build 7bbbddf7 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 267 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: endpoint-security/vmware-carbon-black locale: en labels: vendor: Carbon Black Cloud capability/security: 2.16 capability/endpoint-security: 3.54 vendor/vmware: 0.88 annotations: source: src/content/solutions/en/endpoint-security/vmware-carbon-black.md route: /en/solutions/endpoint-security/vmware-carbon-black/ schema: /nerd/schema/solutions.json markdown: /en/solutions/endpoint-security/vmware-carbon-black.mdspec: title: Carbon Black tags: [security, endpoint-security] vendors: [vmware] summary: >- Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures. photoNeed: A security console on screen with real alerts in it, being triaged stub: false draft: false kind: product addon: false vendorName: Carbon Black Cloud status: current practice: >- Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later. practiceReview: true sections: - heading:

What it is

body: | Carbon Black watches process behaviour on an endpoint and reports what does not fit. A sensor on the machine supplies the events; the analysis runs in the cloud. The difference from classic antivirus is the question being asked. Not "do I recognise this file", but "why is this Office document starting PowerShell". - heading:

What it is for

body: | Estates that want not only to stop an incident but to reconstruct it. Much of the value is in the recording: after something happens, you can work out what happened. That assumes somebody is looking. EDR with nobody assigned to it is a data store. - heading:

What changed

body: | Broadcom's acquisition of VMware moved the product into a different business unit. That changes little about the product in the short term and quite a lot about contracts and who you talk to. Check both before the next renewal.status: corpus: 267 services: - {ref: services/modern-workplace, score: 0.81} - {ref: services/security, score: 0.76} - {ref: services/network, score: 0.49} - {ref: services/cloud, score: 0.41} posts: - {ref: posts/vmware-security-advisory, score: 0.57} - {ref: posts/vmware-security-advisory-vmsa-2024-0012, score: 0.57} - {ref: posts/vmware-security-advisory-vmsa-2022-0030, score: 0.57} - {ref: posts/vmware-security-advisory-2022-021, score: 0.57} - {ref: posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter, score: 0.51} - {ref: posts/how-to-broadcom-download-token, score: 0.51} experts: - {ref: experts/matthias-frech, score: 0.38} neighbours: - {ref: solutions/endpoint-security, score: 1.00} - {ref: solutions/endpoint-security/microsoft-defender-atp, score: 0.70} - {ref: solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance, score: 0.51}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "endpoint-security/vmware-carbon-black", "locale": "en", "labels": { "vendor": "Carbon Black Cloud", "capability/security": "2.16", "capability/endpoint-security": "3.54", "vendor/vmware": "0.88" }, "annotations": { "source": "src/content/solutions/en/endpoint-security/vmware-carbon-black.md", "route": "/en/solutions/endpoint-security/vmware-carbon-black/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/endpoint-security/vmware-carbon-black.md" } }, "spec": { "title": "Carbon Black", "tags": [ "security", "endpoint-security" ], "vendors": [ "vmware" ], "summary": "Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures.", "photoNeed": "A security console on screen with real alerts in it, being triaged", "stub": false, "draft": false, "kind": "product", "addon": false, "vendorName": "Carbon Black Cloud", "status": "current", "practice": "Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later.\n", "practiceReview": true }, "sections": [ { "heading": "

What it is

",
"body": "Carbon Black watches process behaviour on an endpoint and reports what does not fit. A\nsensor on the machine supplies the events; the analysis runs in the cloud.\n\nThe difference from classic antivirus is the question being asked. Not \"do I recognise\nthis file\", but \"why is this Office document starting PowerShell\"." }, { "heading": "

What it is for

",
"body": "Estates that want not only to stop an incident but to reconstruct it. Much of the value is\nin the recording: after something happens, you can work out what happened.\n\nThat assumes somebody is looking. EDR with nobody assigned to it is a data store." }, { "heading": "

What changed

",
"body": "Broadcom's acquisition of VMware moved the product into a different business unit. That\nchanges little about the product in the short term and quite a lot about contracts and who\nyou talk to. Check both before the next renewal." } ], "status": { "corpus": 267, "services": [ { "ref": "services/modern-workplace", "score": "0.81" }, { "ref": "services/security", "score": "0.76" }, { "ref": "services/network", "score": "0.49" }, { "ref": "services/cloud", "score": "0.41" } ], "posts": [ { "ref": "posts/vmware-security-advisory", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-vmsa-2024-0012", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-vmsa-2022-0030", "score": "0.57" }, { "ref": "posts/vmware-security-advisory-2022-021", "score": "0.57" }, { "ref": "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter", "score": "0.51" }, { "ref": "posts/how-to-broadcom-download-token", "score": "0.51" } ], "experts": [ { "ref": "experts/matthias-frech", "score": "0.38" } ], "neighbours": [ { "ref": "solutions/endpoint-security", "score": "1.00" }, { "ref": "solutions/endpoint-security/microsoft-defender-atp", "score": "0.70" }, { "ref": "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance", "score": "0.51" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "endpoint-security/vmware-carbon-black"locale = "en"[metadata.labels]vendor = "Carbon Black Cloud""capability/security" = "2.16""capability/endpoint-security" = "3.54""vendor/vmware" = "0.88"[metadata.annotations]source = "src/content/solutions/en/endpoint-security/vmware-carbon-black.md"route = "/en/solutions/endpoint-security/vmware-carbon-black/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/endpoint-security/vmware-carbon-black.md"[spec]title = "Carbon Black"tags = ["security", "endpoint-security"]vendors = ["vmware"]summary = "Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures."photoNeed = "A security console on screen with real alerts in it, being triaged"stub = falsedraft = falsekind = "product"addon = falsevendorName = "Carbon Black Cloud"status = "current"practice = '''Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later.'''practiceReview = true[[sections]]heading = "

What it is

"
body = '''Carbon Black watches process behaviour on an endpoint and reports what does not fit. Asensor on the machine supplies the events; the analysis runs in the cloud.The difference from classic antivirus is the question being asked. Not "do I recognisethis file", but "why is this Office document starting PowerShell".'''[[sections]]heading = "

What it is for

"
body = '''Estates that want not only to stop an incident but to reconstruct it. Much of the value isin the recording: after something happens, you can work out what happened.That assumes somebody is looking. EDR with nobody assigned to it is a data store.'''[[sections]]heading = "

What changed

"
body = '''Broadcom's acquisition of VMware moved the product into a different business unit. Thatchanges little about the product in the short term and quite a lot about contracts and whoyou talk to. Check both before the next renewal.'''[status]corpus = 267[[status.services]]ref = "services/modern-workplace"score = "0.81"[[status.services]]ref = "services/security"score = "0.76"[[status.services]]ref = "services/network"score = "0.49"[[status.services]]ref = "services/cloud"score = "0.41"[[status.posts]]ref = "posts/vmware-security-advisory"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2024-0012"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-vmsa-2022-0030"score = "0.57"[[status.posts]]ref = "posts/vmware-security-advisory-2022-021"score = "0.57"[[status.posts]]ref = "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter"score = "0.51"[[status.posts]]ref = "posts/how-to-broadcom-download-token"score = "0.51"[[status.experts]]ref = "experts/matthias-frech"score = "0.38"[[status.neighbours]]ref = "solutions/endpoint-security"score = "1.00"[[status.neighbours]]ref = "solutions/endpoint-security/microsoft-defender-atp"score = "0.70"[[status.neighbours]]ref = "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance"score = "0.51"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>endpoint-security/vmware-carbon-black</name> <locale>en</locale> <labels> <vendor>Carbon Black Cloud</vendor> <entry key="capability/security">2.16</entry> <entry key="capability/endpoint-security">3.54</entry> <entry key="vendor/vmware">0.88</entry> </labels> <annotations> <source>src/content/solutions/en/endpoint-security/vmware-carbon-black.md</source> <route>/en/solutions/endpoint-security/vmware-carbon-black/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/endpoint-security/vmware-carbon-black.md</markdown> </annotations> </metadata> <spec> <title>Carbon Black</title> <tags> <item>security</item> <item>endpoint-security</item> </tags> <vendors> <item>vmware</item> </vendors> <summary>Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures.</summary> <photoNeed>A security console on screen with real alerts in it, being triaged</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <addon>false</addon> <vendorName>Carbon Black Cloud</vendorName> <status>current</status> <practice>Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later. </practice> <practiceReview>true</practiceReview> </spec> <sections> <section> <heading>

What it is

</heading>
<body>Carbon Black watches process behaviour on an endpoint and reports what does not fit. Asensor on the machine supplies the events; the analysis runs in the cloud.The difference from classic antivirus is the question being asked. Not "do I recognisethis file", but "why is this Office document starting PowerShell". </body> </section> <section> <heading>

What it is for

</heading>
<body>Estates that want not only to stop an incident but to reconstruct it. Much of the value isin the recording: after something happens, you can work out what happened.That assumes somebody is looking. EDR with nobody assigned to it is a data store. </body> </section> <section> <heading>

What changed

</heading>
<body>Broadcom's acquisition of VMware moved the product into a different business unit. Thatchanges little about the product in the short term and quite a lot about contracts and whoyou talk to. Check both before the next renewal. </body> </section> </sections> <status> <corpus>267</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.81</score> </item> <item> <ref>services/security</ref> <score>0.76</score> </item> <item> <ref>services/network</ref> <score>0.49</score> </item> <item> <ref>services/cloud</ref> <score>0.41</score> </item> </services> <posts> <item> <ref>posts/vmware-security-advisory</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2024-0012</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-vmsa-2022-0030</ref> <score>0.57</score> </item> <item> <ref>posts/vmware-security-advisory-2022-021</ref> <score>0.57</score> </item> <item> <ref>posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter</ref> <score>0.51</score> </item> <item> <ref>posts/how-to-broadcom-download-token</ref> <score>0.51</score> </item> </posts> <experts> <item> <ref>experts/matthias-frech</ref> <score>0.38</score> </item> </experts> <neighbours> <item> <ref>solutions/endpoint-security</ref> <score>1.00</score> </item> <item> <ref>solutions/endpoint-security/microsoft-defender-atp</ref> <score>0.70</score> </item> <item> <ref>solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance</ref> <score>0.51</score> </item> </neighbours> </status></manifest>
Solution · VMware

Carbon Black

The vendor calls it: Carbon Black Cloud

Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures.

VMware Pinnacle Partner

Topics Security 2.16 Endpoint Security 3.54
Vendors VMware 0.88
04Services
06Posts
02Capabilities
267Corpus

What it is

Carbon Black watches process behaviour on an endpoint and reports what does not fit. A sensor on the machine supplies the events; the analysis runs in the cloud.

The difference from classic antivirus is the question being asked. Not “do I recognise this file”, but “why is this Office document starting PowerShell”.

What it is for

Estates that want not only to stop an incident but to reconstruct it. Much of the value is in the recording: after something happens, you can work out what happened.

That assumes somebody is looking. EDR with nobody assigned to it is a data store.

What changed

Broadcom’s acquisition of VMware moved the product into a different business unit. That changes little about the product in the short term and quite a lot about contracts and who you talk to. Check both before the next renewal.

What we do with it

Draft, unreviewed

Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later.

This paragraph is a draft and nobody at soulTec has confirmed it yet. Everything above it describes the product and is checkable against the vendor.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.