Software / Application Control / Carbon Black

Carbon Black

Carbon Black is Broadcom’s endpoint security portfolio for threat prevention, behavioral detection, incident response, application control and workload protection.

7.9/10 TechZella Score
Visit Website ↗
At a glance

Quick Verdict

Carbon Black offers broad endpoint, EDR, application control and workload capabilities, with documented APIs and integrations. G2 reviews are generally positive, but reviewers also mention cost, dashboard responsiveness and configuration complexity.

Overview

Carbon Black is Broadcom’s security software portfolio for protecting endpoints, servers, virtual machines and cloud workloads. Its products combine prevention, behavioral analytics, endpoint detection and response, threat hunting, application control and remediation.

The portfolio includes Carbon Black Endpoint, Carbon Black Cloud, Carbon Black EDR, Carbon Black App Control and Carbon Black Workload. Carbon Black originated as Bit9 in 2002 and became part of Broadcom after Broadcom completed its VMware acquisition on November 22, 2023.

Key Features

Carbon Black Cloud provides next-generation antivirus, behavioral EDR, ransomware detection, custom detection rules, endpoint telemetry, investigation tools and real-time audit and remediation.

Carbon Black EDR supports continuous endpoint activity recording, attack-chain visualization, threat hunting and live response. App Control uses an allowlist-oriented positive security model, while Workload extends visibility and protection to public, private and hybrid cloud environments.

The platform supports integrations through APIs, SDKs, data forwarding and security-stack connectors. Endpoint Standard can forward alert data to SIEM platforms that accept standard Syslog data.

Pricing

Broadcom does not publish standard Carbon Black list prices on its product pages. The official buying path directs customers to Broadcom partners or sales representatives.

Publicly listed pricing varies by product, edition, endpoint or workload count, deployment model and contract terms. No official free-trial offer was publicly listed in the reviewed product materials.

Pros & Cons

Pros: Broad product coverage, strong endpoint telemetry, behavioral detection, threat-hunting workflows, documented APIs and support for cloud and on-premises deployments.

Cons: Pricing is not transparent, product selection can be complex, and independent reviews mention configuration effort, occasional dashboard slowness and resource or compatibility concerns.

Alternatives

Comparable products include Microsoft Defender for Endpoint, SentinelOne Singularity, Sophos Endpoint, CrowdStrike Falcon, Trellix Endpoint Security and Palo Alto Networks Cortex XDR. The closest choice depends on deployment requirements, existing security tooling, cloud coverage and preferred response workflows.

FAQ

What is Carbon Black? Carbon Black is Broadcom’s portfolio of endpoint protection, endpoint detection and response, application control and workload security products.

Which operating systems does Carbon Black support? Carbon Black Endpoint Standard documentation lists Windows, macOS and Linux support. Exact versions depend on the sensor release and product edition.

Does Carbon Black have an API? Yes. Carbon Black Cloud provides platform and product-specific REST APIs, API keys, a Python SDK and integration documentation.

Does Carbon Black integrate with SIEM tools? Yes. Endpoint Standard can forward alert data to systems that accept standard Syslog data. Carbon Black also documents broader APIs and integration resources.

Is Carbon Black available as a free trial? No official public free-trial offer was identified in the reviewed Broadcom materials. Prospective customers are directed to sales or partners.

Capabilities

Features

Endpoint Protection

  • Next-generation antivirus
  • Behavioral threat detection
  • Malware and non-malware prevention
  • Living-off-the-land attack detection
  • Ransomware detection and prevention
  • Custom detection rules

Detection and Response

  • Endpoint activity telemetry
  • Threat investigation
  • Attack-chain visualization
  • Threat hunting
  • Live response
  • Remote remediation
  • Alert prioritization

Application and Workload Security

  • Positive security model
  • Application allowlisting
  • Change prevention
  • Cloud workload protection
  • Hybrid cloud visibility
  • CIS benchmark support

Integrations and API

  • REST APIs
  • API-key authentication
  • Python SDK
  • Syslog alert forwarding
  • Data forwarding
  • Security-stack integrations
Product details

Specifications

DeploymentCloud-native and on-premises product options
Supported operating systemsWindows, macOS and Linux
Primary interfaceWeb console
APICarbon Black Cloud REST APIs, product APIs and Python SDK
IntegrationsSyslog-capable SIEM platforms, documented APIs and security-stack integrations
Free TrialNot publicly listed
Pricing modelCustom quote through Broadcom or partners
VendorBroadcom
OriginFounded as Bit9 in 2002
Visual preview

Demo & Screenshots

Screenshots are not available yet.TechZella will add verified product images when suitable official screenshots are found.
Our evidence-based assessment

TechZella Score

A proprietary editorial score based on product capabilities, usability, value, performance, support and user sentiment evidence.

7.9/10Moderate confidence
Features8.8
Ease of Use7.8
Value for Money6.8
Performance8.4
Support7.4
User Sentiment8.1

Carbon Black offers broad endpoint, EDR, application control and workload capabilities, with documented APIs and integrations. G2 reviews are generally positive, but reviewers also mention cost, dashboard responsiveness and configuration complexity.

Methodology v1.0. This is a TechZella editorial assessment, not a direct user-review average.

Independent review sources

Trusted Ratings

Ratings are published by the respective review platforms and may change over time.

Plans & pricing

Pricing

Carbon Black

Contact sales
Custom contract

Broadcom does not publish standard public pricing. Customers are directed to Broadcom partners or sales representatives. No official public free trial was identified.

Check current pricing →

Pricing may change. Verify current plans on the vendor's website.

Editorial assessment

Pros & Cons

Pros

  • Covers endpoint prevention, EDR, application control and workload protection.
  • Provides detailed endpoint telemetry for investigation and threat hunting.
  • Offers documented REST APIs, API keys, SDKs and integration resources.
  • Supports Windows, macOS and Linux endpoint environments.
  • Includes cloud-native and on-premises product options.

Cons

  • Public pricing is not available, requiring a sales or partner engagement.
  • The portfolio contains several products and editions, which can complicate selection.
  • Some independent reviewers report dashboard slowness, configuration effort or compatibility issues.
  • Advanced capabilities may require dedicated security operations expertise.
Similar software

Alternatives

Compare options

Top Competitors

Community feedback

Reviews

No reviews yet. Be the first to share your experience.

Write a Review