JH
Jared H.
Senior Network Analyst
Government Administration
Enterprise (> 1000 emp.)
"If you want to see the anatomy of an attack..."
5/5
What do you like best about Carbon Black EDR?

Ability to record and replay events and tuning capability to record fewer event types for nodes with limited connectivity or low bandwidth. Excellent forensic tool for understanding how an attack occurred. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

I'd love a smaller footprint on the endpoint devices but CarbonBlack is already less intrusive to the host than most products that perform this function. Customized reporting could be easier as well. Review collected by and hosted on G2.com.

Collette K.
CK
Collette K.
Cyber Security Forensic Lead
Insurance
Enterprise (> 1000 emp.)
"CB Review"
4/5
What do you like best about Carbon Black EDR?

Ability to see a system activity, file activity, net connections, drilling down by process Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Dislike the command prompt in the go live feature, commands could be made more user friendly,

checkin time Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"A Powerful Tool For Techie Types"
3/5
What do you like best about Carbon Black EDR?

It tracks everything. Really. It correlates and provides a timeline of events. You can literally peruse the killchain. You can also find out everyplace a file exists and you can ban it making it very easy to stop an infection. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

You need to under the operating system files and calls really well. The watchlists are not intuitive to create. Results are not always as expected but support will help clear it up for you. Review collected by and hosted on G2.com.

Verified User in Construction
AC
Verified User in Construction
Enterprise (> 1000 emp.)
"Carbon Black Review"
3.5/5
What do you like best about Carbon Black EDR?

Threat detection and being able to not just see issues on bit 9 but find where it came from originally Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Not the easiest to use. Find it difficult to move around in the console and look for a specific machine that has a suspected threat. Or any kind of process searching Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"CarbonBlack is a delight to work with. I like the visibility and the hunting aspect it gives me."
5/5
What do you like best about Carbon Black EDR?

New threat intelligence is added frequently. I like the recorded aspect and the visibility it gives me into our end points. I like the fact I can go back in time and hunt for artifacts of intrustions. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

from triage page the refresh after clearing an alert is not working all the time Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"Carbon Black gives me visibility that I desperately need."
4/5
What do you like best about Carbon Black EDR?

The user interface is intuitive, useful and pretty to look at. Being able to show less experienced admin's exactly what happened and when is incredibly convincing. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Stability, - had several issues with storing events, and server side issues. Review collected by and hosted on G2.com.

Verified User in Oil & Energy
AO
Verified User in Oil & Energy
Enterprise (> 1000 emp.)
"Great incident response tool"
5/5
What do you like best about Carbon Black EDR?

Real time analysis of what files are doing on your endpoints. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Cost and not a single agent with Parity. Review collected by and hosted on G2.com.