---
# source: src/content/solutions/en/endpoint-security/vmware-carbon-black.md
# route:  /en/solutions/endpoint-security/vmware-carbon-black/
title: Carbon Black
tags: [security, endpoint-security]
vendors: [vmware]
summary: Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures.
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: product
addon: false
vendorName: Carbon Black Cloud
status: current
practice: >
  Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later.
practiceReview: true
---

## What it is

Carbon Black watches process behaviour on an endpoint and reports what does not fit. A
sensor on the machine supplies the events; the analysis runs in the cloud.

The difference from classic antivirus is the question being asked. Not "do I recognise
this file", but "why is this Office document starting PowerShell".

## What it is for

Estates that want not only to stop an incident but to reconstruct it. Much of the value is
in the recording: after something happens, you can work out what happened.

That assumes somebody is looking. EDR with nobody assigned to it is a data store.

## What changed

Broadcom's acquisition of VMware moved the product into a different business unit. That
changes little about the product in the short term and quite a lot about contracts and who
you talk to. Check both before the next renewal.
