---
title: Carbon Black EDR Reviews
meta_title: 'Carbon Black EDR Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 86 reviews by the users' company size, role or industry to
  find out how Carbon Black EDR works for a business like yours.
aggregate_rating:
  rating_value: 4.4
  review_count: 86
  scale: '5'
date_modified: '2026-07-17'
parent_category:
  name: Endpoint Protection
  url: https://www.g2.com/categories/endpoint-protection
---

# Carbon Black EDR Reviews
**Vendor:** Broadcom  
**Category:** [Endpoint Detection &amp; Response (EDR) Software](https://www.g2.com/categories/endpoint-detection-response-edr)  
**Average Rating:** 4.4/5.0  
**Total Reviews:** 86
## About Carbon Black EDR
Carbon Black EDR is a market-leading incident response and threat hunting solution designed to provide responders with the most information possible, accompanied by expert threat analysis and armed with real-time response capabilities to stop attacks, minimize damage and close security gaps. Carbon Black EDR makes these teams more efficient, reducing investigations from days to hours, and more effective, enabling them to discover threats before attacks can exploit them. Carbon Black EDR also allows teams to connect to and isolate infected machines to prevent lateral movement and remediate devices without costly IT involvement. Continuous and Centralized Recording Centralized access to continuously recorded endpoint data means that security professionals have the information they need to hunt threats in real time as well as conduct in-depth investigations after a breach has occurred. Live Response for Remote Remediation With Live Response, incident responders can create a secure connection to infected hosts to pull or push files, kill processes, perform memory dumps and quickly remediate from anywhere in the world. Attack Chain Visualization and Search Carbon Black EDR provides intuitive attack chain visualization to make identifying root cause fast and easy. Analysts can quickly jump through each stage of an attack to gain insight into the attacker’s behavior, close security gaps and learn from every new attack technique to avoid falling victim to the same attack twice. Automation via Integrations and Open APIs Carbon Black boasts a robust partner ecosystem and open platform that allows security teams to integrate products like Carbon Black EDR into their existing security stack.



## Carbon Black EDR Pros & Cons
**What users like:**

- Users value the **real-time threat detection** of Carbon Black EDR, enhancing security through continuous monitoring and advanced analysis. (5 reviews)
- Users value the **rapid incident response** capabilities of Carbon Black EDR, enhancing their cybersecurity effectiveness significantly. (2 reviews)
- Users value the **real-time threat detection** capabilities of Carbon Black EDR, enhancing security through continuous monitoring and proactive strategies. (1 reviews)
- Users rave about the **next-gen antivirus and behavior analysis** of Carbon Black EDR, ensuring robust protection against all threats. (1 reviews)
- Users praise the **AI-powered behavior analysis** of Carbon Black EDR, enhancing security against various cyber threats. (1 reviews)
- Users appreciate the **automation capabilities** of Carbon Black EDR, enhancing efficiency through integration and real-time monitoring. (1 reviews)
- Centralized Management (1 reviews)
- Customer Support (1 reviews)
- Ease of Use (1 reviews)
- Easy Integrations (1 reviews)

**What users dislike:**

- Users find the **pricing to be steep** , making it less accessible for some despite its great features. (2 reviews)
- Users report **high resource usage** with Carbon Black EDR, which can impact performance on lower-spec machines. (2 reviews)
- Users face **overwhelming alert issues** that can hinder usability and impact resource management significantly. (1 reviews)
- Users often face **false positives** with Carbon Black EDR, requiring careful tuning to prevent alert fatigue. (1 reviews)
- Users find the **inefficient search functionality** of Carbon Black EDR challenging, complicating their ability to quickly locate information. (1 reviews)
- Learning Curve (1 reviews)
- Poor Documentation (1 reviews)

## Carbon Black EDR Reviews
  ### 1. Handle you Incidence Response with CB Response and stay protected 24hours.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Catherine W. | Information Technology Specialist, Computer & Network Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 05, 2019

**What do you like best about Carbon Black EDR?**

This software take less time to investigate threats ,suspicious and malicious behaviours.

**What do you dislike about Carbon Black EDR?**

Since installation of this software we have not seen any problem related to it hence no dislike . It works well with us.

**Recommendations to others considering Carbon Black EDR:**

This software provide maximum security from all corners, i hope you try it and find it helpful. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

This system isolate found threats and by so they don't spread and finally eliminates them. This software enable to quickly block cyber attackers before they can harm the system.

  ### 2. Detect respond  and  stay safe from advanced threats.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Naomi M. | IT Manager, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 06, 2019

**What do you like best about Carbon Black EDR?**

This software takes less time to investigate threats and block any attacker or malicious activity.

**What do you dislike about Carbon Black EDR?**

This software has to be kept on updates to support it functions other than that no other dislike for this software as it functions very well with our systems.

**Recommendations to others considering Carbon Black EDR:**

I have tried the many benefits of this software and I hope you will find them benefitial to yourself as well.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Detecting any incoming or already existing threats isolates them and repairs the damage if any.

  ### 3. Fasntastic product that collects all relevant data

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** August 29, 2019

**What do you like best about Carbon Black EDR?**

The best part about Carbon Black Response is the amount of data that is collected, they make no assumptions about what they think you want like other vendors do but provide almost all telemetry one could want in an EDR. 

**What do you dislike about Carbon Black EDR?**

Sluggishness of the console can sometimes cause issues. 

**Recommendations to others considering Carbon Black EDR:**

Great product without the clutter that other products have. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Ability to do deep dives and investigate anything we find suspicious. 

  ### 4. CB Response Review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Investment Management | Mid-Market (51-1000 emp.)

**Reviewed Date:** September 13, 2019

**What do you like best about Carbon Black EDR?**

I like the capabilities that exist in CB response, the product is very agile and detailed

**What do you dislike about Carbon Black EDR?**

portal can sometimes be slow and it takes too long to load

**Recommendations to others considering Carbon Black EDR:**

get CB response its a great product

**What problems is Carbon Black EDR solving and how is that benefiting you?**

many problems. incident response, threat hunting and overall IT hygiene are all use cases for the product. the sky is the limit

  ### 5. Highly-scalable, real-time threat hunter and incident response software.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Faith A. | IT Manager, Telecommunications, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 03, 2019

**What do you like best about Carbon Black EDR?**

I like the way this software consolidate threat intelligence for your environment to automatically detect suspicious behaviour.

**What do you dislike about Carbon Black EDR?**

So far this software has not presented any serious drawback since we started using it.

**Recommendations to others considering Carbon Black EDR:**

This software has sophisticated detections which combines custom and cloud-native threat. This advantage suites it for use in many organizations.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

We are using this software to deal with advanced threat hunting and IR capabilities. We are also storing information with this software.

  ### 6. Exellent software to detect and respond to advance attack.

**Rating:** 5.0/5.0 stars

**Reviewed by:** paul k. | IT Manager, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 21, 2019

**What do you like best about Carbon Black EDR?**

This software automatically collects and stores detailed data for post-incident investigation.

**What do you dislike about Carbon Black EDR?**

its works poorly in remote areas where network coverage is low.

**Recommendations to others considering Carbon Black EDR:**

This system offers comprehensive endpoint protection via one sensor which is good for detection of malware. It is also easy to use therefore I recommend it to anyone in search of it.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

This software makes it easy to respond and re-mediate  in real time by powerfully stopping the active attacks and quickly repairing damage.

  ### 7. CB Response - Value shown immediately 

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Enterprise (> 1000 emp.)

**Reviewed Date:** November 30, 2019

**What do you like best about Carbon Black EDR?**

The all-in-one dashboard to show all my devices easily.   Also the minimal configuration needed.

**What do you dislike about Carbon Black EDR?**

The live response piece can be tricky to use.

**Recommendations to others considering Carbon Black EDR:**

Determine if on premise or cloud solution is your best option

**What problems is Carbon Black EDR solving and how is that benefiting you?**

We track IOC and other monitored activities such as command line prompt commands

  ### 8. Detect, validate advanced threats and respond to them safely with CB response. 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Eunice M. | IT Manager, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 09, 2019

**What do you like best about Carbon Black EDR?**

It helps save time and has greater protection hence fewer threats. 

**What do you dislike about Carbon Black EDR?**

I don't have any major drawback for this program but sometimes it may run slowly. 

**Recommendations to others considering Carbon Black EDR:**

I would recommend CB response for its good services to any organization. It also has fewer threats on its security. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Has  helped provide quick response to attacks. 

  ### 9. Security threat contained

**Rating:** 4.5/5.0 stars

**Reviewed by:** Richard N. | Information Technology Manager, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 18, 2019

**What do you like best about Carbon Black EDR?**

Its ability to give when and where the attack was able to compromise the system and its resolution.

**What do you dislike about Carbon Black EDR?**

Somehow complex but a very nice software I like it.

**Recommendations to others considering Carbon Black EDR:**

Good at finding malware already in the system and preventing it from progress. A good product.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Monitor and analyse any potential threats or attacks in progress across all endpoints.

  ### 10. ADVANCED THREAT HUNTING AND INCIDENT RESPONSE IN THE CLOUD

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 24, 2019

**What do you like best about Carbon Black EDR?**

I like this platform because it detects and responds to advanced attacks with unfiltered visibility

**What do you dislike about Carbon Black EDR?**

The software works on well enabled networks and Android devices

**Recommendations to others considering Carbon Black EDR:**

This is the best platform that enhances ability to deliver rapid incidents detection and response to our global customers

**What problems is Carbon Black EDR solving and how is that benefiting you?**

I have been using this in my systems to detect any threats and attacks that may affect my systems.investigations that typically take days or weeks can be completed in just minutes 

  ### 11. Good product. Great support. 

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Enterprise (> 1000 emp.)

**Reviewed Date:** September 06, 2019

**What do you like best about Carbon Black EDR?**

Lots of process information, providing for very in-depth investigations.

**What do you dislike about Carbon Black EDR?**

On-premesis setup is a bit finicky for large Enterprise environments. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Investigations and root cause analysis are much easier. 

  ### 12. Great Enterprise Product, But Learning Curve Is Steep.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Enterprise (> 1000 emp.)

**Reviewed Date:** December 31, 2018

**What do you like best about Carbon Black EDR?**

The Logs are very granular. Visibility is great and deployment is a breeze.

**What do you dislike about Carbon Black EDR?**

The Learning curve is a little steeper than other tools

**Recommendations to others considering Carbon Black EDR:**

This is a very powerful tool and will require a lot of learning. I would recommend hiring some one with a lot of experience you getting plenty of training. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Added Layers to Endpoint Security. Gets very granular with the with current processes and new spawned processes. to allow for deep inspection for Indications of compromise.  

  ### 13. Carbon Black for Threat Response

**Rating:** 4.5/5.0 stars

**Reviewed by:** Shaun H. | System Administrator, Sports, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 09, 2017

**What do you like best about Carbon Black EDR?**

While most companies just use a typical anti-virus we use the Carbon Black Defense combined with Carbon Black Response.  It's good because it gives you a play by play of every action on a particular node.  Using the built in alerts or creating your own you'll find that it's easy to go through and work an issue!

**What do you dislike about Carbon Black EDR?**

The only thing I really dislike about Cb Response is the layout and the lack of documentation displayed as you do things (ie. searching, although documentation does exist you just have to look elsewhere.)

**Recommendations to others considering Carbon Black EDR:**

I would highly recommend this product in order to keep track of everything that happens on your computer, from an application running, to it reaching out to China, or even just one app starting another.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

When using Cb Response we feel better equipped to handle any issues such as ransomware and other malicious content reaching out to external sites.

  ### 14. Highly effective for forensics, but not for small teams.

**Rating:** 2.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Mid-Market (51-1000 emp.)

**Reviewed Date:** January 15, 2018

**What do you like best about Carbon Black EDR?**

Very detailed information on the time(s) surrounding a supposed incident. 

**What do you dislike about Carbon Black EDR?**

Seems to really shine only in internet-accessible networks; not very great at isolated networks like mine.

**Recommendations to others considering Carbon Black EDR:**

Consider CB Defense, as many of the features of CB Response are being placed there, and it includes a true antimalware component. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

We needed a way to determine what circumstances surrounded a breach, so we can better learn to close them.

  ### 15. works well

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** March 30, 2018

**What do you like best about Carbon Black EDR?**

the ability to search all stated events from the one problem event 
how if one thing start it show all that spawned off that one item 

**What do you dislike about Carbon Black EDR?**

we have not come across much yet we do not like 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

ISM controls 

  ### 16. really good product that could be better if it didn't break stuff

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Publishing | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 24, 2017

**What do you like best about Carbon Black EDR?**

in theory it should work great. It seems to be a great tool.

**What do you dislike about Carbon Black EDR?**

their updates that they push out, don't seem to be thoroughly tested as they have recalled them a few times.
We lost the ability to sandbox an infected endpoint because the update they pushed out broke our servers so we had to dial back.  They have not been able to fix that yet.


**Recommendations to others considering Carbon Black EDR:**

due proper testing to make sure the current version can do exactly what you want.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

security remediation

  ### 17. Good model/framework could use some tweaking(which might be done in the upcoming version)

**Rating:** 3.5/5.0 stars

**Reviewed by:** Everett H. | Cyber Security Tool Analyst, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** May 02, 2017

**What do you like best about Carbon Black EDR?**

The ability see/analyze every process can give a huge insight into a potential threat, which makes hunting a good deal more efficient.

**What do you dislike about Carbon Black EDR?**

The biggest problem seems to be that the complexity of the inner workings makes it very difficult to identify the root cause of an issue, which I think has in turn made the whole thing a bit temperamental.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Cb Response is used as an endpoint threat detection and response(shockingly) tool.The biggest benefit is the ability to determine where and how an attacker was able to compromise the network.

  ### 18. CB Response- Proactive Threat Hunting

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 26, 2017

**What do you like best about Carbon Black EDR?**

Its Highly scalable, real-time EDR with unparalleled visibility for top security operations centers.

**What do you dislike about Carbon Black EDR?**

The only thing I really dislike about Cb Response is the layout and the lack of documentation

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Carbon Black offers endpoint detection and blocking granularity like never before! We were able to detect and block things that wasn't even detected by previous software. 

  ### 19. Intelligent detection and fast response

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Enterprise (> 1000 emp.)

**Reviewed Date:** October 19, 2017

**What do you like best about Carbon Black EDR?**

The flexibility to create complex queries.to match malicious or non standard behavior

**What do you dislike about Carbon Black EDR?**

False positives is a problem because there is not an easy way of dealing with them

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Incident response of remote sites, using live response. Malicious behavior is easily catched even before user realized she opened a malicious  PDF or word, for example

  ### 20. Easy to use - provides valuable information quickly

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Utilities | Enterprise (> 1000 emp.)

**Reviewed Date:** May 01, 2017

**What do you like best about Carbon Black EDR?**

This makes it very easy to search a specific threat domain to see if anyone visited it.  Very helpful in analyzing Phishing attempts and if the user actually clicked on them.

**What do you dislike about Carbon Black EDR?**

Some queries can be complex, requires use of API for some more advanced searching.

**Recommendations to others considering Carbon Black EDR:**

Very easy endpoint to install, just "install and go" to start collecting data.  Plan what type of data is relevant, so you don't overload yourself with Watchlists that trigger too many false positives.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

This provides us with our Incident Response management, and also allows us to quickly review IOC's when they are released.

  ### 21. Fantastic Forensics

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 04, 2017

**What do you like best about Carbon Black EDR?**

Response hints threats in real time so you get instant intelligence

**What do you dislike about Carbon Black EDR?**

Would prefer for the Cb portfolio to all sit as one agent. 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Visibility across our entire network means I can massively reduce investigation time and therefor time to remediation is much better

  ### 22. Incident response made easy

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Government Administration | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 04, 2017

**What do you like best about Carbon Black EDR?**

After installling cb Response everyhing is visibel in your environment, and you can search through your events really easy. It doesn't matter what you want to find you can do a search on it very easy.

**What do you dislike about Carbon Black EDR?**

Configuration is mostly done in conf files, and is not vrey user friendly. Not all supports have a deap linux experiance, whitch can be an problem when the product is based on linux. 

**Recommendations to others considering Carbon Black EDR:**

Deploy it as fast as possible, its a great product.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

CB response makes incident response very easy. you can searche on everything and makes long IR jobs really fast.

  ### 23. Unrivaled visibility and invaluable IR tool

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Investment Management | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 01, 2017

**What do you like best about Carbon Black EDR?**

Our IR team loves the ability to get instant access to what has occurred on our endpoints in the organization. With the ability to instantly get access to the machine through Live response.

**What do you dislike about Carbon Black EDR?**

The console can get a bit slow if you haven't put in appropriate filters.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Incident response

  ### 24. One of our best security investments

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 14, 2017

**What do you like best about Carbon Black EDR?**

Cb response gives us excellent visibility into our endpoints.  We have decided to balance our strategy and focus more on detection and response.  We all know if the talented bad guys want to get in, they will.  With Cb, I have a virtual video recorder on all my endpoints (servers and workstations) and alerting that is effective.  It took us about a month to fine tune.

**What do you dislike about Carbon Black EDR?**

The pricing model could improve.  Given Cb's recent acquisitions and focus on "beyond AV", having the suite of products, including Protection makes most sense.  But I find the pricing to be sometimes complex and expensive for cloud version.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

We wanted visibility into endpoints and ability to detect and contain a threat once identified.  

  ### 25. Best EDR tools around

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Enterprise (> 1000 emp.)

**Reviewed Date:** May 04, 2017

**What do you like best about Carbon Black EDR?**

Integrated Threat Feeds, Integrations with SIEM, Detects threats not found by other methods.  Great hunting and response tool. 

**What do you dislike about Carbon Black EDR?**

It would be nice if there were granular block actions that could be performed by the product.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Resolving Security Risks and detecting advanced threats.

  ### 26. One of the best security products I have used 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Enterprise (> 1000 emp.)

**Reviewed Date:** April 21, 2017

**What do you like best about Carbon Black EDR?**

Really easy to use and brilliant 'workflow' . The community around this product is also great and it's easy to create rules/watch lists 

**What do you dislike about Carbon Black EDR?**

Would like to see better search result display options thT can be useful when hunting 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Visibility into the endpoint whenever something has to be looked at , great for incident response 

  ### 27. See Everything on your endpoints

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brad M. | Senior Enterprise Systems Engineer, Retail, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 13, 2016

**What do you like best about Carbon Black EDR?**

Carbon Black Enterprise Response provides awesome visibility into your endpoints.  Being able to view the process chain of an attack is very useful in learning how the attacks work, preventing them from happening again and educating our users.  Very easy to deploy agents and start gathering useful data.  Lots of  great intelligence feeds.

**What do you dislike about Carbon Black EDR?**

I have had some issues with re-occurring alerts even after i have mark them as as Resolved or Resolved False Positive.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Being able to see exactly what is going on has been huge for us.  We have Carbon Black Enterprise Protection keeping malicious and unwanted software from running, but Enterprise Response shows us how these items are getting on our machines.  I have used Enterprise Response numerous times to track down blocked Ransom-ware attacks to malicious email attachments our users have opened.  Before Enterprise Response it was difficult if not impossible to find the cause of these types of attacks.

  ### 28. granular process insight

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** June 09, 2016

**What do you like best about Carbon Black EDR?**

The granular insight into what process/files are doing what to whom, and when. The watch lists provide a great way to triage suspicious activities and direct daily monitoring and incident response. Integration with CB Enterprise Protection (formerly bit9).

**What do you dislike about Carbon Black EDR?**

We're still tuning, but the enormous amount of standard events are quite a bit to comb through. While it is a monitoring tool, i often have requests to produce reports to illustrate 'what this product is delivering for the company', which i've yet to find a good solution.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

We brought in CB Response for a special use case in a sensitive environment where we thought we should have more detailed visibility.

  ### 29. Carbon Black - Detect and Respond

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Electrical/Electronic Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** January 23, 2016

**What do you like best about Carbon Black EDR?**

Cb has provided us visibility into threat behavior beyond any product out there today. The ability to ban malicious files, create feeds, watch lists, open API, integrations with many other products (and ability to add other products easily), Live Response, isolation and much more, make Cb the differentiator over any other ETDR product on the market today. 
Carbon Black provides the ability to also go back in time, which defeats a lot of other products in the space that only can go back a short period of time without disrupting the endpoint. The centralized infrastructure methodology makes sense for Cb as it technically can save money vs other products that will run CPU/mem to the max and begin to overwhelm the workstation/server. Cb is a very lightweight sensor, we see around 0-1% CPU, and 10-28Mb of memory. 28Mb on the high end for instances where it is a busy server like TMG or Exchange. 
Cb is deployed to around 60k endpoints with no issues. We've had minor hiccups over time caused by Cb, but nothing widespread and nothing that wasn't fixed on the new patch level etc. 
Working with Cb is probably one of the best things about the product. The PM team, engineering, executive team are all great people. Not forgetting the sales team, they are good people too. Everyone at Cb is committed to working and ensuring their product is the best. We have been with Cb since 4.2 and it has really grown a lot since. 
the API - is probably one of the most important features to Carbon Black that many products out there fail at. The ability to automate and orchestrate a lot of threat hunting, or even remediation tasks is incredible. Many products fail at this part, or place in API in after the fact. Cb is also 100% committed to ensuring the API is very flexible. They have some of the best developers working it. 
Integrations - Cb allows for many integrations, whether ones they've created or ones you create. It's very flexible. 
Splunk - we use the cb-event-forwarder to dump most all data to Splunk. This allows us to quickly perform analytics on raw endpoint data. With this, we've taken our detection and response to the next level. 

**What do you dislike about Carbon Black EDR?**

Not a deal breaker in any sense - 
1. High availability. Not really an issue since the sensors cache data until the cluster is back online.
2. Cluster upgrade process could be better.
3. Solr has got to go...

**Recommendations to others considering Carbon Black EDR:**

Carbon Black is not traditional IR. It's not slow in any sense and it provides a lot of data. The point being, it will change the game and disrupt the attacker far faster than you will ever do with MIR or HX. Nothing truly compares to what Cb can provide you. If you are having issues, or want to go beyond waiting hours for triage to appear, you should really look at and consider Cb.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Many problems have been solved with Carbon Black including what I believe to be the most important - dwell time. If a breach takes 200+ days to detect, Carbon Black can assist with dropping that dwell time to far less than 1 month. The ability to decrease dwell time and detect things beyond malware is gold. 


  ### 30. If you want to see the anatomy of an attack...

**Rating:** 5.0/5.0 stars

**Reviewed by:** Jared H. | Senior Network Analyst, Government Administration, Enterprise (> 1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

Ability to record and replay events and tuning capability to record fewer event types for nodes with limited connectivity or low bandwidth. Excellent forensic tool for understanding how an attack occurred.

**What do you dislike about Carbon Black EDR?**

I'd love a smaller footprint on the endpoint devices but CarbonBlack is already less intrusive to the host than most products that perform this function. Customized reporting could be easier as well.

**Recommendations to others considering Carbon Black EDR:**

This is a great product for analyzing attacks and malware installations. It will help you figure out which parts of your network are most vulnerable.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Finding out how malware was installed to a corporate endpoint . How did it evade our security software? Was it installed by a user? What machines are infected? Carbon Black has the answers.

  ### 31. CB Review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Collette K. | Cyber Security Forensic Lead, Insurance, Enterprise (> 1000 emp.)

**Reviewed Date:** May 19, 2016

**What do you like best about Carbon Black EDR?**

Ability to see a system activity, file activity, net connections, drilling down by process

**What do you dislike about Carbon Black EDR?**

Dislike the command prompt in the go live feature, commands could be made more user friendly, 

checkin time 

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Incident response, pulling memory from a host quickly

  ### 32. A Powerful Tool For Techie Types

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

It tracks everything. Really. It correlates and provides a timeline of events. You can literally peruse the killchain. You can also find out everyplace a file exists and you can ban it making it very easy to stop an infection.

**What do you dislike about Carbon Black EDR?**

You  need to under the operating system files and calls really well. The watchlists are not intuitive to create. Results are not always as expected but support will help clear it up for you.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Understanding how a breach occurred. Stopping an exploit in progress. Finding malware already in the environment that other tools missed.

  ### 33. Carbon Black Review

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Construction | Enterprise (> 1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

Threat detection and being able to not just see issues on bit 9 but find where it came from originally

**What do you dislike about Carbon Black EDR?**

Not the easiest to use. Find it difficult to move around in the console and look for a specific machine that has a suspected threat. Or any kind of process searching

**Recommendations to others considering Carbon Black EDR:**

If you can have more than just one person working on this solution. It takes a lot of time and focus

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Being able to figure out where our infections come from

  ### 34. CarbonBlack is a delight to work with.  I like the visibility and the hunting aspect it gives me.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

New threat intelligence is added frequently.  I like the recorded aspect and the visibility it gives me into our end points.  I like the fact I can go back in time and hunt for artifacts of intrustions.

**What do you dislike about Carbon Black EDR?**

from triage page the refresh after clearing an alert is not working all the time

**Recommendations to others considering Carbon Black EDR:**

best product we have added into our organization for security.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

forensics, prevention and hunting are all great aspects of this product

  ### 35. Carbon Black gives me visibility that I desperately need.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

The user interface is intuitive, useful and pretty to look at.  Being able to show less experienced admin's exactly what happened and when is incredibly convincing.

**What do you dislike about Carbon Black EDR?**

Stability, - had several issues with storing events, and server side issues.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Incident Response and forensics is actually happening now.  Before we were guessing and hoping.  Now I have data to act on.

  ### 36. Great incident response tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Enterprise (> 1000 emp.)

**Reviewed Date:** December 01, 2015

**What do you like best about Carbon Black EDR?**

Real time analysis of what files are doing on your endpoints.

**What do you dislike about Carbon Black EDR?**

Cost and not a single agent with Parity.

**Recommendations to others considering Carbon Black EDR:**

Great product for incident response.

**What problems is Carbon Black EDR solving and how is that benefiting you?**

Ability to respond to threats in a timely manner.


## Carbon Black EDR Discussions
  - [What does carbon black software do?](https://www.g2.com/discussions/what-does-carbon-black-software-do) - 1 comment

- [View Carbon Black EDR pricing details and edition comparison](https://www.g2.com/products/carbon-black-edr/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-07-30+17%3A06%3A20+-0500&secure%5Bsession_id%5D=a716f337-1581-481b-8619-78beee2cbed5&secure%5Btoken%5D=6c3eb2e1e096cf5ffedb2ad0afb0b8f610f01feba232c7b162a5dc0381280b37&format=llm_user)
## Carbon Black EDR Integrations
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

## Carbon Black EDR Features
**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

## Top Carbon Black EDR Alternatives
  - [Microsoft Defender for Endpoint](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews) - 4.4/5.0 (303 reviews)
  - [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews) - 4.7/5.0 (204 reviews)
  - [Sophos Endpoint](https://www.g2.com/products/sophos-endpoint/reviews) - 4.7/5.0 (793 reviews)

