Softwr
V

VMware Carbon Black

Cloud-delivered endpoint protection and EDR, now owned by Broadcom and positioned alongside Symantec.

As of 30 August 2026, VMware Carbon Black's pricing is not published; the vendor quotes on request. A single-agent EDR and endpoint prevention product with a cloud console and unusually deep vSphere integration. Softwr lists it under Cybersecurity. VMware Carbon Black is made by Broadcom (formerly VMware), launched in 2002, available on Windows, macOS, API.

Overview

What VMware Carbon Black does

Carbon Black Cloud is a SaaS endpoint security product. One sensor on Windows, macOS and Linux feeds a hosted console, and the capabilities are sold as tiers on top of that sensor: Endpoint Standard for behavioural prevention, Enterprise EDR for continuous recording and threat hunting, Audit and Remediation for live queries across the fleet, plus workload and container editions. The company began as Bit9, merged with the original Carbon Black, was bought by VMware in 2019, and passed to Broadcom when its VMware acquisition closed in November 2023. Carbon Black now sits in Broadcom's enterprise security business alongside Symantec, and the VMware branding is being retired. What distinguishes it technically is that Enterprise EDR streams endpoint events continuously rather than only when something alerts. Process launches, network connections and file modifications are sent to the cloud whether or not a detection fires, so an analyst can ask a question in March about what happened in January. Most prevention-first products only retain what they flagged, which means an investigation into something they did not flag has nothing to look at. The second distinguishing piece is the vSphere path: the workload sensor deploys through the ESXi host rather than requiring a separate install inside every guest, which was the reason many VMware shops chose it. That advantage is now attached to a hypervisor whose licensing Broadcom has restructured, so the technical fit and the commercial risk come from the same place. It is bought by security teams that already have someone to operate it: a SOC that wants raw telemetry to hunt over, an MDR provider running it on a client's behalf, or a VMware-heavy estate consolidating agents. The trade-off is ownership rather than technology. Broadcom concentrates direct sales and support on its largest accounts and routes the rest through partners, so a mid-size customer can lose named contacts and meet a materially different quote at renewal. Beneath that sits the ordinary EDR trade-off: the product produces telemetry, not answers, and an organisation without an analyst or a managed service ends up paying to record data nobody reads.

What people use it for

  • A SOC that wants unfiltered endpoint telemetry to hunt over rather than only vendor-generated alerts
  • A vSphere estate that wants workload protection deployed through the hypervisor instead of installing an agent in every guest
  • Replacing signature antivirus after an incident where the incumbent product had no record of what the attacker did
  • An organisation already inside a Broadcom or Symantec enterprise agreement that can consolidate endpoint onto an existing contract

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about VMware Carbon Black.

  • Broadcom's enterprise model concentrates direct sales and support on its largest accounts and moves everyone else to resellers, so a mid-size customer can lose named support contacts and face a substantially repriced renewal with limited notice.
  • Continuous EDR recording is retained for a defined window and longer retention is a paid tier, so the investigation you most need is often the one whose telemetry has already aged out, and that is discovered during the incident rather than before it.
  • The product assumes an operator: watchlists, policy tuning and alert triage are ongoing work, and organisations without a dedicated analyst or an MDR contract typically leave policies in monitor mode and pay for telemetry that is never reviewed.
  • The sensor operates in the same kernel and file-filter territory as other endpoint agents, so running it alongside an incumbent antivirus, DLP or backup agent commonly produces performance complaints and requires maintained exclusion lists on both sides.
  • Linux sensor support is tied to specific distribution and kernel versions, so a routine operating system upgrade can leave hosts without a supported sensor until a matching build ships, and anything outside the supported list gets no coverage at all.

Cross-shopped

What people choose instead of VMware Carbon Black

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

Pricing

What VMware Carbon Black costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

CB Endpoint Standard

Free

  • NGAV
  • Behavioral EDR
  • Device control
  • Contact sales for pricing

CB Endpoint Advanced

Free

  • All Standard features
  • Threat hunting
  • Audit and remediation
  • Vulnerability management

CB Endpoint Enterprise

Free

  • All Advanced features
  • Advanced threat hunting
  • Live response
  • Custom watchlists

Capabilities

Features

  • Endpoint Standard

    Behavioural prevention driven by policy rules on process reputation and observed actions rather than signatures alone

  • Enterprise EDR

    Continuous recording of process, network and file events to the cloud for retrospective hunting

  • Audit and Remediation

    SQL-style live queries run across the fleet to answer inventory and configuration questions on demand

  • Single sensor

    One agent supplies prevention, EDR and query rather than three separate installs

  • Live Response

    Interactive remote shell on an endpoint for containment, collection and cleanup

  • Workload protection

    vSphere deployment through the ESXi host instead of a per-guest agent install

  • Container security

    Image scanning and Kubernetes posture checks in the container tier

  • Watchlists and feeds

    Saved queries and IOC feeds that raise an alert when incoming telemetry matches

  • Policy groups

    Per-group prevention rules so servers, developer machines and standard laptops can differ

  • REST API

    Documented API for exporting alerts and telemetry into a SIEM or SOAR platform

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Who owns Carbon Black now?

Broadcom. It acquired VMware in November 2023, and Carbon Black now sits in Broadcom's enterprise security business alongside Symantec. VMware branding is being phased out.

Why do the docs use names I do not recognise?

The product has been renamed repeatedly. CB Defense is now Endpoint Standard, CB ThreatHunter is Enterprise EDR and CB LiveOps is Audit and Remediation. Older community answers and runbooks still use the previous names.

Does it replace my existing antivirus?

Yes on supported Windows, macOS and Linux versions, and running it alongside another antivirus is not recommended because the two agents contend for the same hooks. Check your compliance requirements, as some auditors still ask for a named antivirus product.

Do I need a full-time analyst to run it?

To get value from Enterprise EDR, effectively yes. The prevention tier can run with part-time attention, but the hunting and recording capability is only worth its cost if somebody is querying it, which is why many customers buy it through an MDR provider.

How is it licensed?

Per endpoint, per year, with the capability tier determining the rate and workload and container protection priced separately. Extended EDR data retention is an additional line item.

Behind it

Who makes VMware Carbon Black

Company
Broadcom (formerly VMware)
Based in
Palo Alto, California, USA
Share

Keep looking

Where to go from VMware Carbon Black

Best Cybersecurity software for

Compare VMware Carbon Black with

Other Cybersecurity software

  • Powerful protection against evolving threats

    From $36/yr14 researched notes
  • The world's most-loved password manager

    From $2.99/mo10 researched notes
  • Simplify online life with LastPass password manager

    Free plan12 researched notes
  • Stop breaches with AI-native cybersecurity

    Free, then $7.99/device/month12 researched notes
  • Autonomous endpoint protection and response

    11 researched notes
  • XDR platform correlating Trend Micro's endpoint, email, server, cloud and network sensors, licensed through a shared credit pool.

    From $75/yr14 researched notes
  • Email security and data protection suite from a private company owned by Thoma Bravo, licensed per user with modules sold separately.

    From $6/mo14 researched notes
  • Advanced endpoint protection with deep learning

    From $28/yr11 researched notes
  • No-code drag-and-drop authentication platform.

    Free, then $249/mo12 researched notes
  • Agentic trust management with compliance automation.

    12 researched notes
  • Managed video loss prevention with human auditors for restaurants, convenience stores and retail

    Pricing on request12 researched notes
  • Consumer VPN registered in the British Virgin Islands, owned by Kape Technologies since 2021, with repeated third-party audits.

    From $6.67/mo14 researched notes
  • CNCF-graduated runtime threat detection for Linux and Kubernetes using eBPF

    Open source12 researched notes

Softwr does not host reviews and shows no star rating for VMware Carbon Black, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on VMware Carbon Black

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare VMware Carbon Black with alternatives