Two years ago, my team was under pressure to replace our aging endpoint stack. We needed something cloud-native, with strong EDR, and that could tie into our existing VMware infra. Carbon Black (now Broadcom, but let's stick with the name) seemed like the obvious frontrunner.
We pulled the trigger. After 24 months of daily ops, here's my real-world breakdown.
**The Good (What We'd Choose Again For):**
* **Visibility is top-tier.** The queryable telemetry is fantastic for hunting. I've built custom alerts that have caught things our old tool would have missed.
* **The VMware integration** (for us, using vSphere) delivers on its promise. Sensor deployment and management through that pipeline is smooth.
* **Policy granularity** is a win. We can tune policies for different server and workstation groups without breaking a sweat. The "allow/block" lists are more effective than I expected.
**The Not-So-Good (The Trade-offs):**
* **Cost.** It's premium pricing. You need to be using the advanced features (like Live Response) to justify it. The annual bill still makes me wince.
* **Noise floor can be high.** Out of the box, it took us a good 3-4 months of tuning exclusions and adjusting alert thresholds to get the alert volume to a manageable level. Be prepared for that setup investment.
* **The console.** While powerful, it's not the most intuitive. New analysts on the team needed more ramp-up time than with some competitor tools I've tested.
**Side-by-Side Consideration (My Spreadsheet Says...):**
If I were making the decision today, I'd still shortlist Carbon Black, but the field is more crowded. For our use case (heavy VMware shop, need for deep forensics), it still wins on integration and data depth. For a team wanting a faster time-to-value or with a tighter budget, I'd probably look harder at Microsoft Defender for Endpoint or CrowdStrike.
**Final Verdict:**
Yes, we'd likely choose it again, but with clearer eyes on the operational tuning required. It's a powerful engine, but you need to be a dedicated mechanic to get it running just right for your environment. The value is absolutely there if you leverage its full dataset.
— alex
Data > opinions
The tuning period you mentioned is the real hidden cost. You need a dedicated analyst just to manage those exclusions and keep the signal-to-noise ratio sane. Most teams underestimate the ongoing FTE commitment for that.
We've seen similar with other "premium" EDR tools. The initial deployment is just step one. The real work starts when you have to operationalize all that data without drowning in alerts.
Have you automated any of that tuning? We ended up building internal dashboards to track exclusion effectiveness and alert fatigue. It helped, but it's another system to maintain.
garbage in, garbage out
That's a really good point about the hidden FTE cost. We're a smaller shop, and we definitely felt that pinch when we first got the alert volume dialed in. It took a lot of manual review cycles before we had a stable baseline.
What did you use to build those internal dashboards? I've been looking at pulling some of the audit log data into Power BI to visualize policy changes over time, but I'm not sure which API endpoints are best for that.
That 3-4 month tuning period hits home. We saw the same thing. I'm curious, did your noise floor issues ever really settle, or do you still get surprise flare-ups after major Windows updates?
The Live Response cost justification is real, but we've found it's also a training bottleneck. You need people who can use it properly, otherwise you're just paying for a feature that increases risk.
Automate everything.