EDR / Broadcom

Carbon Black Cloud Enterprise EDR

Carbon Black Cloud Enterprise EDR focuses on endpoint activity visibility, search and investigation. Its technical overview describes an evidence-oriented workflow in which analysts examine recorded behavior, connect related observations and use queries to investigate questions beyond the alert that started the case.

Endpoint detection and responseResearch reviewed

What you are evaluating

Carbon Black is a Broadcom division. Cloud Enterprise EDR and the separate Carbon Black EDR deployment are distinct offerings; endpoint prevention and other cloud modules need explicit package verification.

A useful evaluation context

An evaluation fits existing Carbon Black Cloud users or teams prioritizing endpoint evidence search and investigation workflows.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Endpoint activity records provide evidence for examining behavior observed on supported devices during an investigation.
  • Search functions let analysts query recorded activity to investigate a specific host or behavior pattern.
  • Investigation workflows connect activity observations so analysts can explain relationships and follow evidence across a case.

Where it fits in the work

  1. Confirm the selected product configuration supplies the records needed for a defined endpoint investigation.
  2. Collect an authorized benign baseline on a training host and document uncertainty in the evidence.
  3. Record approval before any response and verify that normal lab operation is restored afterward.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

A learner starts with a known benign process event on a lab host and writes an investigation question about related activity. They use the available search functions to find evidence and note what the query cannot establish.

Evidence to look for

Preserve the query, time window and matching event references. The final explanation should identify both observed relationships and gaps, without treating absence of a result as proof that an event never occurred.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Does the proposal cover Cloud Enterprise EDR or the separately deployed Carbon Black EDR product?
  2. Which prevention, response and retention functions belong to other modules rather than this entitlement?
  3. Which supported operating systems and export formats are documented for the exact release under evaluation?

Names you may encounter: VMware Carbon Black Cloud. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.