No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Endpoint vs VMware Carbon Black Cloud comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
6th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
112
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
NetWitness Endpoint
Ranking in Endpoint Detection and Response (EDR)
51st
Average Rating
8.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
No ranking in other categories
VMware Carbon Black Cloud
Ranking in Endpoint Detection and Response (EDR)
56th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
19
Ranking in other categories
Security Incident Response (4th)
 

Mindshare comparison

As of June 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.5%, down from 4.0% compared to the previous year. The mindshare of NetWitness Endpoint is 0.2%, up from 0.0% compared to the previous year. The mindshare of VMware Carbon Black Cloud is 0.6%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.5%
NetWitness Endpoint0.2%
VMware Carbon Black Cloud0.6%
Other95.7%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
LA
Computer Security Consultant at SECURE SOFT
Machine learning capabilities enhance risk management for financial industry deployments
At my company, we usually use NetWitness Endpoint for our customers with a primary focus on the financial industry, where eighty to ninety percent of our deployments occur NetWitness Endpoint offers the capability of machine learning or artificial intelligence. It provides a risk score for each…
reviewer2771742 - PeerSpot reviewer
Sec consultant at a tech services company with 5,001-10,000 employees
Has supported consistent deployment across departments but needs better OS compatibility and detection performance
I am not really looking for a new solution, actually, I was preparing for an interview and wanted to have a comparison between both tools. I have not worked with any of these products before, but we had a training demonstration yesterday with Dynatrace, and I have investigated the Wiz solution better. In terms of experience, it will be my first time with CDR. I am working with something for EDR, specifically, we have an EDR, it's VMware Carbon Black Cloud. They have a hybrid environment, both on-prem and cloud. I would usually recommend this product for big companies, because it's not cheap, so only big companies would I expect to pay for that. The review rating for VMware Carbon Black Cloud is 6 out of 10.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that you can select remote access of any machine for sandboxing."
"These days it's machine-learning technology and behavior-based analytics features that make us more secure."
"The live terminal is probably the best thing ever. It gives you the access to get straight onto any machine."
"Implementing Cortex XDR by Palo Alto Networks has had a significant impact on my security analyst workload because it becomes much easier."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities."
"The stability of this product is very good."
"Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
"NetWitness Endpoint offers the capability of machine learning or artificial intelligence."
"With this solution, you can do so remotely; this is valuable because you don't have to bring the computer onsite to analyze it and it decreases response time by about 40 percent."
"For setup, the server can be given to you as a VM image and with minimal configuration needed."
"Carbon Black Cb Response significantly reduced time to containment in the environment which enabled the isolation of incidents to single hosts or network segments."
"The most valuable feature of VMware Carbon Black Cloud is the possibility of securing any PC worldwide."
"What we mainly find valuable in the product is exactly what our use case is, as we use Carbon Black for the intrusion alerts and quarantine."
"​The ability to isolate an endpoint with only the host name and a click of a button is a major time saver."
"Integration and scalability are the most valuable."
"The most valuable features are the threat-hunting and the batch console."
 

Cons

"I have run into some detection issues with Cortex XDR. It needs to be better at detection of internal attacks."
"It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
"They are charging for Network Traffic Analyzer (NTA) services, so if the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better."
"This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance."
"A potential area of improvement for Cortex XDR by Palo Alto Networks is the cost."
"The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements."
"NetWitness Endpoint lacks automatic response capabilities. While it can be used for response, the process is manual, requiring the user to manually respond to alerts, which is not ideal."
"For a junior engineer, it's confusing."
"Setup is incredibly complex and poorly documented. Every time an upgrade was needed we would need to engage Professional Services for troubleshooting help. Certificates and web services proved to be the most significant sticking points. Since the product runs on a Linux platform, perhaps having staff with more Linux experience could have alleviated some difficulty."
"It's not highly available, so you have to have a core server."
"The product detects too many false positives initially and it could integrate better with other security solutions."
"Setup is incredibly complex and poorly documented."
"The solution's support could be improved."
"The threat intelligence feed could use some fine tweaking."
"It's not simple."
 

Pricing and Cost Advice

"Cortex XDR by Palo Alto Networks is an expensive solution."
"This is an expensive solution."
"The price of the solution is high for the license and in general."
"The price is on the higher side, but it's okay."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"It is "expensive" and flexible."
"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"The price of the product is not very economical."
Information not available
"VMware Carbon Black Cloud is an expensive solution."
"Purchase Professional Services up front as part of the implementation package, then renew hours annually to ensure you have adequate support for upgrades and enhancements. Overbuy by at least 10% to account for infrastructure growth."
"You need to pay for the licensing of the product. The pricing is costly."
"We had no issues purchasing through our preferred reseller and were able to get a fair price even when not purchasing direct. Carbon Black Enterprise Response didn’t break the bank, though adding on the matching antivirus and anti-malware components of the Protect product was more than we could afford, even with some discounting. Cb Response is really designed to complement Carbon Black’s Defense product. While Response can be used on its own, coupling with Defense seems like the best strategy if you can afford the price tag."
"The solution is very inexpensive so there is great cost savings to using it."
"Pricing for this solution could be made lower."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Comms Service Provider
9%
Manufacturing Company
8%
No data available
Construction Company
12%
Comms Service Provider
11%
Manufacturing Company
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise20
Large Enterprise51
No data available
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise9
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for NetWitness Endpoint?
NetWitness Endpoint is neither expensive nor cheap. It is priced intermediately compared to other solutions.
What needs improvement with NetWitness Endpoint?
NetWitness Endpoint lacks automatic response capabilities. While it can be used for response, the process is manual, ...
What is your primary use case for NetWitness Endpoint?
At my company, we usually use NetWitness Endpoint ( /products/netwitness-endpoint-41546-reviews ) for our customers w...
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What needs improvement with Carbon Black CB Response?
I see room for improvement as I remember some problems on compatibility with some operating systems; I recall we coul...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Carbon Black CB Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
ALLETE belk
Find out what your peers are saying about CrowdStrike, SentinelOne, Microsoft and others in Endpoint Detection and Response (EDR). Updated: May 2026.
896,942 professionals have used our research since 2012.