Carbon Black CB Defense vs Microsoft Defender for Endpoint comparison

Cancel
You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary
Updated on Apr 4, 2022

We performed a comparison between Carbon Black CB Defense and Microsoft Defender for Endpoint based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Most Carbon Black CB Defense users tell us the solution is very easy to set up and deploy. For many situations, full deployment is completed in less than an hour. Microsoft Defender for Endpoint users feel that although the solution is not complex to deploy, it is also not one they consider “easy.” Average deployment takes from a few hours to days or weeks depending on the system configuration.
  • Features: Carbon Black CB Defense users really like the dynamic grouping, which allows you to group endpoints based on setup criteria. Carbon Black CB Defense has great intelligent learning and outstanding security. If an application has not been approved through Carbon Black, it can not run in the environment - everything has to be approved first. Carbon Black CB Defense users would like to see defense provided for mobile devices and better control over containers. Users also feel the time it takes for an application to be whitelisted should be faster, in addition to making some improvements to the feature set for the firewall.

    Microsoft Defender for Endpoint users appreciate the Attack Surface Reduction controls, the Exploit Prevention Controls, and the Automated Investigation and Response, which do a great job and greatly reduce the SOC workloads. Microsoft Defender for Endpoint has a ransomware solution built into it, which is a very unique option. Users would like to see a more refined console and an improved GUI. Reporting could also be more detailed and onboarding a bit faster.
  • Pricing: Users consistently felt that both solutions were costly.
  • Service and Support: Carbon Black CB Defense users are very satisfied with the service that they receive, many rating it as excellent. Microsoft Defender for Endpoint users mostly feel service needs to be improved, rating it from poor to adequate.

Comparison Results: Based on the above comparison, Carbon Black CB Defense finishes ahead of Microsoft Defender Endpoint. Carbon Black CB Defense is very easy to deploy, is extremely scalable, and offers outstanding security protection. Users indicate that they feel the processor-based definitions is one of the features that make this solution most effective in keeping environments secure.

To learn more, read our detailed Carbon Black CB Defense vs. Microsoft Defender for Endpoint Report (Updated: May 2023).
708,830 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"appreciate the File Trajectory feature, as it's excellent for an analyst or mobile analyst. I can track everything that happens on our server from my PC or device. Integration with SecureX is a welcome feature because it connects Cisco's integrated security portfolio with our complete infrastructure. Sandboxing is helpful, and integration with the Cisco environment is excellent as we use many of their products, and that's very valuable for us.""Another of my favorite features is called the Device Trajectory, where it shows everything that's going on, on a computer. It shows the point in time when a virus is downloaded, so you can see if the user was surfing the internet or had a program open. It shows every running process and file access on the computer and saves it like a snapshot when it detects something malicious. It also has a File Trajectory, so you can even see if that file has been found on any of your other computers that have AMP.""The most valuable feature is its threat protection and data privacy, including its cyber attack and data protection, as we need to cover and protect data on user devices.""Definitely, the best feature for Cisco Secure Endpoint is the integration with Talos. On the backend, Talos checks all the signatures, all the malware, and for any attacks going on around the world... Because Secure Endpoint has a connection to it, we get protected by it right then and there.""The threat Grid with the ability to observe the sandboxing, analyze, and perform investigations of different malicious files has been great.""The best feature that we found most valuable, is actually the security product for the endpoint, formerly known as AMP. It has behavioral analytics, so you can be more proactive toward zero-day threats. I found that quite good.""The integration with other Cisco products seemed to be really effective. We had Umbrella in place and we were using AnyConnect as well as Firepower. Once a threat was detected, being able to do the threat lookups and the live tracking was really useful.""The biggest lesson that I have learned from using this product is that there is a lot more malware slipping through my email filters than I expected."

More Cisco Secure Endpoint Pros →

"I found the offline scanning to be particularly useful.""We can access computers remotely if we need to.""We have another piece of that infrastructure that does what they call threat emulation. It's like sandboxing where it takes files that it doesn't know about, puts them in a VM-type environment, and it kicks them off to see if there's any malware or tendencies that might look like malware, that kind of thing.""The best feature of this solution is that we have a live response, which is really tailored to our needs.""The initial setup is very easy.""CB Defense is more powerful, and you can take more actions than others. Its security features and signatures are constantly updated, so it is more effective than other security solutions.""It has the best live response feature.""The visibility provided has been great."

More Carbon Black CB Defense Pros →

"The stability keeps getting better and better.""Microsoft Defender for Endpoint has been secure and there is zero maintenance required because it updates with Microsoft Windows.""Microsoft Defender for Endpoint is easy to load and it runs quietly in the background, unlike other solutions.""Its threat intelligence feature is beneficial. This solution smoothly integrates with SIEM.""It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool.""We have just started to implement it. It is useful for protection from malware and ransomware.""It comes included with the Windows license.""It depends on the licensing. Most of the customers have got at least a 365 E3 license, and they can use most of the features of Windows 10 Defender. So, anyone who has got an enterprise license can start using those features. Some of the customers have got E5 licenses, and they can use all advanced features. Customers with E5 licenses use the advanced site protection (ATP) features and web content filtering without going via a proxy, which gives the benefit of replacing the proxy. They can get the benefit of MCAS and integration with Intune and the endpoint manager. It is a kind of single platform for all 365 technologies. It helps customers in managing everything through a unified portal."

More Microsoft Defender for Endpoint Pros →

Cons
"In terms of the user experience, if the UX design could be much simpler [that would improve things]... if they could make it more intuitive for someone who is not an engineer so that they still can read what's going on in their webpage and understand, that would be something.""This product has issues with the number of false positives that it reports.""It could be improved in connection with artificial intelligence and IoT.""They could improve the main dashboard to more clearly show me the things that I want to see. When I open the dashboard right now, I see a million things and they are not always the things that I need.""In Orbital, there are tons of prebuilt queries, but there is not a lot of information in lay terms. There isn't enough information to help us with what we're looking for and why we are looking for it with this query. There are probably a dozen queries in there that really focus on what I need to focus on, but they are not always easy to find the first time through.""On the firewall level, they were lagging a little bit behind, but they are running up again. I have full trust in the new 3000 series of firewalls where we would also be able to look more into the traffic that we're monitoring and get more security layers in our services. That would definitely be a big step.""We don't have issues. We think that Cisco covers all of the security aspects on the market. They continue to innovate in the right way.""Cisco is good in terms of threat intelligence plus machine learning-based solutions, but we feel Cisco is lagging behind in using artificial intelligence in its systems."

More Cisco Secure Endpoint Cons →

"The local technical support is very poor, but the support from headquarters is very nice.""The solution needs expanded endpoint query tools.""Integration is difficult, but CB Defense is more powerful than others. It is difficult to implement but easy to pick up many detections.""With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue.""I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others.""I am not sure whether Carbon Black CB Defense can be considered as a stable solution or not.""There's some disparity between the on-premise and the cloud type of application.""The solution would be more effective if there was a way to block automatically based on behavior."

More Carbon Black CB Defense Cons →

"Additional security would be beneficial.""I would like MDE to have the ability to isolate a certain amount of time on the timeline.""Right now, the solution provides some recommendations on the dashboard but we don't have any priorities. It's a mix of all the vulnerabilities and all the security recommendations. I would like to see some priority or categorization of high, medium, and low so that we can fix the high ones first.""Microsoft Defender could be improved with features more like the McAfee ePO. It would be better if I had a console to get all the information for my endpoints. Maybe this is too much for it, but it would be better if it could handle those non-signature-based malicious codes or viruses.""Integration with third-party vendors could be better. It would be better if it integrates with other protection solutions or other products outside of Microsoft. Nowadays, anti-virus protection doesn't really have to be planned as overall protection for your environment in terms of security. There are really different avenues that bad actors can take to wreak havoc on your machine.""My main issue with the tool is that there are too many menus. This causes a steep learning curve for those without training or unfamiliar with Defender for Endpoint. From an end-user perspective, the solution is there on the machine and does its job; it works seamlessly. However, as a security professional dealing with it behind the scenes, the learning curve can be steep, but not too steep. Still, it has taken some of my analysts up to a month to get familiar with the product.""Microsoft Defender for Endpoint could improve by making the reporting better.""I would like Microsoft to have some kind of direct integration for USB controls. They have GPO and other controls to control the access of the USB drives on devices, but if there is something that can be directly implemented into the portal, it would be good. There should be a way to control via a cloud portal or something like that in a dynamic way. USB control for data exfiltration would be a good feature to implement. Currently, there are ways to do it, but it involves too many different things. You have to implement it via GPOs and other stuff, and then you move or copy those big files via Defender ATP. If there is a simple way of implementing those features, it would be great."

More Microsoft Defender for Endpoint Cons →

Pricing and Cost Advice
  • "We have a license for 3,000 users and if we get up to 3,100 users, it doesn't stop working, but on the next renewal date you're supposed to go in there and add that extra 100 licenses. It's really good that they let you grow and expand and then pay for it. Sometimes, with other products, you overuse a license and they just don't work."
  • "Cisco Secure Endpoint is not too expensive and it's not cheap. It's quite fair."
  • "The price is very fair to the customer."
  • "...the licensing needs to be improved. All the product features we need are there. It's just a matter of the complexity and the different offerings and trying to figure things out."
  • "The pricing and licensing fees are okay."
  • "Because we do see the value of what it's bringing, I think they have priced it well."
  • "The solution is highly affordable; I believe we pay $2 or $3 per endpoint. It's significantly cheaper than the competitors on the market."
  • "We had faced some license issues, but it has been improved. At the beginning of the implementation, we faced a lot of licensing issues, but now, we have EA licensing, which gives us an opportunity to grow."
  • More Cisco Secure Endpoint Pricing and Cost Advice →

  • "The license is annual. It's a standard license."
  • "Its pricing was very good, which is one of the reasons I went to it as an alternative. It is on a yearly basis. There are no additional fees."
  • "This is a really expensive product and we pay licensing fees on a yearly basis."
  • "It is more expensive, but it's worth it. There are no additional costs beyond the standard licensing fee."
  • "The licensing cost is on the more expensive side, but I thought it was worth it because they did a good job. It was one of the vendors I truly didn't have to worry about too much until this latest upgrade."
  • "In terms of licensing costs, Carbon Black CB Defense was all associated with CROW and the services my company is using with them, so it came all-inclusive."
  • "The pricing is annually based and operates through another department than mine."
  • "CB Defense is available on a yearly subscription and is priced by the number of endpoints."
  • More Carbon Black CB Defense Pricing and Cost Advice →

  • "Microsoft Defender is an expensive product in my country."
  • "The normal, standalone model, is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive."
  • "Microsoft Defender for Endpoint comes with Windows 10, and it's free. But for you to be able to manage it in the cloud and use the console, you need to have either an Office 365 E5 subscription or a Microsoft M365 subscription. You need to buy an extra license."
  • "As we operate in the educational sector, we are eligible for an educational discount."
  • "The subscription is part of Windows, so we don't have to pay anything extra for this product."
  • "It is so expensive. It isn't cheaper than McAfee or other solutions."
  • "It is free."
  • "You don't need to worry about the renewal and purchase of antivirus products. It is bundled with Windows 10, so you don't need to worry about separately purchasing any antiviruses."
  • More Microsoft Defender for Endpoint Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which EPP (Endpoint Protection for Business) solutions are best for your needs.
    708,830 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The best feature that we found most valuable, is actually the security product for the endpoint, formerly known as AMP… more »
    Top Answer:On the firewall level, they were lagging a little bit behind, but they are running up again. I have full trust in the… more »
    Top Answer:I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR)… more »
    Top Answer:Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoint… more »
    Top Answer:SentinelOne is hands down my recommended solution. SentinelOne has not been breached and offers upto $1,000,000… more »
    Top Answer:Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface… more »
    Top Answer:We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior… more »
    Top Answer:The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push… more »
    Comparisons
    Also Known As
    Cisco AMP for Endpoints
    Bit9, Confer
    Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
    Learn More
    Cisco
    Video Not Available
    Overview

    Cisco Secure Endpoint is a comprehensive endpoint security solution that natively includes open and extensible extended detection and response (XDR) and advanced endpoint detection and response (EDR) capabilities.

    Secure Endpoint offers relentless breach protection that enables you to be confident, be bold, and be fearless with one of the industry’s most trusted endpoint security solutions. It protects your hybrid workforce, helps you stay resilient, and secures what’s next with simple, comprehensive endpoint security powered by unique insights from 300,000 security customers and deep visibility from the networking leader.

    Learn more about Secure Endpoint: www.cisco.com/go/endpoint

    Cisco Secure Endpoint was formerly known as Cisco AMP for Endpoints.

    Reviews from Real Users

    Cisco Secure Endpoint stands out among its competitors for a number of reasons. Two major ones are its ability to enable developers to easily secure their endpoints with one single operation using its management console and its advanced alerting techniques.

    Tim C., an IT manager at Van Der Meer Consulting, writes, "The solution makes it possible to see a threat once and block it everywhere across all endpoints and the entire security platform. It has the ability to block right down to the file and application level across all devices based on policies, such as, blacklisting and whitelisting of software and applications. This is good. Its strength is the ability to identify threats very quickly, then lock them and the network down and block the threats across the organization and all devices, which is what you want. You don't want to be spending time working out how to block something. You want to block something very quickly, letting that flow through to all the devices and avoiding the same scenario on different operating systems."

    Wouter H., a technical team lead network & security at Missing Piece BV, notes, "Any alert that we get is an actionable alert. Immediately, there is information that we can just click through, see the point in time, what happened, what caused it, and what automatic actions were taken. We can then choose to take any manual actions, if we want, or start our investigation. We're no longer looking at digging into information or wading through hundreds of incidents. There's a list which says where the status is assigned, e.g., under investigation or investigation finished. That is all in the console. It has taken away a lot of the administration, which we would normally be doing, and integrated it into the console for us."

    CB Defense is an industry-leading next-generation antivirus (NGAV) and endpoint detection and response (EDR) solution. CB Defense is delivered through the CB Predictive Security Cloud, an endpoint protection platform that consolidates security in the cloud using a single agent, console and data set. CB Defense is certified to replace AV and designed to deliver the best endpoint security with the least amount of administrative effort. It protects against the full spectrum of modern cyber attacks, including the ability to detect and prevent both known and unknown attacks. CB Defense leverages the powerful capabilities of the CB Predictive Security Cloud, applying our unique streaming analytics to unfiltered endpoint data in order to predict, detect, prevent, respond to and remediate cyber threats. In addition, CB Defense provides a suite of response and remediation tools, including Live Response, which allows security personnel to perform remote live investigations, intervene with ongoing attacks and instantly remediate endpoint threats. For peace of mind, CB Defense customers can also leverage CB ThreatSight, Carbon Black’s managed threat alert service, to validate alerts and uncover new threats.

    Microsoft Defender for Endpoint is a complete endpoint security solution that delivers preventative protection, post-breach detection, automated investigation, and response. With Defender for Endpoint, you have: 

    Agentless, cloud powered - No additional deployment or infrastructure. No delays or update compatibility issues. Always up to date. 

    Unparalleled optics - Built on the industry’s deepest insight into Windows threats and shared signals across devices, identities, and information. 

    Automated security - Take your security to a new level by going from alert to remediation in minutes—at scale. 

    To learn more about our solution, ask questions, and share feedback, join our Microsoft Security, Compliance and Identity Community.
    Offer
    Learn more about Cisco Secure Endpoint
    Learn more about Carbon Black CB Defense
    Learn more about Microsoft Defender for Endpoint
    Sample Customers
    Heritage Bank, Mobile County Schools, NHL University, Thunder Bay Regional, Yokogawa Electric, Sam Houston State University, First Financial Bank
    Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
    Petrofrac, Metro CSG, Christus Health
    Top Industries
    REVIEWERS
    Computer Software Company12%
    Healthcare Company12%
    Comms Service Provider12%
    Government8%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Government9%
    Financial Services Firm7%
    Comms Service Provider7%
    REVIEWERS
    Manufacturing Company18%
    Computer Software Company16%
    Financial Services Firm11%
    Construction Company11%
    VISITORS READING REVIEWS
    Computer Software Company16%
    Government9%
    Financial Services Firm8%
    Manufacturing Company6%
    REVIEWERS
    Financial Services Firm20%
    Computer Software Company16%
    Energy/Utilities Company7%
    Comms Service Provider7%
    VISITORS READING REVIEWS
    Computer Software Company16%
    Educational Organization12%
    Government9%
    Financial Services Firm8%
    Company Size
    REVIEWERS
    Small Business32%
    Midsize Enterprise24%
    Large Enterprise44%
    VISITORS READING REVIEWS
    Small Business28%
    Midsize Enterprise17%
    Large Enterprise55%
    REVIEWERS
    Small Business39%
    Midsize Enterprise16%
    Large Enterprise45%
    VISITORS READING REVIEWS
    Small Business28%
    Midsize Enterprise18%
    Large Enterprise54%
    REVIEWERS
    Small Business40%
    Midsize Enterprise16%
    Large Enterprise44%
    VISITORS READING REVIEWS
    Small Business24%
    Midsize Enterprise24%
    Large Enterprise52%
    Buyer's Guide
    Carbon Black CB Defense vs. Microsoft Defender for Endpoint
    May 2023
    Find out what your peers are saying about Carbon Black CB Defense vs. Microsoft Defender for Endpoint and other solutions. Updated: May 2023.
    708,830 professionals have used our research since 2012.

    Carbon Black CB Defense is ranked 15th in EPP (Endpoint Protection for Business) with 25 reviews while Microsoft Defender for Endpoint is ranked 1st in EPP (Endpoint Protection for Business) with 114 reviews. Carbon Black CB Defense is rated 7.6, while Microsoft Defender for Endpoint is rated 8.2. The top reviewer of Carbon Black CB Defense writes "The manage, detect, and response feature enables Carbon Black to continuously check logs and advise us on how to improve some of the policies". On the other hand, the top reviewer of Microsoft Defender for Endpoint writes "Enables ingestion of events directly into your SIEM/SOAR, but requires integration with all Defender products to work optimally". Carbon Black CB Defense is most compared with CrowdStrike Falcon, SentinelOne Singularity Complete, Trend Micro Deep Security, Secureworks Red Cloak Threat Detection and Response and Symantec Endpoint Security, whereas Microsoft Defender for Endpoint is most compared with Sophos Intercept X, Symantec Endpoint Security, CrowdStrike Falcon and SentinelOne Singularity Complete. See our Carbon Black CB Defense vs. Microsoft Defender for Endpoint report.

    See our list of best EPP (Endpoint Protection for Business) vendors and best EDR (Endpoint Detection and Response) vendors.

    We monitor all EPP (Endpoint Protection for Business) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.