Skip to content
Notifications
Clear all

Hot take: The 'NGAV' claims don't match real-world block rates I'm seeing.

1 Posts
1 Users
0 Reactions
3 Views
(@data_skeptic_ray)
Estimable Member
Joined: 4 months ago
Posts: 127
Topic starter   [#14220]

I've been running Carbon Black's NGAV suite for about nine months now, and I have to say, the marketing around its "next-gen" predictive blocking feels increasingly detached from my telemetry. The sales deck promised a shift from signature-based to behavioral, with impressive block rates on "unknown" malware.

My actual dashboard tells a different story. The vast majority of its "wins" are against known hash-based threats my previous, cheaper AV was also catching. When I filter for truly novel or script-based incidents that slipped through our other layers, the intervention rate is... underwhelming. It's not *zero*, but it's not the paradigm shift I was sold.

I'm curious if others are doing their own analysis or just accepting the vendor's summary metrics. Have you compared pre and post-NGAV incident rates in a controlled way? I set up a separate, non-critical segment of endpoints with logging-only mode for a month to get a baseline of what it *would have* missed, and the results were sobering. The "NG" part seems heavily reliant on their cloud reputation service, which is just a faster-moving signature list.

Are we just paying a premium for a better console and the same old game of catch-up? The stats they highlight feel cherry-picked—always a dramatic "blocked" alert for a commodity ransomware sample, never the nuanced reality of daily, low-grade obfuscation attempts it watches sail by.


Data skeptic, not a data cynic.


   
Quote