TrustRadius
https://dudodiprj2sv7.cloudfront.net/product-logos/r2/1s/BMIZHXNJT5B5.PNGProtection you can count onWe used Cb Protection as a replacement for primary antivirus/anti-malware. We had a different product that was not reliable and found that the concept behind Cb Protect made sense. Use a list of known good publishers and reputable software, and then blacklist the rest. We still ran an antivirus as a secondary, but we didn't have to go with a big name with lots of extraneous features, and (as far as I am aware) never had an incident where any potential malicious items moved past Cb Protect to hit the antivirus.,Device Control - you can view and allow/disallow the ability for certain devices to be used in your environment. Specifically we used this with USB drives. If you have one you want to use - whitelist the serial number. The rest can't be used. Simple and easy. Software blocking. If you have an extremely dynamic software base (I doubt this is likely) this could get a bit annoying, but for most organizations like ours where we have specific applications that are required, and then the rest are a bit of an afterthought, it's easy to whitelist the correct applications that you want to be able to run in your environment. The rest can't run (in high enforcement). Users are able to easily request new applications, and you can set certain groups to be able to approve it on their own. Solid platform - with few exceptions setting up new software was very easy (Dragon Medical was a bit tricky, but worked through it with support). Once you have your rules set up and the initial setup done, you tend not to have to do much of anything except to update on occasion and deal with a few requests for applications to be unblocked, or publishes approved.,Cost - Cb Protect is part of now a 3 fold protection offering by Carbon Black. The other parts give you visibility and a more traditional antivirus (Conifer I believe). Once you price all three together, things get expensive. You get what you pay for I guess, as alternatives cost less, but you do lose out on features. On-Prem - I don't believe this has changed, but when we first set up the only option was on-prem. This has a LOT of benefits, but with more mobile users, it can become a bit of a hassle for management and updating policies. A cloud option, or cloud connector would be nice. Application whitelisting outperforms traditional AV/Malware protection but also takes a bit more babysitting. You end up spending a lot of time looking at new programs etc coming down the pipe. A great example is products that self update. These can become a pain as the product updates typically don't show up as signed, or not signed the way Protect looks for, so you end up whitelisting them as they come up, and depending on how often and how many you have in the environment it can be annoying. Protect is nice, but you really need to also have Response to see a holistic view. Else you're going endpoint to endpoint if you are breached/infected, and that gets tedious quickly. However this also adds to the cost.,9,Protect took care of our objective, which was to protect the endpoints against rogue software and to help with preventing users from installing software that wasn't necessary/desired.,Barkly,Cisco Sourcefire SNORT, eClinicalWorks, VMware ESXi
Unspecified
Cb Protection
2 Ratings
Score 9.0 out of 101
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>TRScore

Cb Protection Reviews

Cb Protection
2 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>
Score 9.0 out of 101
Show Filters 
Hide Filters 
Filter 2 vetted Cb Protection reviews and ratings
Clear all filters
Overall Rating
Reviewer's Company Size
Last Updated
By Topic
Industry
Department
Experience
Job Type
Role
Reviews (1-1 of 1)
  Vendors can't alter or remove reviews. Here's why.
David Myers profile photo
June 14, 2017

Cb Protection Review: "Protection you can count on"

Score 9 out of 10
Vetted Review
Verified User
Review Source
We used Cb Protection as a replacement for primary antivirus/anti-malware. We had a different product that was not reliable and found that the concept behind Cb Protect made sense. Use a list of known good publishers and reputable software, and then blacklist the rest. We still ran an antivirus as a secondary, but we didn't have to go with a big name with lots of extraneous features, and (as far as I am aware) never had an incident where any potential malicious items moved past Cb Protect to hit the antivirus.
  • Device Control - you can view and allow/disallow the ability for certain devices to be used in your environment. Specifically we used this with USB drives. If you have one you want to use - whitelist the serial number. The rest can't be used. Simple and easy.
  • Software blocking. If you have an extremely dynamic software base (I doubt this is likely) this could get a bit annoying, but for most organizations like ours where we have specific applications that are required, and then the rest are a bit of an afterthought, it's easy to whitelist the correct applications that you want to be able to run in your environment. The rest can't run (in high enforcement). Users are able to easily request new applications, and you can set certain groups to be able to approve it on their own.
  • Solid platform - with few exceptions setting up new software was very easy (Dragon Medical was a bit tricky, but worked through it with support). Once you have your rules set up and the initial setup done, you tend not to have to do much of anything except to update on occasion and deal with a few requests for applications to be unblocked, or publishes approved.
  • Cost - Cb Protect is part of now a 3 fold protection offering by Carbon Black. The other parts give you visibility and a more traditional antivirus (Conifer I believe). Once you price all three together, things get expensive. You get what you pay for I guess, as alternatives cost less, but you do lose out on features.
  • On-Prem - I don't believe this has changed, but when we first set up the only option was on-prem. This has a LOT of benefits, but with more mobile users, it can become a bit of a hassle for management and updating policies. A cloud option, or cloud connector would be nice.
  • Application whitelisting outperforms traditional AV/Malware protection but also takes a bit more babysitting. You end up spending a lot of time looking at new programs etc coming down the pipe. A great example is products that self update. These can become a pain as the product updates typically don't show up as signed, or not signed the way Protect looks for, so you end up whitelisting them as they come up, and depending on how often and how many you have in the environment it can be annoying.
  • Protect is nice, but you really need to also have Response to see a holistic view. Else you're going endpoint to endpoint if you are breached/infected, and that gets tedious quickly. However this also adds to the cost.
Cb Protect is best suited somewhere where you want to maximize the lockdown of workstations. So moving past no local admin rights to blocking specific applications and peripherals. The idea would be to have a list of applications you want to run, and then anything else is not able to be used. As stated prior, if you have a very fluid environment where you are having all sorts of new applications installed frequently (I feel for you!!) this is still do-able, but it misses the general idea. I think especially in environments that are more sensitive to new applications, like banks, healthcare systems etc, this is a good fit. The ability to look at application levels, drift, unapproved software etc is very useful.
Read David Myers's full review

Cb Protection Scorecard Summary

About Cb Protection

Carbon Black offers Cb Protection, an application control solution for enterprise endpoints and critical systems. IT, compliance, infrastructure, and security teams use Cb Protection to establish automated software execution controls and protection policies that safeguard corporate and customer data.

Carbon Black is ranked #1 in endpoint prevention by Forrester. More than 2,200 organizations, including 30 of the Fortune 100, use Carbon Black. The vendor says with over 7 million licenses sold, and more than 75 dedicated MSSPs using CB as part of their security services, Carbon Black’s solution is the top choice to eliminate risk, maximize uptime and exceed regulatory controls.
Categories:  Application Security

Cb Protection Integrations

Cb Protection Competitors

Symantec Critical System Protection, McAfee Application Control, Lumension

Cb Protection Technical Details

Operating Systems: Unspecified
Mobile Application:No
Supported Languages: English