Try our new research platform with insights from 80,000+ expert users
reviewer2173167 - PeerSpot reviewer
Cyber Security Manager Senior Specialist at a university with 501-1,000 employees
Real User
May 10, 2023
A scalable and easy-to-deploy EDR solution that offers its users a good customer support
Pros and Cons
  • "It is a scalable solution...The initial setup was straightforward."
  • "Right now, Carbon Black CB Defense doesn't support cloud computing and Kubernetes."

What is our primary use case?

I am associated with the incident response team, and we use Carbon Visibility for converged networks.

What needs improvement?

Right now, Carbon Black CB Defense doesn't support cloud computing and Kubernetes. However, if it does support them, then it would be better.

For how long have I used the solution?

I have been using Carbon Black CB Defense since 2019.

What do I think about the stability of the solution?

It is mostly a stable solution, but sometimes there are stability issues.

Buyer's Guide
VMware Carbon Black Endpoint
December 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,889 professionals have used our research since 2012.

What do I think about the scalability of the solution?

It is a scalable solution.

How are customer service and support?

The technical support is nice. We can reach them 24/7. I rate technical support a seven out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was straightforward. We use it for the environment server, clients like end users, and competitors. We use some automation tools like SCCM for Windows, Linksys, and some other automation tools, and we use a lot of them to deploy. So, it depends since it is a circle and because every day, there is a new server that joins the environment. And when your server line client enters the server environment, they automatically install blockings.

But the environment contains over twenty thousand clients. It may take three or three months, depending on whether the employee works in their home. They can only join the network once they log in to VPN. So as a result of that, sometimes deployment time takes too much time. We have very big environments, but a lot of the domain is managed by some administration. Less than ten people were required for the deployment.

What about the implementation team?

We used local support to deploy it.

What's my experience with pricing, setup cost, and licensing?

There are more expensive products than Carbon Black CB Defense, so we are using the solution for its availability.

What other advice do I have?

I recommend the solution to others planning to use it. I rate the overall solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Suzan Demir - PeerSpot reviewer
Sales Operations Specialist at a computer software company with 51-200 employees
Real User
Feb 15, 2023
Shows the whole process of events but has compatibility problems with Linux
Pros and Cons
  • "The initial setup was fairly easy."
  • "CB Defense could be more compatible with Linux, and its cloud provision could be improved."

What needs improvement?

CB Defense could be more compatible with Linux, and its cloud provision could be improved.

For how long have I used the solution?

I've been using CB Defense for two years.

What do I think about the scalability of the solution?

CB Defense is scalable so long as the deployment has been done correctly.

How are customer service and support?

Carbon Black's support team are very slow to answer questions.

How was the initial setup?

The initial setup was fairly easy. Deployment will take one to two weeks, depending on how many endpoints there are.

What's my experience with pricing, setup cost, and licensing?

CB Defense is available on a yearly subscription and is priced by the number of endpoints.

What other advice do I have?

I would recommend CB Defense for users who want an on-prem solution that lets them see the whole process of any event. I would give CB Defense a rating of six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
VMware Carbon Black Endpoint
December 2025
Learn what your peers think about VMware Carbon Black Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,889 professionals have used our research since 2012.
ICT/Systems Application Engineer at a manufacturing company with 10,001+ employees
Real User
Jan 22, 2023
Works well and instantly, responsive technical support, with high scalability
Pros and Cons
  • "The whole purpose of the product, like application control, is very good, and also if you need to update some policies, it works well and instantly."
  • "I would like to see the user credentials feature improved. I would also like to see more reporting features and better ways to roll the reports out."

What is our primary use case?

Our primary use case is for application control.

What is most valuable?

The whole purpose of the product, like application control, is very good, and also if you need to update some policies, it works well and instantly.

What needs improvement?

I would like to see the user credentials feature improved. I would also like to see more reporting features and better ways to roll the reports out.

For how long have I used the solution?

I have been using Carbon Black CB Defense for more than a year.

What do I think about the stability of the solution?

I would say the stability is high a nine on a scale of one to ten.

What do I think about the scalability of the solution?

On a scale of one to ten, I would give it a nine for being highly scalable.

How are customer service and support?

Technical support is pretty responsive. I have not had to use them a lot and when we need them we route them through our team.

How was the initial setup?

The initial setup was straightforward I had some minor issues with the web application I logged in and fixed them. The initial deployment only took about half a day. We have deployed to around one hundred systems.

What about the implementation team?

The deployment was done in-house.

What's my experience with pricing, setup cost, and licensing?

The pricing is annually based and operates through another department than mine.

What other advice do I have?

I would rate Carbon Black CB Defense an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Ashish Dubey - PeerSpot reviewer
Lead Security Analyst at a tech services company with 201-500 employees
Real User
Dec 15, 2022
Manages multiple endpoints from a central location and detects alerts on the basis of AI
Pros and Cons
  • "The solution has a library where we can have multiple threat intels onboarded. We just have to subscribe to a particular site intel and they'll provide us with all of the truncated details so that we can create IOCs and alerts on the basis of those IOCs."
  • "A search bar in the investigation page and some AI-related tasks like outgoing alerts, or recent tactics that are being used in the market, must be embedded in the tool so that it's easier to find alerts."

What is our primary use case?

Carbon Black is an EDR solution and a Next Generation AV. It works on the basis of machine learning and artificial intelligence. It's used to manage multiple endpoints from a central location and detects alerts on the basis of AI. If we have any custom alerts, they can be triggered or flagged. In that case, we can have a centralized alerting system. It can also be used to isolate, repair, or remediate a machine when it is taken by an attack.

We aren't responsible for managing the infrastructure of this particular tool. We're using it for investigation purposes and to monitor products that are being used by our clients.

It's deployed on a public cloud.

What is most valuable?

The solution has a library where we can have multiple threat intels onboarded. We just have to subscribe to a particular site intel and they'll provide us with all of the truncated details so that we can create IOCs and alerts on the basis of those IOCs. 

It's one of the best features because there are multiple third-party vendors who can provide us with site intel in one location. You just have to subscribe to them, and they'll start providing you with IOCs. If a new attack starts, you will have all the basic IOCs on that list, which can be used to identify if the same attack is happening in your environment.

We can isolate devices in just two clicks. That's also a great feature. We can remediate and repair devices from a central location. It's not too difficult to use that particular tool. The user interface is very easy to understand. You are not required to roam around the console to find where the alert went. It's easy to resolve that.

When we onboarded Carbon Black, there weren't many EDR solutions available in the market. It was one of the best tools when it was launched. We don't have any complaints with the tool. The tool is very good. It highlights many of the alerts and events.

What needs improvement?

When you're investigating an alert, you will get a graph and will see the details related to the process that triggered the alert. Below the graph, there are network connections, file modifications, industry modifications, and multiple other activities. If you want to specifically find which additional modification has been performed, you will have to find the log you're searching for. There isn't a search bar to check for file modifications or network connections. In that case, you don't have a search bar, so you have to check each and every event, which could be more than 1,000.

You would have to check 1,000 events manually, or you would have to export sheets to view what you are searching for. If they added a search bar, it would reduce the time it takes to do investigations.

If you want to log into a device, there's a process named winlogon.exe, which is supposed to be initiated. If I'm using Carbon Black, I will have to check where winlogon.exe is being observed or at what time it was being observed. Because there's no search bar, I will have to check for the event in all the device events.

A search bar in the investigation page and some AI-related tasks like outgoing alerts, or recent tactics that are being used in the market, must be embedded in the tool so that it's easier to find alerts. The AI must be stronger so it can identify activity that is actually malicious.

For how long have I used the solution?

I have used this solution for a year and a half.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

It's scalable because it's based on the cloud.

How was the initial setup?

It's sensor-based, so you have to install the machine associated with your application. You will have the configuration file and the agent installation file. You'll have to run the configuration file, and then you'll be onboarded to Carbon Black. It's easy.

Deployment was fast. It took 15 minutes.

We have a group of about eight people for maintenance and supervision.

What other advice do I have?

I would rate this solution as eight out of ten.

It's a good tool, but it requires some updates. It doesn't have new features like multi-tactics, which other EDR products are providing.

My advice is to acknowledge or resolve a particular alert because once they resolve, it will be very difficult for you to find that alert. Handle it with care because with just a click, the device will be isolated. It could be a server, host, or network device. If you click the wrong button out of curiosity, it will destroy the machine. It has multiple accesses and won't ask if you're sure if you want to do an activity or not.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1785597 - PeerSpot reviewer
IT Manager at a financial services firm with 51-200 employees
Real User
Feb 20, 2022
Straightforward to set up, provides automatic site blocking, and forwards information to our SOC
Pros and Cons
  • "One of the most valuable features is that it will block vulnerable sites. If there was a connection between one of our devices to a known malware site, it will block it."
  • "This product should be cheaper."

What is our primary use case?

We primarily use this product to provide threat intelligence to our SOC about our endpoints.

What is most valuable?

One of the most valuable features is that it will block vulnerable sites. If there was a connection between one of our devices to a known malware site, it will block it. Then also alerts our SOC.

What needs improvement?

This product should be cheaper.

For how long have I used the solution?

I have been working with Carbon Black CB Defense for three years.

What do I think about the stability of the solution?

Stability-wise, it is good.

What do I think about the scalability of the solution?

I am satisfied with the scalability. We use it across the company and all of the users have it on their laptops. It's a mixture of IT people, finance, doctors, lawyers, dentists, and other professional services. It's a wide range of people and there are about 180 in total.

How are customer service and support?

The technical support is okay.

Which solution did I use previously and why did I switch?

We also use Sophos Intercept X in our business.

How was the initial setup?

CB Defense is pretty straightforward to set up.

What about the implementation team?

The implementation was done by my own team.

What's my experience with pricing, setup cost, and licensing?

This is a really expensive product and we pay licensing fees on a yearly basis. The subscription includes technical support.

What other advice do I have?

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1762626 - PeerSpot reviewer
IT Administrator at a manufacturing company with 501-1,000 employees
Real User
Jan 28, 2022
Puts very little load on the servers, does an excellent job, and has very good pricing
Pros and Cons
  • "I found it very valuable as a whole. It is good at detecting anything and has kept us very safe. It is also very easy to use."
  • "I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others."

What is our primary use case?

It is used for protecting our file servers. Its version is kept up to date, so it should be fairly current.

How has it helped my organization?

We found that Trend Micro was producing a little bit more load on our servers than what we wanted. So, we went to Carbon Black because it was integrated with VMware. It is great on the servers. It puts very little load, and it does an excellent job.

What is most valuable?

I found it very valuable as a whole. It is good at detecting anything and has kept us very safe. It is also very easy to use. 

What needs improvement?

I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others.

For how long have I used the solution?

I have been using it for close to a year.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

I believe it is very scalable. In terms of its users, for the most part, there are only two of us using it. I am the IT administrator and primary user, and we have an IT support person who handles PCs and backs me up on servers. We are taking care of its deployment and maintenance.

We are looking at the possibility of expanding its usage in the future to include desktops.

How are customer service and support?

I've never had to call technical support.

Which solution did I use previously and why did I switch?

We were using Trend Micro Apex One on our servers, and we found that Trend Micro tended to load the servers up a little bit. That's why we switched to Carbon Black.

How was the initial setup?

It was very straightforward. It was very easy to set up. 

Its deployment didn't take that long at all. We purchased it and then just installed it on different servers, one at a time.

What about the implementation team?

We did it ourselves.

What was our ROI?

I've never calculated an ROI on it.

What's my experience with pricing, setup cost, and licensing?

Its pricing was very good, which is one of the reasons I went to it as an alternative. It is on a yearly basis. There are no additional fees.

Which other solutions did I evaluate?

We did not evaluate other options.

What other advice do I have?

If you're running a VMware environment, you can definitely go ahead and use it. 

I would rate it a 10 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ICT Manager at a computer software company with 1-10 employees
Real User
Aug 23, 2021
A stable solution which can be flexibily configured

What is our primary use case?

Carbon Black CB Defense is a multi-purpose solution. We can use it for XDR ADF. This way, if someone is trying to attack one's end point, in which there is a script such as PowerShell, but without a signature, the solution will be aware of such an attack and respond accordingly. It will detect the behavior and respond to the SOC.

What is most valuable?

The solution will prevent communication of one compromised device with another. 

What needs improvement?

In the month-long evaluation of the solution that we conducted, we found the POC to not be helpful, owing to the issue the client encountered with the platform, the operating system, which did not lend adequate support. 

While we paid for both on-cloud and on-premises deployment, the issue is not with the entrepreneur's upload, but with the end point. 

And do you have already some customers regarding Carbon Black?

Syed Faisal:
No, even Carbon Black, everyone has this solution for Windows IoT and Linux environment. But this is something called the product called Dell. This is a Dell based, [inaudible 00:02:31]. More or less the Dell [inaudible 00:02:33] which is running Dell customer OS, [inaudible 00:02:39]. But unfortunately we cannot install the agent on it.

The licensing price is a bit expensive when compared with other solutions. 

For how long have I used the solution?

We've been using Carbon Black CB Defense for just a month. 

What do I think about the stability of the solution?

The solution is scalable. 

What do I think about the scalability of the solution?

The solution is stable and the policy can be configured with flexibility. The solution comes with its own pre-built standard policy. Yet, we can write our own, which means the solution serves us going forward. 

How are customer service and technical support?

The tech support is mostly okay. 

How was the initial setup?

The solution is very easy to install.

Full deployment takes no more than an hour. 

What about the implementation team?

Installation can be done on one's own. 

What's my experience with pricing, setup cost, and licensing?

The licensing is a bit pricier than other solutions. 

We pay for the license annually. 

What other advice do I have?

While I do not know the exact number of customers making use of the solution, my understanding is that most of the MNC, multinational companies, and the majority of the banking sector are doing so. 

I would recommend the solution to others.

I rate Carbon Black CB Defense as a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer917823 - PeerSpot reviewer
IT Manager - System Administration at a pharma/biotech company with 501-1,000 employees
Real User
Aug 21, 2021
Easy to set up and offers good protection but the on-premises deployment has a lot of issues
Pros and Cons
  • "The initial setup is very easy."
  • "With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue."

What is our primary use case?

We primarily use the solution for operations and also security. On the security front, we have a specific project that's ongoing right now. We are moving away from the on-prem Carbon Black to the cloud one. 

We primarily use the solution for endpoint protection.

What is most valuable?

The protection of the user machines has been great. For example, if a laptop gets stolen, or let's say, an employee gets let go, the product provides us with the ability to actually lock people out of the network and handle remote wipes and stuff like that.

The initial setup is very easy.

What needs improvement?

The on-prem one was very problematic, especially version 7.2, which did not play nice with Symantec at all. The last upgrade of the client actually triggered a block to the networking, to our active directory domain controllers.

There was a bug that we found was in Macs. It was triggering false positives as it wasn't able to figure out the right parent upon login. With the Carbon Black Cloud, we just got it two to three weeks ago. So far, I haven't seen any false positives. The cloud seems to be a much better product. 

With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue.

I need more time to explore the cloud deployment, as we've only had it for three weeks at this point. 

For how long have I used the solution?

It's been at least four years since we started using the solution. Four or five years.

We started with the on-prem one and now we're in yet another project with a cloud deployment.

What do I think about the stability of the solution?

While the on-prem has some bugs we have been dealing with, so far, after using the could for three weeks, it's like night and day. It's been very stable. There are no bugs or glitches.

What do I think about the scalability of the solution?

I'm not aware of the scalability capabilities yet, as I don't have the entire company on it yet. We are still in testing mode. We just got the cloud deployment three weeks ago. So I can't really answer that truthfully.

Right now, we have seven people on the solution currently.

How are customer service and technical support?

We haven't yet used the technical support. I can't speak to how helpful or responsive they would be.

That said, we did use technical support when we were on the on-premises version, and they were terrible. We would ask for bug fixes and new versions would come and yet they would not actually fix the problems that were highlighted.

Which solution did I use previously and why did I switch?

We also use Red Cloak, which is a completely different prody=uct and something that we still use. 

How was the initial setup?

The initial setup is very simple. The cloud version in particular is very simple. It's not overly complex or difficult.

What's my experience with pricing, setup cost, and licensing?

I'm not dealing with the pricing. I can't speak to the costs involved.

What other advice do I have?

There are two versions of Carbon Black that VMware has, one of them is the on-prem one and the endpoint clients are in the user machines and servers, so AWS and data center and VSS.

I'd advise those interested in the solution to go with the cloud deployment model. We've had a lot of issues with the on-premises version.

I'd rate the solution at a seven out of ten. There seems to be quite a disparity between the cloud and on-premises versions. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free VMware Carbon Black Endpoint Report and get advice and tips from experienced pros sharing their opinions.