--- title: Carbon Black EDR Reviews meta\_title: 'Carbon Black EDR Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 87 reviews by the users' company size, role or industry to find out how Carbon Black EDR works for a business like yours. aggregate\_rating: rating\_value: 4.4 review\_count: 87 scale: '5' date\_modified: '2026-08-07' parent\_category: name: Endpoint Protection url: https://www.g2.com/categories/endpoint-protection ---

# Carbon Black EDR Reviews & Product Details

Claimed

###### Profile Status

This profile is currently managed by Carbon Black EDR but has limited features.  
  
Are you part of the Carbon Black EDR team? [Upgrade your plan](https://sell.g2.com) to enhance your branding and engage with visitors to your profile!

Carbon Black EDR is a market-leading incident response and threat hunting solution designed to provide responders with the most information possible, accompanied by expert threat analysis and armed with real-time response capabilities to stop attacks, minimize damage and close security gaps. Carbon Black EDR makes these teams more efficient, reducing investigations from days to hours, and more effective, enabling them to discover threats before attacks can exploit them. Carbon Black EDR also allows teams to connect to and isolate infected machines to prevent lateral movement and remediate devices without costly IT involvement. Continuous and Centralized Recording Centralized access to continuously recorded endpoint data means that security professionals have the information they need to hunt threats in real time as well as conduct in-depth investigations after a breach has occurred. Live Response for Remote Remediation With Live Response, incident responders can create a secure connection to infected hosts to pull or push files, kill processes, perform memory dumps and quickly remediate from anywhere in the world. Attack Chain Visualization and Search Carbon Black EDR provides intuitive attack chain visualization to make identifying root cause fast and easy. Analysts can quickly jump through each stage of an attack to gain insight into the attacker’s behavior, close security gaps and learn from every new attack technique to avoid falling victim to the same attack twice. Automation via Integrations and Open APIs Carbon Black boasts a robust partner ecosystem and open platform that allows security teams to integrate products like Carbon Black EDR into their existing security stack.

* * *

Seller
[Broadcom](https://www.g2.com/sellers/broadcom-ab3091cd-4724-46a8-ac89-219d6bc8e166)
Discussions
[Carbon Black EDR Community](https://www.g2.com/products/carbon-black-edr/discuss)
Languages Supported

English

Solution Type

Best-of-Breed

Overview by
Hope Boyer

Show More

## Value at a Glance

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

## Top-Rated Alternatives

[

 ![Microsoft Defender for Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Microsoft Defender for Endpoint")

Microsoft Defender for Endpoint

4.4/5(312)

](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)

[

 ![SentinelOne Singularity Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SentinelOne Singularity Endpoint")

SentinelOne Singularity Endpoint

4.7/5(211)

](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)

[

 ![Sophos Endpoint](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Sophos Endpoint")

Sophos Endpoint

4.7/5(837)

](https://www.g2.com/products/sophos-endpoint/reviews)

[
View All Alternatives
](https://www.g2.com/products/carbon-black-edr/competitors/alternatives)

## User Insights

Average based on 87 real user reviews.

Implementation Time

3 months

Perceived Cost

$$$$$

[Log in to unlock pricing and user insights](/login)

## Carbon Black EDR Integrations
(2)

What do users say about integrations?

Integration information sourced from real user reviews.

[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Proofpoint Threat Response Auto-Pull

](https://www.g2.com/products/proofpoint-threat-response-auto-pull/reviews)[

 ![Product Avatar Image](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Product Avatar Image")

Splunk Enterprise

](https://www.g2.com/products/splunk-enterprise/reviews)

Show More

JH

Jared H.

Senior Network Analyst

Government Administration

Enterprise (\> 1000 emp.)

12/1/2015

"If you want to see the anatomy of an attack..."

5/5

What do you like best about Carbon Black EDR?

Ability to record and replay events and tuning capability to record fewer event types for nodes with limited connectivity or low bandwidth. Excellent forensic tool for understanding how an attack occurred. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

I'd love a smaller footprint on the endpoint devices but CarbonBlack is already less intrusive to the host than most products that perform this function. Customized reporting could be easier as well. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

This is a great product for analyzing attacks and malware installations. It will help you figure out which parts of your network are most vulnerable. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Finding out how malware was installed to a corporate endpoint . How did it evade our security software? Was it installed by a user? What machines are infected? Carbon Black has the answers. Review collected by and hosted on G2.com.

Show More

12/13/2015
Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Collette K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Collette K.")
CK

Collette K.

Cyber Security Forensic Lead

Insurance

Enterprise (\> 1000 emp.)

5/19/2016

"CB Review"

4/5

What do you like best about Carbon Black EDR?

Ability to see a system activity, file activity, net connections, drilling down by process Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Dislike the command prompt in the go live feature, commands could be made more user friendly,

checkin time Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Incident response, pulling memory from a host quickly Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite

 ![Verified User in Information Technology and Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Information Technology and Services")
AI

Verified User in Information Technology and Services

Mid-Market (51-1000 emp.)

12/1/2015

"A Powerful Tool For Techie Types"

3/5

What do you like best about Carbon Black EDR?

It tracks everything. Really. It correlates and provides a timeline of events. You can literally peruse the killchain. You can also find out everyplace a file exists and you can ban it making it very easy to stop an infection. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

You need to under the operating system files and calls really well. The watchlists are not intuitive to create. Results are not always as expected but support will help clear it up for you. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Understanding how a breach occurred. Stopping an exploit in progress. Finding malware already in the environment that other tools missed. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Construction](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Construction")
AC

Verified User in Construction

Enterprise (\> 1000 emp.)

12/1/2015

"Carbon Black Review"

3.5/5

What do you like best about Carbon Black EDR?

Threat detection and being able to not just see issues on bit 9 but find where it came from originally Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Not the easiest to use. Find it difficult to move around in the console and look for a specific machine that has a suspected threat. Or any kind of process searching Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

If you can have more than just one person working on this solution. It takes a lot of time and focus Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Being able to figure out where our infections come from Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Computer Software](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Computer Software")
AC

Verified User in Computer Software

Mid-Market (51-1000 emp.)

12/1/2015

"CarbonBlack is a delight to work with. I like the visibility and the hunting aspect it gives me."

5/5

What do you like best about Carbon Black EDR?

New threat intelligence is added frequently. I like the recorded aspect and the visibility it gives me into our end points. I like the fact I can go back in time and hunt for artifacts of intrustions. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

from triage page the refresh after clearing an alert is not working all the time Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

best product we have added into our organization for security. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

forensics, prevention and hunting are all great aspects of this product Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Financial Services](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Financial Services")
AF

Verified User in Financial Services

Enterprise (\> 1000 emp.)

12/1/2015

"Carbon Black gives me visibility that I desperately need."

4/5

What do you like best about Carbon Black EDR?

The user interface is intuitive, useful and pretty to look at. Being able to show less experienced admin's exactly what happened and when is incredibly convincing. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Stability, - had several issues with storing events, and server side issues. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Incident Response and forensics is actually happening now. Before we were guessing and hoping. Now I have data to act on. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerIncentivizedSource: G2 invite on behalf of seller

 ![Verified User in Oil & Energy](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User in Oil & Energy")
AO

Verified User in Oil & Energy

Enterprise (\> 1000 emp.)

12/1/2015

"Great incident response tool"

5/5

What do you like best about Carbon Black EDR?

Real time analysis of what files are doing on your endpoints. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Cost and not a single agent with Parity. Review collected by and hosted on G2.com.

Recommendations to others considering Carbon Black EDR:

Great product for incident response. Review collected by and hosted on G2.com.

What problems is Carbon Black EDR solving and how is that benefiting you?

Ability to respond to threats in a timely manner. Review collected by and hosted on G2.com.

Show More

1/4/2016
Validated ReviewerIncentivizedSource: G2 invite on behalf of seller

## Questions about Carbon Black EDR? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

[
Ask about Carbon Black EDR
](https://www.g2.com/products/carbon-black-edr/discussions/new)

GU

Guest User
•
Last activity over 3 years ago

What does carbon black software do?

0 Upvotes

1

[
Join the conversation
](https://www.g2.com/discussions/what-does-carbon-black-software-do)

[
View all Discussions
](https://www.g2.com/products/carbon-black-edr/discuss)

## Pricing Insights

Averages based on real user reviews.

### Time to Implement

3 months

### Return on Investment

16 months

### Average Discount

19%

[
View More Pricing Information
](https://www.g2.com/products/carbon-black-edr/pricing)

Carbon Black EDR Comparisons

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_4e2b08dd17397bdc99a5658447cbc589/microsoft-defender-for-endpoint.jpg "Product Avatar Image")

Microsoft Defender for...

4.4/5(312)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-microsoft-defender-for-endpoint)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_14c966aee92aa8713f0bf6eb7b139afa/carbon-black-cloud.png "Product Avatar Image")

Carbon Black Cloud

4.1/5(39)

[
Compare Now
](https://www.g2.com/compare/carbon-black-cloud-vs-carbon-black-edr)

 ![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/small_square/small_square_5292562d6a2cb01ab3d34a4e57a3225a/sentinelone-singularity-endpoint.png "Product Avatar Image")

SentinelOne Singularity...

4.7/5(211)

[
Compare Now
](https://www.g2.com/compare/carbon-black-edr-vs-sentinelone-singularity-endpoint)

##### Categories on G2

[Endpoint Detection & Response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr)

##### Explore More

[Which Contact Center AI Observability platforms are most trusted by compliance officers in regulated industries based on user reviews?](https://www.g2.com/discussions/which-contact-center-ai-observability-platforms-are-most-trusted-by-compliance-officers-in-regulated-industries-based-on-user-reviews)[What is the best recruitment marketing tool for employer branding?](https://www.g2.com/discussions/what-is-the-best-recruitment-marketing-tool-for-employer-branding)[Top AWS Marketplace solutions for DevOps workflows](https://www.g2.com/discussions/which-aws-marketplace-solutions-are-best-for-devops-workflows)

[Which cloud directory provider has the best security and compliance features for a healthcare organization that has strict access control requirements?](https://www.g2.com/discussions/which-cloud-directory-provider-has-the-best-security-and-compliance-features-for-a-healthcare-organization-that-has-strict-access-control-requirements)[Which AI content tool offers the most natural language output?](https://www.g2.com/discussions/which-ai-content-tool-offers-the-most-natural-language-output)[Pros and Cons Details](https://www.g2.com/products/carbon-black-edr/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)