--- title: Carbon Black EDR Reviews meta\_title: 'Carbon Black EDR Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 87 reviews by the users' company size, role or industry to find out how Carbon Black EDR works for a business like yours. aggregate\_rating: rating\_value: 4.4 review\_count: 87 scale: '5' date\_modified: '2026-08-07' parent\_category: name: Endpoint Protection url: https://www.g2.com/categories/endpoint-protection ---

# Carbon Black EDR Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by Carbon Black EDR but has limited features.  
  
Are you part of the Carbon Black EDR team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

Carbon Black EDR is a market-leading incident response and threat hunting solution designed to provide responders with the most information possible, accompanied by expert threat analysis and armed with real-time response capabilities to stop attacks, minimize damage and close security gaps. Carbon Black EDR makes these teams more efficient, reducing investigations from days to hours, and more effective, enabling them to discover threats before attacks can exploit them. Carbon Black EDR also allows teams to connect to and isolate infected machines to prevent lateral movement and remediate devices without costly IT involvement. Continuous and Centralized Recording Centralized access to continuously recorded endpoint data means that security professionals have the information they need to hunt threats in real time as well as conduct in-depth investigations after a breach has occurred. Live Response for Remote Remediation With Live Response, incident responders can create a secure connection to infected hosts to pull or push files, kill processes, perform memory dumps and quickly remediate from anywhere in the world. Attack Chain Visualization and Search Carbon Black EDR provides intuitive attack chain visualization to make identifying root cause fast and easy. Analysts can quickly jump through each stage of an attack to gain insight into the attacker’s behavior, close security gaps and learn from every new attack technique to avoid falling victim to the same attack twice. Automation via Integrations and Open APIs Carbon Black boasts a robust partner ecosystem and open platform that allows security teams to integrate products like Carbon Black EDR into their existing security stack.

* * *

Seller
[Broadcom](https://www.g2.com/sellers/broadcom-ab3091cd-4724-46a8-ac89-219d6bc8e166)
Discussions
[Carbon Black EDR Community](https://www.g2.com/products/carbon-black-edr/discuss)
Languages Supported

English

Solution Type

Best-of-Breed

Overview by
Hope Boyer

Show More

## Value at a Glance

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

## Top-Rated Alternatives

[

 ![Microsoft Defender for Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Microsoft Defender for Endpoint")

Microsoft Defender for Endpoint

4.4/5(312)

](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)

[

 ![SentinelOne Singularity Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SentinelOne Singularity Endpoint")

SentinelOne Singularity Endpoint

4.7/5(212)

](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)

[

 ![Sophos Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Sophos Endpoint")

Sophos Endpoint

4.7/5(837)

](https://www.g2.com/products/sophos-endpoint/reviews)

[
View All Alternatives
](https://www.g2.com/products/carbon-black-edr/competitors/alternatives)

## User Insights

Average based on 87 real user reviews.

Implementation Time

3 months

Perceived Cost

$$$$$

[Log in to unlock pricing and user insights](/login)

## Carbon Black EDR Integrations
(2)

What do users say about integrations?

Integration information sourced from real user reviews.

[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Proofpoint Threat Response Auto-Pull

](https://www.g2.com/products/proofpoint-threat-response-auto-pull/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Splunk Enterprise

](https://www.g2.com/products/splunk-enterprise/reviews)

Show More

 ![Verified User in Utilities](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Utilities")
AU

Verified User in Utilities

Enterprise (\> 1000 emp.)

5/1/2017

"Easy to use - provides valuable information quickly"

5/5

What do you like best about Carbon Black EDR?

This makes it very easy to search a specific threat domain to see if anyone visited it. Very helpful in analyzing Phishing attempts and if the user actually clicked on them. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Some queries can be complex, requires use of API for some more advanced searching. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Very easy endpoint to install, just "install and go" to start collecting data. Plan what type of data is relevant, so you don't overload yourself with Watchlists that trigger too many false positives. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

This provides us with our Incident Response management, and also allows us to quickly review IOC's when they are released. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: Organic

 ![Verified User in Computer & Network Security](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer & Network Security")
AC

Verified User in Computer & Network Security

Small-Business (50 or fewer emp.)

10/4/2017

"Fantastic Forensics"

4/5

What do you like best about Carbon Black EDR?

Response hints threats in real time so you get instant intelligence Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Would prefer for the Cb portfolio to all sit as one agent. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Visibility across our entire network means I can massively reduce investigation time and therefor time to remediation is much better Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Government Administration](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Government Administration")
AG

Verified User in Government Administration

Mid-Market (51-1000 emp.)

5/4/2017

"Incident response made easy"

5/5

What do you like best about Carbon Black EDR?

After installling cb Response everyhing is visibel in your environment, and you can search through your events really easy. It doesn't matter what you want to find you can do a search on it very easy. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Configuration is mostly done in conf files, and is not vrey user friendly. Not all supports have a deap linux experiance, whitch can be an problem when the product is based on linux. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Deploy it as fast as possible, its a great product. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

CB response makes incident response very easy. you can searche on everything and makes long IR jobs really fast. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: Seller invite

 ![Verified User in Investment Management](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Investment Management")
AI

Verified User in Investment Management

Mid-Market (51-1000 emp.)

5/1/2017

"Unrivaled visibility and invaluable IR tool"

4.5/5

What do you like best about Carbon Black EDR?

Our IR team loves the ability to get instant access to what has occurred on our endpoints in the organization. With the ability to instantly get access to the machine through Live response. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

The console can get a bit slow if you haven't put in appropriate filters. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Incident response Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

 ![Verified User in Computer Software](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer Software")
EC

Verified User in Computer Software

Mid-Market (51-1000 emp.)

2/14/2017

"One of our best security investments"

4.5/5

What do you like best about Carbon Black EDR?

Cb response gives us excellent visibility into our endpoints. We have decided to balance our strategy and focus more on detection and response. We all know if the talented bad guys want to get in, they will. With Cb, I have a virtual video recorder on all my endpoints (servers and workstations) and alerting that is effective. It took us about a month to fine tune. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

The pricing model could improve. Given Cb's recent acquisitions and focus on "beyond AV", having the suite of products, including Protection makes most sense. But I find the pricing to be sometimes complex and expensive for cloud version. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

We wanted visibility into endpoints and ability to detect and contain a threat once identified. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Consumer Goods](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Consumer Goods")
EC

Verified User in Consumer Goods

Enterprise (\> 1000 emp.)

5/4/2017

"Best EDR tools around"

4.5/5

What do you like best about Carbon Black EDR?

Integrated Threat Feeds, Integrations with SIEM, Detects threats not found by other methods. Great hunting and response tool. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

It would be nice if there were granular block actions that could be performed by the product. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Resolving Security Risks and detecting advanced threats. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: Seller invite

 ![Verified User in Telecommunications](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Telecommunications")
UT

Verified User in Telecommunications

Enterprise (\> 1000 emp.)

4/21/2017

"One of the best security products I have used "

5/5

What do you like best about Carbon Black EDR?

Really easy to use and brilliant 'workflow' . The community around this product is also great and it's easy to create rules/watch lists Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Would like to see better search result display options thT can be useful when hunting Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Visibility into the endpoint whenever something has to be looked at , great for incident response Review collected by and hosted on G2.com.

Show More

Validated ReviewerSource: Organic

 ![Brad M.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brad M.")
BM

Brad M.

Senior Enterprise Systems Engineer

Retail

Mid-Market (51-1000 emp.)

4/13/2016

"See Everything on your endpoints"

5/5

What do you like best about Carbon Black EDR?

Carbon Black Enterprise Response provides awesome visibility into your endpoints. Being able to view the process chain of an attack is very useful in learning how the attacks work, preventing them from happening again and educating our users. Very easy to deploy agents and start gathering useful data. Lots of great intelligence feeds. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

I have had some issues with re-occurring alerts even after i have mark them as as Resolved or Resolved False Positive. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Being able to see exactly what is going on has been huge for us. We have Carbon Black Enterprise Protection keeping malicious and unwanted software from running, but Enterprise Response shows us how these items are getting on our machines. I have used Enterprise Response numerous times to track down blocked Ransom-ware attacks to malicious email attachments our users have opened. Before Enterprise Response it was difficult if not impossible to find the cause of these types of attacks. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: Organic

 ![Verified User in Financial Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Financial Services")
AF

Verified User in Financial Services

Enterprise (\> 1000 emp.)

6/9/2016

"granular process insight"

3.5/5

What do you like best about Carbon Black EDR?

The granular insight into what process/files are doing what to whom, and when. The watch lists provide a great way to triage suspicious activities and direct daily monitoring and incident response. Integration with CB Enterprise Protection (formerly bit9). Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

We're still tuning, but the enormous amount of standard events are quite a bit to comb through. While it is a monitoring tool, i often have requests to produce reports to illustrate 'what this product is delivering for the company', which i've yet to find a good solution. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

We brought in CB Response for a special use case in a sensitive environment where we thought we should have more detailed visibility. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Electrical/Electronic Manufacturing](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Electrical/Electronic Manufacturing")
UE

Verified User in Electrical/Electronic Manufacturing

Enterprise (\> 1000 emp.)

1/23/2016

"Carbon Black - Detect and Respond"

5/5

What do you like best about Carbon Black EDR?

Cb has provided us visibility into threat behavior beyond any product out there today. The ability to ban malicious files, create feeds, watch lists, open API, integrations with many other products (and ability to add other products easily), Live Response, isolation and much more, make Cb the differentiator over any other ETDR product on the market today.

Carbon Black provides the ability to also go back in time, which defeats a lot of other products in the space that only can go back a short period of time without disrupting the endpoint. The centralized infrastructure methodology makes sense for Cb as it technically can save money vs other products that will run CPU/mem to the max and begin to overwhelm the workstation/server. Cb is a very lightweight sensor, we see around 0-1% CPU, and 10-28Mb of memory. 28Mb on the high end for instances where it is a busy server like TMG or Exchange.

Cb is deployed to around 60k endpoints with no issues. We've had minor hiccups over time caused by Cb, but nothing widespread and nothing that wasn't fixed on the new patch level etc.

Working with Cb is probably one of the best things about the product. The PM team, engineering, executive team are all great people. Not forgetting the sales team, they are good people too. Everyone at Cb is committed to working and ensuring their product is the best. We have been with Cb since 4.2 and it has really grown a lot since.

the API - is probably one of the most important features to Carbon Black that many products out there fail at. The ability to automate and orchestrate a lot of threat hunting, or even remediation tasks is incredible. Many products fail at this part, or place in API in after the fact. Cb is also 100% committed to ensuring the API is very flexible. They have some of the best developers working it.

Integrations - Cb allows for many integrations, whether ones they've created or ones you create. It's very flexible.

Splunk - we use the cb-event-forwarder to dump most all data to Splunk. This allows us to quickly perform analytics on raw endpoint data. With this, we've taken our detection and response to the next level. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Not a deal breaker in any sense -

1. High availability. Not really an issue since the sensors cache data until the cluster is back online.

2. Cluster upgrade process could be better.

3. Solr has got to go... Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Carbon Black is not traditional IR. It's not slow in any sense and it provides a lot of data. The point being, it will change the game and disrupt the attacker far faster than you will ever do with MIR or HX. Nothing truly compares to what Cb can provide you. If you are having issues, or want to go beyond waiting hours for triage to appear, you should really look at and consider Cb. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Many problems have been solved with Carbon Black including what I believe to be the most important - dwell time. If a breach takes 200+ days to detect, Carbon Black can assist with dropping that dwell time to far less than 1 month. The ability to decrease dwell time and detect things beyond malware is gold. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: Organic

## Questions about Carbon Black EDR? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about Carbon Black EDR
](https://www.g2.com/products/carbon-black-edr/discussions/new)

GU

Guest User
•
Last activity over 3 years ago

What does carbon black software do?

0 Upvotes

1

[
Join the conversation
](https://www.g2.com/discussions/what-does-carbon-black-software-do)

[
View all Discussions
](https://www.g2.com/products/carbon-black-edr/discuss)

## Pricing Insights

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

### Average Discount

19%

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

Carbon Black EDR Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_4e2b08dd17397bdc99a5658447cbc589/microsoft-defender-for-endpoint.jpg "Product Avatar Image")

Microsoft Defender for...

4.4/5(312)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-microsoft-defender-for-endpoint)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_14c966aee92aa8713f0bf6eb7b139afa/carbon-black-cloud.png "Product Avatar Image")

Carbon Black Cloud

4.1/5(39)

[
Compare Now
](https://www.g2.com/compare/carbon-black-cloud-vs-carbon-black-edr)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_5292562d6a2cb01ab3d34a4e57a3225a/sentinelone-singularity-endpoint.png "Product Avatar Image")

SentinelOne Singularity...

4.7/5(212)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-sentinelone-singularity-endpoint)

##### Categories on G2

[Endpoint Detection & Response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr)

##### Explore More

[Which partner ecosystem software is the best for tracking partner-sourced and partner-influenced revenue so partnerships can actually prove their contribution to the business?](https://www.g2.com/discussions/which-partner-ecosystem-software-is-the-best-for-tracking-partner-sourced-and-partner-influenced-revenue-so-partnerships-can-actually-prove-their-contribution-to-the-business)[Best iPaaS for small business software integration](https://www.g2.com/discussions/what-s-the-best-ipaas-for-small-business-software-integration)[Which ERM systems have the most stable and reliable uptime record with proven customer support, based on user reviews?](https://www.g2.com/discussions/which-erm-systems-have-the-most-stable-and-reliable-uptime-record-with-proven-customer-support-based-on-user-reviews)

[What is the recommended knowledge management software for customer support?](https://www.g2.com/discussions/what-is-the-recommended-knowledge-management-software-for-customer-support)[Which web client accelerators have the best caching and compression effectiveness?](https://www.g2.com/discussions/which-web-client-accelerators-have-the-best-caching-and-compression-effectiveness)[Pros and Cons Details](https://www.g2.com/products/carbon-black-edr/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)