We use Cb response primarily as our incidence response. Our environment has more than 300 users handling sensitive client information, like financial data and personal identifiable information, so security is a huge concern. When we receive an incident report from our SOC, our first move is to isolate the endpoint, and Cb response does that seamlessly. We are also able to use the product to perform an in-depth binary process analysis to see if there were any suppressed malicious services.
Technical Support Specialist at a financial services firm
We are able to remotely isolate exploited endpoints in seconds
Pros and Cons
- "We are able to remotely isolate exploited endpoints in seconds and perform a live deep dive of any endpoint into its running processes (as necessary) without the need for extra scripts."
- "The ability to isolate an endpoint with only the host name and a click of a button is a major time saver."
- "The threat intelligence feed could use some fine tweaking."
- "We are subscribed to FS-ISAC threat indicator, but have been unsuccessful in adding it to our alliance feeds."
What is our primary use case?
How has it helped my organization?
Cb Response is our primary incident response tool. With this product in our hands, we are able to remotely isolate exploited endpoints in seconds and perform a live deep dive of any endpoint into its running processes (as necessary) without the need for extra scripts.
What is most valuable?
The ability to isolate an endpoint with only the host name and a click of a button is a major time saver. No need to go hunting for an IP or typing in terminal.
What needs improvement?
The threat intelligence feed could use some fine tweaking. We are subscribed to FS-ISAC threat indicator, but have been unsuccessful in adding it to our alliance feeds. So, rather than Cb Response being able to pull the data from the feed, we have to manually blacklist MD5 hashes.
Buyer's Guide
VMware Carbon Black Cloud
May 2025

Learn what your peers think about VMware Carbon Black Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
For how long have I used the solution?
Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

VMware Consultant at V2S Corporation
A highly scalable solution that can be used to get a better view of the security of endpoints and workstations
Pros and Cons
- "The most valuable feature of VMware Carbon Black Cloud is the possibility of securing any PC worldwide."
- "The solution's support could be improved."
What is our primary use case?
VMware Carbon Black Cloud is a good home office tool for people working outside the office.
How has it helped my organization?
VMware Carbon Black Cloud helped us to get a better view of the security of endpoints and workstations.
What is most valuable?
The most valuable feature of VMware Carbon Black Cloud is the possibility of securing any PC worldwide.
What needs improvement?
The solution's support could be improved.
For how long have I used the solution?
I have been using VMware Carbon Black Cloud for a couple of months.
What do I think about the stability of the solution?
I rate VMware Carbon Black Cloud a nine out of ten for stability.
What do I think about the scalability of the solution?
I rate VMware Carbon Black Cloud ten out of ten for scalability.
How was the initial setup?
VMware Carbon Black Cloud's initial setup is neither hard nor easy.
What was our ROI?
We have seen a good return on investment with VMware Carbon Black Cloud.
What other advice do I have?
VMware Carbon Black Cloud is deployed on-cloud in our organization.
I recommend users test the solution and check the use cases before buying it.
Overall, I rate VMware Carbon Black Cloud a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free VMware Carbon Black Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Popular Comparisons
Rapid7 InsightIDR
VMware Carbon Black Endpoint
Fidelis Elevate
IBM Resilient
Trellix Helix Connect
Buyer's Guide
Download our free VMware Carbon Black Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Carbon Black and Cylance Comparison for EDR
- What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
- What are the Top 5 cybersecurity trends in 2022?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- What is the difference between cyber resilience and business continuity?
- What is an incident response playbook and how is it used in SOAR?
- What is the difference between mitigation and remediation in incident response?
- What does the Log4j/Log4Shell vulnerability mean for your company?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?