TrustRadius: an HG Insights company

Carbon Black EDR

Score7.5 out of 10

28 Reviews and Ratings

What is Carbon Black EDR?

Carbon Black EDR is an on-premise incident response and threat hunting solution designed for security operations center (SOC) teams with offline environments or on-premises requirements.

Read more details.

Categories & Use Cases

Videos

Top Performing Features

  • Threat Recognition

    Detection and recognition of malicious software within a network that could pose a threat to sensitive information.

    Category average: 9.5

  • Anti-Exploit Technology

    In-memory and application layer attack blocking (e.g. ransomeware)

    Category average: 9

  • Infection Remediation

    Capability to quarantine infected endpoint and terminate malicious processes.

    Category average: 8

Areas for Improvement

  • Behavioral Analytics

    Using threat behavior to establish a pattern which can be used to identify the similar threats faster in the future.

    Category average: 8.5

  • Threat Analysis

    Analyzing known factors such as behavior patterns, affected areas, and other specific features to more easily identify a threat.

    Category average: 8

  • Threat Intelligence Reporting

    Generates reports that display information on threats (such as name, type, frequency of attack, area affected, etc.)

    Category average: 7

Who Buys & Uses Carbon Black EDR

Carbon Black EDR former user experience

Use Cases and Deployment Scope

Carbon Black was used in our organization as the primary means of endpoint protection, threat detection, and lockdown of any infected systems. It was used widely to regulate all assets, from pos systems to servers to personally-issued devices. We monitored it regularly and responded to its alerts. It was effective at this level.

Pros

  • Threat detection
  • Threat remediation
  • System lockdown
  • Visibility into attacks

Cons

  • UI
  • Overly technical on the surface
  • False positives

Return on Investment

  • Costly, but worthwhile
  • Support personnel were responsive
  • Difficult to quantify threat detection remediation in ROI

Usability

Alternatives Considered

Trend Micro Cloud One, Cyera and Microsoft Defender Vulnerability Management

Other Software Used

Microsoft Defender for Office 365, Cyera, Symantec Advanced Threat Protection

Protect your endpoint with Carbon Black EDR

Use Cases and Deployment Scope

VMware Carbon Black EDR is used for investigation of endpoint. It helps in looking out for any malicious activity in the host machines. We get various information about the activity like in which machine the event is occurring, occurrence time and what all events are being performed in the endpoint. It helps in checking all the network connections made by the machine , any modification in the files made in the machine, all the processes that are running in the machine can be checked using VMware Carbon Black EDR. It helps in creating custom watchlist of events also it has threat feeds for investigation.

Pros

  • Helps in tracking network connections made by machine
  • Process Tree which show series of workflow which clear and easy to understand.
  • Enables to go live into the machine and investigate

Cons

  • Number of false positive which are triggered due to threat feeds are sometimes more needs to be fine tuned by the client.
  • In very rare scenarios processes are not captured properly.

Return on Investment

  • It is helping to protect us from potential loss of revenue that would be caused by malware or a compromised account.
  • It took some time in deploying in the environment , but that time is much worth it because of the results we are getting now.
  • It helps in hunting, which help us check and protect our environment from any cyber attacks.

Alternatives Considered

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)

Other Software Used

Microsoft Azure, Amazon WorkSpaces (VDI), Amazon Web Services

Cb Response is great for endpoint investigation and response

Pros

  • Process tree view of endpoint activity
  • Ability to pull files from host
  • Threat Intelligence integration
  • Isolate a host

Cons

  • Needs more defensive abilities

Return on Investment

  • Increased visibility across the enterprise for threats
  • Rapid ability to investigate and remediate threats

Alternatives Considered

FireEye Endpoint Security