Top Carbon Black Companies
Browse 0 vetted companies specializing in Carbon Black. Expert Cybersecurity providers with proven Carbon Black expertise. Compare ratings, portfolios, and reviews to find the perfect partner.
We're growing this directory — more Carbon Black companies coming soon.
0 companies found
No companies listed yet for Carbon Black.
List your company →Specialize in Carbon Black?
Get listed and reach clients looking for Carbon Black experts.
List Your Company →Quick Stats
- Companies listed
- 0
VMware Carbon Black is an enterprise endpoint detection and response (EDR) platform used by thousands of organizations worldwide to detect advanced threats, investigate incidents, and prevent breaches across endpoints, servers, and cloud workloads. Companies specializing in Carbon Black deployment and management help security teams get measurable value from the platform without years of internal expertise buildup.
Carbon Black's power comes with significant complexity - policy tuning, sensor deployment at scale, SIEM integration, and alert triage require dedicated expertise that many organizations lack internally. Without proper configuration, teams drown in false positives or miss genuine attacks hiding in behavioral telemetry.
VMware Carbon Black - By the Numbers
- 6,000+ enterprise customers - Carbon Black (now part of Broadcom's portfolio following the 2023 VMware acquisition) serves organizations across finance, healthcare, government, and critical infrastructure.
- $1.5 billion+ - Carbon Black's estimated annual revenue at time of VMware acquisition, reflecting deep enterprise market penetration.
- 400+ billion security events analyzed daily - The Carbon Black Cloud platform processes massive telemetry volumes using behavioral analytics and machine learning threat detection.
- MITRE ATT&CK coverage - Carbon Black Enterprise EDR maps detections to MITRE ATT&CK framework tactics and techniques, supporting structured threat hunting and reporting.
- 2026 Broadcom licensing changes - Following Broadcom's VMware acquisition, Carbon Black licensing and bundling shifted significantly; organizations should reassess contracts and explore MSSP-delivered alternatives.
- 15-minute mean time to detect (MTTD) - Properly tuned Carbon Black deployments help security teams achieve detection times well below the industry average of 24+ hours for sophisticated intrusions.
What Carbon Black Companies Do
Carbon Black Deployment and Sensor Rollout
Managed deployment providers handle enterprise-wide sensor installation across Windows, macOS, and Linux endpoints - including virtual machines, VDI environments, and cloud workloads in AWS, Azure, and GCP. This includes policy group design, exclusion lists, and initial tuning to minimize performance impact on endpoints.
Policy Tuning and False Positive Reduction
Out-of-the-box Carbon Black policies generate significant alert noise in most environments. Specialist partners analyze your organization's software baseline, create application allowlists, tune behavioral policies by business unit, and reduce false positives to make analyst workflows sustainable without sacrificing detection coverage.
Threat Hunting
Carbon Black's Live Response, Process Search, and Enterprise EDR capabilities enable proactive threat hunting. Companies offering this service query Carbon Black telemetry for indicators of compromise (IoCs), hunt for lateral movement patterns, and search for persistence mechanisms using Carbon Black's Query Language (CBQL) and process tree visualization.
Incident Response Using Carbon Black
When a breach occurs, Carbon Black IR specialists use Live Response for remote forensic collection, analyze process trees to reconstruct attack timelines, and leverage network connection data to identify scope. Firms with Carbon Black expertise can compress IR investigation time significantly compared to teams working with unfamiliar tools.
SIEM and SOAR Integration
Carbon Black generates rich telemetry that becomes most powerful when correlated with other security data sources. Integration partners connect Carbon Black to Splunk, Microsoft Sentinel, IBM QRadar, or Palo Alto Cortex XSOAR to enable automated playbooks, enriched alerts, and unified dashboards across the security stack.
Managed Detection and Response (MDR) with Carbon Black
Some providers offer 24/7 MDR services built on Carbon Black, handling alert monitoring, triage, and response actions on behalf of the customer. This model suits organizations that own Carbon Black licenses but lack staffing for round-the-clock security operations.
Carbon Black Services Costs and Pricing
Pricing for Carbon Black professional services depends on endpoint count, engagement scope, and whether you are deploying Carbon Black Cloud (SaaS) or CB Response (on-premises). Note that Broadcom's post-acquisition licensing restructuring in 2024-2025 significantly changed cost structures for many customers.
- Carbon Black Cloud licensing (2025-2026): Broadcom now sells Carbon Black primarily through bundled VMware vDefend packages. Standalone EDR pricing for enterprise customers typically ranges from $30-$60 per endpoint per year for core EDR functionality.
- Deployment services - up to 1,000 endpoints: $15,000-$40,000 for a full deployment engagement including policy design, exclusion tuning, and handover documentation.
- Deployment services - 1,000-10,000 endpoints: $40,000-$120,000 depending on environment complexity (multi-domain, VDI, cloud workloads).
- MDR services on Carbon Black: $15-$40 per endpoint per month for 24/7 monitoring and response, depending on SLA tiers and coverage scope.
- Threat hunting retainer: $5,000-$20,000/month for dedicated proactive hunting services using Carbon Black telemetry, typically including monthly hunt reports and IOC feeds.
- Incident response (emergency): $250-$500/hr for Carbon Black-enabled IR, with many firms offering pre-purchased retainer hours at discounted rates ($15,000-$50,000 retainer blocks).
How to Choose a Carbon Black Partner
Carbon Black's product portfolio changed substantially following Broadcom's 2023 acquisition of VMware. Selecting a partner requires ensuring they track current product direction, not just legacy CB Response or CB Defense knowledge.
- Verify current Broadcom partnership status: With the VMware acquisition, partner programs were reorganized. Confirm the firm holds current Broadcom/VMware Partner status and that their team has completed 2025-2026 certification updates for Carbon Black Cloud and vDefend.
- Ask about policy methodology: Effective Carbon Black deployment is 20% installation and 80% policy refinement. Ask candidates to walk you through how they build initial exclusion lists, how they handle LOLBas (living-off-the-land binaries), and how they validate coverage after tuning.
- Evaluate threat intelligence integration: Strong partners bring external threat intelligence feeds (MISP, commercial TI platforms) and map them into Carbon Black watchlists and IOC feeds, not just work with out-of-the-box detections.
- Request MITRE ATT&CK coverage reporting examples: Ask to see a sample coverage report showing which ATT&CK techniques their Carbon Black configurations detect. This reveals gaps and demonstrates analytical rigor.
- Assess cloud workload experience: If you run workloads in AWS, Azure, or GCP, ensure the partner has deployed Carbon Black Cloud Workload Protection in cloud environments - this requires different expertise than endpoint-only deployments.
- Understand their Broadcom licensing guidance: Partners knowledgeable about the post-acquisition licensing changes can help you right-size or renegotiate contracts - this expertise alone can save six figures on renewals.
VMware Carbon Black - Frequently Asked Questions
What happened to VMware Carbon Black after the Broadcom acquisition?▼
Broadcom completed its acquisition of VMware in November 2023 and subsequently reorganized the VMware product portfolio. Carbon Black security products were rebranded under the VMware vDefend Security platform umbrella. Broadcom shifted Carbon Black to a bundled enterprise licensing model, discontinuing many perpetual and standalone subscription options. Some customers saw significant price increases at renewal, driving some to evaluate alternatives like CrowdStrike Falcon, Microsoft Defender for Endpoint, or SentinelOne. Work with a Broadcom-certified partner to understand your current contract terms and renewal options before your next renewal date.
How long does a Carbon Black deployment typically take?▼
For a 500-2,000 endpoint deployment, expect 6-12 weeks from project kickoff to a tuned, production-ready state. The first 2-3 weeks cover policy design and pilot group deployment to 50-100 endpoints. Weeks 3-6 involve full rollout in sensor-only or report-only mode to collect baseline telemetry. The final phase - tuning policies to reduce false positives and enable blocking - typically takes another 2-4 weeks of iteration. Rushing this process leads to operational disruption from overly aggressive policies or missed detections from overly permissive ones.
Can Carbon Black replace our antivirus solution?▼
Yes - Carbon Black Cloud Endpoint Standard (previously CB Defense) includes Next-Generation Antivirus (NGAV) functionality that can replace traditional signature-based AV. It uses behavioral analysis and machine learning rather than signature databases, meaning it can detect novel malware that signature-based tools miss. Many organizations run a "replace AV" project as the first phase of Carbon Black deployment, eliminating one agent from endpoints before adding Carbon Black's EDR capabilities. Confirm with your compliance and cyber insurance requirements that NGAV satisfies your AV mandate before decommissioning legacy AV.
What is the difference between Carbon Black Cloud EDR and Enterprise EDR?▼
Carbon Black Cloud Endpoint Standard (formerly CB Defense) is the core NGAV+EDR offering with alert-driven investigation. Carbon Black Enterprise EDR (formerly CB Response) is the advanced tier designed for threat hunters and mature security operations - it provides continuous endpoint data recording, unlimited historical telemetry query, Live Response for remote shell access, and integration with threat intelligence platforms. Enterprise EDR generates significantly more data and requires analyst expertise to leverage effectively. Most mid-market organizations start with Endpoint Standard and upgrade to Enterprise EDR as their SOC matures.
How does Carbon Black handle Linux and macOS endpoints?▼
Carbon Black Cloud supports Windows, macOS (including Apple Silicon Macs on modern sensor versions), and Linux (major distributions including RHEL, CentOS, Ubuntu, and Amazon Linux). Linux sensor support lags slightly behind Windows in feature parity - some behavioral detection capabilities and Live Response features have limited Linux support compared to Windows. macOS support has improved significantly with sensor versions compatible with macOS 13 Ventura through macOS 15 Sequoia. When evaluating Carbon Black for heterogeneous environments, request a sensor compatibility matrix for your specific OS versions and distributions before committing.