alert Triage. It has helped to detect threats across the data. It contains full details of the process execution "kill chain" and "go live" for immediate remediation.
What needs improvement?
It would be a better solution if Carbon Black Cb Defense had an on-promise solution and a virus auto delete or quarantine.
For how long have I used the solution?
One to three years.
What do I think about the scalability of the solution?
No scalability issues.
How was the initial setup?
The initial setup is straightforward. The configurations are a bit complex.
What about the implementation team?
The vendor has a high level of expertise.
What's my experience with pricing, setup cost, and licensing?
The cost is a considerable factor, but the benefit factor is the most important. When you compare it with other products, the price is high. Carbon Black will negotiate the price.
Which other solutions did I evaluate?
We evaluated McAfee and Symantec.
What other advice do I have?
I have done a few PoCs and implementations with Carbon Black Cb Defense.
Disclosure: My company has a business relationship with this vendor other than being a customer: Our company has engaged with Carbon Black as an exclusive partner in Sri Lanka.
IT Manager at a financial services firm with 51-200 employees
Straightforward to set up, provides automatic site blocking, and forwards information to our SOC
Pros and Cons
- "One of the most valuable features is that it will block vulnerable sites. If there was a connection between one of our devices to a known malware site, it will block it."
- "This product should be cheaper."
What is our primary use case?
We primarily use this product to provide threat intelligence to our SOC about our endpoints.
What is most valuable?
One of the most valuable features is that it will block vulnerable sites. If there was a connection between one of our devices to a known malware site, it will block it. Then also alerts our SOC.
What needs improvement?
This product should be cheaper.
For how long have I used the solution?
I have been working with Carbon Black CB Defense for three years.
What do I think about the stability of the solution?
Stability-wise, it is good.
What do I think about the scalability of the solution?
I am satisfied with the scalability. We use it across the company and all of the users have it on their laptops. It's a mixture of IT people, finance, doctors, lawyers, dentists, and other professional services. It's a wide range of people and there are about 180 in total.
How are customer service and support?
The technical support is okay.
Which solution did I use previously and why did I switch?
We also use Sophos Intercept X in our business.
How was the initial setup?
CB Defense is pretty straightforward to set up.
What about the implementation team?
The implementation was done by my own team.
What's my experience with pricing, setup cost, and licensing?
This is a really expensive product and we pay licensing fees on a yearly basis. The subscription includes technical support.
What other advice do I have?
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SOC Manager at Nais Srl
Informative, dependable, and ideal for a medium-sized companies
Pros and Cons
- "It is a very complete platform."
- "They will most likely need to create or include a feature that checks the network."
What is most valuable?
It is a very complete platform. It is very useful for my customers.
Carbon Black CB Defense is ideal for a medium-sized business. It is not, in my opinion, suited for large enterprise companies.
Carbon Black works very well for the endpoint. It explains the situation very clearly.
What needs improvement?
I believe they could improve the new intelligence solution to monitor activity, in the network. They will most likely need to create or include a feature that checks the network.
For how long have I used the solution?
I have worked with Carbon Black CB Defense for three or four years.
What do I think about the stability of the solution?
Carbon Black CB Defense is a very stable product.
What do I think about the scalability of the solution?
The scalability of Carbon Black CB Defense is very good.
What other advice do I have?
I would rate Carbon Black CB Defense an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
IT Security Solutions Engineer at Softprom
Good threat analysis, stable, and the technical support is good
Pros and Cons
- "The threat analysis functionality is good."
- "I would like to see improvements made so that we can better see all of the processes."
What is our primary use case?
We are a distributor for Carbon Black and CB Defense is one of the products that we work with and demo for our customers.
How has it helped my organization?
With the Carbon Black endpoint Agent, we have automated the process of isolating the host when a threat appears on it.
What is most valuable?
Using Open API, we were able to freely perform the necessary integration with our other security solutions.
CB Defense allows us to see our whole process as it starts on our endpoint.
The threat analysis functionality is good.
What needs improvement?
To improve the ability to connect also feeds of third resources (communities).
For how long have I used the solution?
We have been using this product for more one year.
What do I think about the stability of the solution?
CB Defense is a stable solution. I do not remember any situations where there are any problems with sensors or endpoints. Just all information about the processes at the endpoint is collected and sent to the Cloud.
What do I think about the scalability of the solution?
This is a scalable product.
How are customer service and technical support?
The technical support is good and we always get answers to all our questions and necessary recommendations for using the Carbon Black Defense.
What other advice do I have?
Overall, this is a very good product.
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner

Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Protection Platform (EPP) Security Incident Response Endpoint Detection and Response (EDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
ESET Endpoint Protection Platform
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I would like to compare CrowdStrike and Carbon Black. On what basis should I decide?
- What Is The Biggest Difference Between BigFix And Carbon Black Cb Defense?
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
- Running Carbon Black Defense Along with Windows Defender
- What Is The Biggest Difference Between Carbon Black Cb Defense And ESET Endpoint Security?
- Which product has better reputation: Carbon Black CB Defense or CrowdStrke Falcon?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?