avatar Carbon Black (VMware) Review

Carbon Black provides robust endpoint protection and EDR capabilities. Strengths include real-time threat detection and response. Areas for improvement include complex deployment and potential performance impact on endpoints.

Visit site

What we love:

Malware Prevention

Strong next-gen antivirus with machine learning and behavioral analysis, but occasional false positives.

8/10

Threat Detection and Response

Excellent EDR capabilities with real-time visibility, advanced threat hunting, and automated response actions.

9/10

Data Loss Prevention

Basic DLP features, but not as comprehensive as dedicated DLP solutions.

6/10

Malware Prevention Review

We've found Carbon Black's malware prevention capabilities to be robust and effective. The platform's next-generation antivirus leverages machine learning and behavioral analysis to detect and block both known and unknown threats. We appreciate its ability to prevent fileless attacks and script-based malware. The real-time threat intelligence feed keeps the system up-to-date with emerging threats. We've noticed a significant reduction in false positives compared to traditional antivirus solutions. Carbon Black's integration with VMware's ecosystem enhances its effectiveness, particularly in virtualized environments. The centralized management console makes it easy for our team to monitor and respond to threats across our network. While the solution is comprehensive, we found the initial setup and fine-tuning process to be somewhat complex. However, once properly configured, it provides excellent protection against a wide range of malware threats.

Threat Detection and Response Review

Carbon Black's Threat Detection and Response capability has impressed us with its comprehensive approach. We appreciate how it combines endpoint detection and response (EDR) with next-generation antivirus, providing a robust defense against various threats.

The real-time visibility into endpoint activities is particularly valuable, allowing us to quickly identify and respond to potential security incidents. We've found the behavioral analytics and machine learning algorithms effective in detecting both known and unknown threats.

The integration with VMware's broader security ecosystem enhances its overall effectiveness. However, we did notice a slight learning curve for our team to fully utilize all features.

While the solution occasionally generates false positives, the ability to fine-tune alerts has helped mitigate this issue. Overall, Carbon Black's Threat Detection and Response functionality has significantly improved our security posture and incident response capabilities.

Data Loss Prevention Review

Carbon Black's Data Loss Prevention (DLP) capabilities have impressed our team. The solution effectively monitors and controls sensitive data across our endpoints, preventing unauthorized exfiltration. We appreciate its robust policy engine, allowing us to create custom rules tailored to our organization's needs.

The real-time visibility into data movement has enhanced our security posture significantly. We've noticed improved incident response times and reduced false positives. The integration with other Carbon Black modules provides a comprehensive security approach.

However, we found the initial setup and configuration process somewhat complex. The learning curve for fine-tuning policies can be steep. Additionally, the reporting features could be more intuitive and customizable.

Overall, Carbon Black's DLP functionality offers strong protection for our sensitive data, though there's room for improvement in user experience and reporting capabilities.

Vulnerability Management Review

We've been impressed with Carbon Black's Vulnerability Management capabilities. The solution provides comprehensive visibility into our endpoints, allowing us to identify and prioritize vulnerabilities effectively. Its real-time scanning and continuous monitoring help us stay on top of potential threats.

The integration with VMware's ecosystem enhances our overall security posture. We appreciate the user-friendly interface and customizable dashboards, which make it easy to track and manage vulnerabilities across our network.

One standout feature is the ability to correlate vulnerabilities with active threats, enabling us to focus on the most critical issues. The automated patching and remediation workflows have significantly reduced our response times.

While the solution is robust, we've encountered occasional false positives. Overall, Carbon Black's Vulnerability Management functionality has greatly improved our security operations and risk management efforts.

Device Control Review

Carbon Black's Device Control feature has significantly enhanced our organization's security posture. We appreciate its granular control over USB devices, allowing us to manage external storage effectively. The policy-based approach enables us to tailor restrictions for different user groups, balancing security needs with productivity.

We've noticed improved visibility into device usage across our network, helping us identify potential risks quickly. The real-time alerts for unauthorized device activities have been particularly useful in preventing data exfiltration attempts.

While the interface is generally user-friendly, we found the initial setup process somewhat complex. However, once configured, it runs smoothly with minimal maintenance required. Overall, Carbon Black's Device Control has proven to be a robust tool in our security arsenal, effectively mitigating risks associated with removable media and external devices.

Basics

avatar

Advanced

avatar

Support

avatar

Technical

avatar

Best for company size?

Small Business 6/10
Mid-sized Business 8/10
Large business 9/10

Industry Focus

Financial Services 9/10
Healthcare 8/10
Government 9/10
Retail 7/10
Manufacturing 8/10
Technology 9/10
Education 7/10
Energy 8/10
Telecommunications 8/10
Transportation 7/10