--- title: Carbon Black EDR Reviews meta\_title: 'Carbon Black EDR Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 87 reviews by the users' company size, role or industry to find out how Carbon Black EDR works for a business like yours. aggregate\_rating: rating\_value: 4.4 review\_count: 87 scale: '5' date\_modified: '2026-08-07' parent\_category: name: Endpoint Protection url: https://www.g2.com/categories/endpoint-protection ---

# Carbon Black EDR Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by Carbon Black EDR but has limited features.  
  
Are you part of the Carbon Black EDR team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

Carbon Black EDR is a market-leading incident response and threat hunting solution designed to provide responders with the most information possible, accompanied by expert threat analysis and armed with real-time response capabilities to stop attacks, minimize damage and close security gaps. Carbon Black EDR makes these teams more efficient, reducing investigations from days to hours, and more effective, enabling them to discover threats before attacks can exploit them. Carbon Black EDR also allows teams to connect to and isolate infected machines to prevent lateral movement and remediate devices without costly IT involvement. Continuous and Centralized Recording Centralized access to continuously recorded endpoint data means that security professionals have the information they need to hunt threats in real time as well as conduct in-depth investigations after a breach has occurred. Live Response for Remote Remediation With Live Response, incident responders can create a secure connection to infected hosts to pull or push files, kill processes, perform memory dumps and quickly remediate from anywhere in the world. Attack Chain Visualization and Search Carbon Black EDR provides intuitive attack chain visualization to make identifying root cause fast and easy. Analysts can quickly jump through each stage of an attack to gain insight into the attacker’s behavior, close security gaps and learn from every new attack technique to avoid falling victim to the same attack twice. Automation via Integrations and Open APIs Carbon Black boasts a robust partner ecosystem and open platform that allows security teams to integrate products like Carbon Black EDR into their existing security stack.

* * *

Seller
[Broadcom](https://www.g2.com/sellers/broadcom-ab3091cd-4724-46a8-ac89-219d6bc8e166)
Discussions
[Carbon Black EDR Community](https://www.g2.com/products/carbon-black-edr/discuss)
Languages Supported

English

Solution Type

Best-of-Breed

Overview by
Hope Boyer

Show More

## Value at a Glance

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

## Top-Rated Alternatives

[

 ![Microsoft Defender for Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Microsoft Defender for Endpoint")

Microsoft Defender for Endpoint

4.4/5(312)

](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)

[

 ![SentinelOne Singularity Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SentinelOne Singularity Endpoint")

SentinelOne Singularity Endpoint

4.7/5(212)

](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)

[

 ![Sophos Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Sophos Endpoint")

Sophos Endpoint

4.7/5(837)

](https://www.g2.com/products/sophos-endpoint/reviews)

[
View All Alternatives
](https://www.g2.com/products/carbon-black-edr/competitors/alternatives)

## User Insights

Average based on 87 real user reviews.

Implementation Time

3 months

Perceived Cost

$$$$$

[Log in to unlock pricing and user insights](/login)

## Carbon Black EDR Integrations
(2)

What do users say about integrations?

Integration information sourced from real user reviews.

[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Proofpoint Threat Response Auto-Pull

](https://www.g2.com/products/proofpoint-threat-response-auto-pull/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Splunk Enterprise

](https://www.g2.com/products/splunk-enterprise/reviews)

Show More

 ![Ananthu R.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Ananthu R.")
AR

Ananthu R.

Senior Information Security Consultant LTI

Mid-Market (51-1000 emp.)

3/28/2022

"CB Response Full Visibility to Endpoints"

4.5/5

What do you like best about Carbon Black EDR?

The best in the market(provide proactive detections based on Behaviour and silent threats on the endpoints) Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

The Alerting part can be customized (So that the analyst can create custom rules more creative and detect insider threats and PUPs) Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Gives me a full view on the related and the triggered process and its behavior,It provides to see the process and way of flow Review collected by and hosted on G2.com.

Show More

10/1/2022
Validated ReviewerSource: Organic

 ![Nishant K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Nishant K.")
NK

Nishant K.

security Engineer

Enterprise (\> 1000 emp.)

6/17/2021

Business partner of the seller or seller's competitor, not included in G2 scores.

"Best endpoint malware detection tool among the others present in the market"

4.5/5

What do you like best about Carbon Black EDR?

This has one of the best correlation mechanics which enables Cb to fetch data from various sources and that too very precisely categorized. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Defensive capability needs more upgrades Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Go for it best solution for an organization Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Real time host devices scanning is one of the beat features to monitor changes that happen in any endpoint. It helps a lot in managing systems and resolving system level issues with ease. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
UI

Verified User in Information Technology and Services

Mid-Market (51-1000 emp.)

7/16/2020

"Carbon Black Response "Hands of Threat Hunters""

4/5

What do you like best about Carbon Black EDR?

When securing the enterprise organizations we cannot only depend on SIEM, threat intelligence and firewall management. Protecting internal endpoint devices is one of challenging job for the organization. Carbon Black Response defend against known as well as emerging threats, so the endpoint users work with confidence that their devices are secured. It is user friendly and very effective tool when we consider the endpoint security and Threat hunting. It gives complete visibility of every endpoint/sensors in organization. It provides threat intelligence feeds and reports for all know threats and malware signatures. It also provides customization watchlists by creating own queries so we can set alerts according to requirement. Process and binary searches are very good feature and very useful for threat hunting. We can block/ban the binaries and also isolate the endpoint which is best of the tool. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Analyst requires good skills for investigate and threat hunting purpose, it is somewhat difficult for beginners to work on CB Response as it requires deep knowledge of all the processes and it's executions.

Threat Intel reports generate some false positive alerts which are hectic sometimes. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

CB Response is must have tool for all security professionals. It is very helpful for effective threat hunting and securing the endpoints. It gives complete visibility of each and every process executing on the endpoint devices. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Benefits are you can do threat hunting very effectively by deeply hunting IOC's and threat signatures. Problems we facing that we have to manually check the reputations of the binaries. It is better if tool give reputations or can give functionality to call API of some reputation check sites. Review collected by and hosted on G2.com.

Show More

7/30/2020
Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Law Practice](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Law Practice")
AL

Verified User in Law Practice

Enterprise (\> 1000 emp.)

7/13/2020

"Carbon Black Response - the standard"

4.5/5

What do you like best about Carbon Black EDR?

I can find what I am looking for when I need it. The product providers us with rich telemetry and can pretty much find anything on a machine where many others cannot. Isolate functions very well and it fast. Most SOC/Incident Response providers use this tool so its best to have this in your organization and deployed already. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Some complex searches using wild cards do not work very well. Some searching capabilities could be improved to make it easier. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

An EDR tool is supposed to be used for investigations and containment. How long does it take you to contain a file/hash and machine? It should be fast and CBR delivers!! Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

CBR provides us with depth of telemetry from all our devices world-wide. It allows us to hunt and perform incident response anywhere. Review collected by and hosted on G2.com.

Show More

Validated ReviewerSource: Organic

 ![Kevin K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Kevin K.")
KK

Kevin K.

IT Director

Information Technology and Services

Mid-Market (51-1000 emp.)

5/3/2017

"CB Response - Improve Your Endpoint Visibility and Lower Response Times"

4.5/5

What do you like best about Carbon Black EDR?

CB Response provides our staff with an extremely detailed and concise overview of our endpoints. Utilizing the tools provided by Response, we can effectively track threats, be notified of detected threats, and quickly investigate and respond to those threats all from one interface. The fact that this is a single product which incorporates all these tools is wonderful. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

As with their CB Protection product, I feel that the administrative interface can be a bit challenging at times. Without prior training on the product, it would be difficult to navigate and perform investigations. Thankfully, the product was provided with an in-depth training process to assist our staff with being acclimated within the environment. By completing the training, my staff was very comfortable navigating and using the product. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

The biggest lift when implementing this product was the steep hardware requirements. Make sure you have a dedicated server with high-end CPU, RAM, and storage components. The product is collecting, querying, and storing data constantly and requires a significantly powerful server. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

The biggest challenge that CB Response solves for our company is the ability to detect, quickly respond, and investigate a threat so that we can take pro-active measures in preventing future threats. The 'Watchlist' component is a valuable tool in which our staff can craft custom events, sequences, or procedures which indicate bad behavior on the system. Using the query language, the various activity logs can be searched to investigate what and endpoint was doing prior, during, and after a reported issue. Review collected by and hosted on G2.com.

Show More

9/6/2019
Current UserValidated ReviewerIncentivizedSource: Seller invite

 ![Verified User in Fund-Raising](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Fund-Raising")
UF

Verified User in Fund-Raising

Mid-Market (51-1000 emp.)

10/16/2019

"Great forensics tool "

4.5/5

What do you like best about Carbon Black EDR?

We have Carbon Black Response running as part of a Managed Security offering. It has detected quite a few issues on the machines where it was installed. This includes obfuscated powershell code and excel documents that run executables. Having this kind of detection makes use trust our security posture even more.

We occasionally use it for troubleshooting purposes, so nothing security related. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Luckily for us it is a managed service and so we do not have to do anything ourselves. Otherwise is would take a steep learning curve to take the most advantage of this product. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

If you need the forensics capabilities this is the go-to product. Just make sure you have in-house knowledge or get it as a managed service. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

We needed the extra protection and the forensics data. So far it has proved useful in detecting malicious or at least questionable software. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

JG

Jeremy G.

Cyber Security Admin

Enterprise (\> 1000 emp.)

9/30/2019

"Carbon Black Response"

4/5

What do you like best about Carbon Black EDR?

I mostly like the Go Live feature to be able to use that for basic administration and/or for other security reasons and being able to have this way to access a pc is useful for me. Most other features we have not even been able to dive into yet and are currently still reviewing. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

I haven't used their support in awhile so I'm not sure on how they are currently doing in that area. Hopefully it's just our server with it being in a master/slave cluster but the email alerts to detection's seem to be slow. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Response may have more features than what you need. If you use their watchlists/alerting you can't really fine tune those out for your environment and it seems to be an either turn on or off type of thing. It's been awhile since I was able to check that and it may have changed to the better, hopefully. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Being able to assist with pcs that lose domain trust and no longer having to ship them to us. Used it to search out what processes happening on a device to understand what happened when something broke on a pc to know when the issue started. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: Seller invite

 ![Verified User in Financial Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Financial Services")
UF

Verified User in Financial Services

Enterprise (\> 1000 emp.)

8/29/2019

"Incident Response - On Prem"

5/5

What do you like best about Carbon Black EDR?

The API's - Ability to write Python or PowerShell Scripts allows us to pull data back faster than if we had to log into the system and it also saves a ton of time. We have also used their Community portal where customers share development scripts.

Intelligence feeds allow us to pull down data from our Threat Intel vendor into CbR and then create WatchList from it.

GoLive - I love this feature to have full access to a machine, it allows us to upload files / scripts and then pull down the results. This has speed up IR. Also gives us a quick way to determine if our AV quarantined a file or if the file still exists on the file system Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

GoLive command interface could use some work, the commands are very limited and not like the DOS or Linux commands we are used to. Ex Can't do "dir /s" or delete a whole folder.

Creating complex watchlists are not that intuitive, it's easy to mess them up and you would not know it unless you had sample / test cases to run them thru.

Very little access control, either have Global rights or Admin rights. We are two version back, so they have made enhancements to allow access to only certain Sensor groups and GoLive.

Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

You need to have an understanding of the OS's that you going to deploy to. Ex. Understand the file system along with system calls. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Determine what happened on a machine for Incident Response by our Security Operations Center and Forensics teams

Being able to figure out where the infections came from (Phishing Emails, Web Download, Unwanted Software package in with other apps, etc)

We have reduced the amount of time it tasks an analysis to perform their daily job functions. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: Organic

 ![Melisa J.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Melisa J.")
MJ

Melisa J.

Director of IT

Computer Software

Mid-Market (51-1000 emp.)

8/3/2019

"Real time threat hunting and incident response solution. "

4.5/5

What do you like best about Carbon Black EDR?

Cb response on Windows endpoints it is easy deploy, maintain and support. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Cb response management tool is not much user friendly especially if you are not well

trained. It may be able to start effective investigation at First side, is better there should be some training for incident response team. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

If your company still on old fashion end points which has lower system resources,then is time you upgrade your end points before they raise complains for slow performance regardless of their task. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

This is a healthy and thriving resources that has enabled our team to perform remote lnvestigation. It has got an excellent feature called window assets which is able to give response which gives response which is stable and offers unparallel insights into what is going on your end point with a minimum suport required. In addition to that user exchange has been very helpful in that in almost an kind of endpoint activity there are reachable details hence enabling tracking of threa. tbytools and give response to them in real time Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
AI

Verified User in Information Technology and Services

Mid-Market (51-1000 emp.)

5/1/2017

"A great analysis tool"

5/5

What do you like best about Carbon Black EDR?

-Ease of use

-Easy to deploy agents

-Ability to auto upgrade sensors as new updates are released.

-Intelligence feeds that make CB response what it is.

-Ability to create custom watch lists Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

CB tends to push out sensor updates and CB application updates that seem to not have been tested enough which leads to issues in Production that sometimes take longer then usual in resolving. The lack of development with response as there seems to be a lack of updates as CB has been concentrating more on PSC. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

I would recommend testing Threat hunter by CB as well and comparing both Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Having the ability to monitor and analyse any potential threads or attacks in progress across all end points. With CB response, we were able to detect an attack and quickly isolate hosts affected. Review collected by and hosted on G2.com.

Show More

8/29/2019
Current UserValidated ReviewerIncentivizedSource: Seller invite

## Questions about Carbon Black EDR? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about Carbon Black EDR
](https://www.g2.com/products/carbon-black-edr/discussions/new)

GU

Guest User
•
Last activity over 3 years ago

What does carbon black software do?

0 Upvotes

1

[
Join the conversation
](https://www.g2.com/discussions/what-does-carbon-black-software-do)

[
View all Discussions
](https://www.g2.com/products/carbon-black-edr/discuss)

## Pricing Insights

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

### Average Discount

19%

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

Carbon Black EDR Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_4e2b08dd17397bdc99a5658447cbc589/microsoft-defender-for-endpoint.jpg "Product Avatar Image")

Microsoft Defender for...

4.4/5(312)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-microsoft-defender-for-endpoint)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_14c966aee92aa8713f0bf6eb7b139afa/carbon-black-cloud.png "Product Avatar Image")

Carbon Black Cloud

4.1/5(39)

[
Compare Now
](https://www.g2.com/compare/carbon-black-cloud-vs-carbon-black-edr)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_5292562d6a2cb01ab3d34a4e57a3225a/sentinelone-singularity-endpoint.png "Product Avatar Image")

SentinelOne Singularity...

4.7/5(212)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-sentinelone-singularity-endpoint)

##### Categories on G2

[Endpoint Detection & Response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr)

##### Explore More

[Which partner ecosystem software is the best for tracking partner-sourced and partner-influenced revenue so partnerships can actually prove their contribution to the business?](https://www.g2.com/discussions/which-partner-ecosystem-software-is-the-best-for-tracking-partner-sourced-and-partner-influenced-revenue-so-partnerships-can-actually-prove-their-contribution-to-the-business)[Best iPaaS for small business software integration](https://www.g2.com/discussions/what-s-the-best-ipaas-for-small-business-software-integration)[Which ERM systems have the most stable and reliable uptime record with proven customer support, based on user reviews?](https://www.g2.com/discussions/which-erm-systems-have-the-most-stable-and-reliable-uptime-record-with-proven-customer-support-based-on-user-reviews)

[What is the recommended knowledge management software for customer support?](https://www.g2.com/discussions/what-is-the-recommended-knowledge-management-software-for-customer-support)[Which web client accelerators have the best caching and compression effectiveness?](https://www.g2.com/discussions/which-web-client-accelerators-have-the-best-caching-and-compression-effectiveness)[Pros and Cons Details](https://www.g2.com/products/carbon-black-edr/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)