Your ATMs and plant PCs run software nobody can patch. They should run nothing else — Carbon Black App Control lets only approved software run on ATMs, POS terminals, old servers and air-gapped machines, enforced by an agent and managed from a server you host — in India if you choose.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Carbon Black App Control — Broadcom’s allowlisting product for servers, desktops and fixed devices. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Instead of hunting for bad files, a machine runs only the software you approved; anything unknown is stopped by default.
What consolidation actually replaces, dimension by dimension.
| Dimension | Scan-and-hope on old machines | Carbon Black App Control |
|---|---|---|
| What decides if a file runs | A scanner’s verdict on whether it looks bad | Whether you have approved it |
| An unpatchable old OS | An open door until it is replaced | Locked to the software already approved |
| A new unknown executable | Runs until a signature catches up | Blocked, prompted or logged, by level |
| Config file changes | Found later, if anyone looks | Logged, or blocked, by an integrity rule |
| Rolling out control | Block first and field the tickets | Visibility, then Low, Medium and High |
| What it is NOT | — | An EDR, an antivirus engine, or a SaaS console |
The cheapest test is a Visibility-mode pilot on one group of fixed-function machines: see what High would block before you switch it on.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A Windows Server host running IIS holds the web console, with Microsoft SQL Server storing every file, approval and event the agents report back to it.
An agent on each machine checks every file that tries to run against the policy it holds, so enforcement keeps working when the link to the server drops.
Files are approved by IT and cloud-driven trust, trusted publishers, custom rules or external sources, rather than by a static list someone edits by hand.
A connector links file and computer pages to the Carbon Black Cloud console when its sensor is installed; on-premises Carbon Black EDR can integrate as well.
One server you host, an agent on every machine — files run only after publishers, rules or IT have approved them.
Carbon Black App Control decides what may run by approval, not by spotting what looks malicious.
At High (Block Unapproved) enforcement, a file with no approval simply does not execute, whatever a malware scanner thinks of it.
High blocks, Medium prompts the user, Low monitors, and two None settings give pure visibility or switch enforcement off.
Trusted publishers, IT and cloud-driven trust, custom rules and external sources approve new software without hand-kept lists.
File Integrity Control rules log every access to chosen configuration or data paths and, if you choose, block the attempt.
Memory Rules stop other processes from reading or altering a protected process, closing a route that allowlisting alone leaves.
Policy can block or limit some removable devices on Windows and Mac machines, set alongside each policy’s enforcement level.
Agents report the software found on each machine, giving the real-time picture Broadcom positions for software asset management.
Broadcom publishes a document mapping App Control to PCI DSS 4.0, useful when card terminals and payment servers are in scope.
In Visibility, block and ban settings are recorded but not enforced, so you can see what High would stop before you turn it on.
A 2024 console demo of approvals, policy and blocking, and a 2021 technical overview of the server, agents and rules.
A walk through the console: approving software, setting policy and watching what agents block.
An older technical tour of the server, agents and rules; product names on screen predate Broadcom.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Broadcom aims App Control at systems that cannot simply be upgraded: end-of-life operating systems running proprietary software, critical servers, and fixed-function ATMs and POS terminals. With only approved files allowed to run, a missing patch matters far less.
The rollout does not have to start with blocking. Visibility records what policy would stop without stopping it, Low monitors unapproved files, Medium asks the user, and High blocks. Teams move groups of machines up a level at a time, once their approvals cover real use.
The App Control Server, its SQL Server database and every event live where you install them: an Indian data centre, a closed network, or your own AWS, Azure or Google Cloud account. Broadcom names air-gapped systems as a target use case, so no cloud dependency is built in.
It is not an EDR or antivirus engine; detection and hunting come from Carbon Black Cloud or another agent. You run and patch the server and SQL database yourself. Busy desktops need steady approvals, Broadcom prints no price, and the newest official demo is from 2024.
Pick the ATMs, POS terminals, old servers and plant PCs first, and note each one’s OS, its owner and how often it changes.
Install App Control Server with SQL Server and IIS in your Indian data centre or cloud account, then size the database.
Deploy agents in Visibility, let the inventory fill, and approve software by publisher and rule rather than file by file.
Move one group at a time from Low to Medium to High, watching blocked-file events and the user prompts each step brings.
Turn on file integrity, memory and device rules where needed, and file the PCI DSS 4.0 mapping with your assessor.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our branch ATMs still run an old Windows build. At High enforcement, a USB-borne tool simply would not start on them.”
“We spent six weeks in Visibility before blocking anything. The event list showed exactly which plant tools still lacked approvals.”
“The PCI DSS 4.0 mapping shortened our assessor’s questions about the POS fleet considerably.”
“Trusted publishers did most of the work. Our in-house tools needed custom rules, and those took longer than planned.”
“File integrity rules on the lab system’s config folder caught a vendor engineer’s change before it went live.”
“Strong once tuned, but the SQL database needs a real DBA, and developer laptops were too dynamic for High.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application control market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only through Broadcom partners; self-hosted server.
The grid nobody publishes — how far down old, fixed and offline systems a product reaches vs how much it controls beyond running a file.
EOL OS, ATMs and air-gapped sites; integrity, memory and device rules.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Trellix Application Control, Airlock Digital, ThreatLocker, Microsoft App Control for Business and BeyondTrust EPM — on deployment, platforms, enforcement, legacy reach, price and India.
| Dimension | Carbon Black App Control | Trellix Application Control | Airlock Digital | ThreatLocker Allowlisting | Microsoft App Control for Business | BeyondTrust Endpoint Privilege Management |
|---|---|---|---|---|---|---|
| What it is | Allowlisting server | Dynamic whitelisting | Allowlisting specialist | Deny-by-default agent | Built into Windows | Privilege tool + control |
| Deployment | Your server, any site | ePO On-Prem | On-prem, cloud, hosted | Cloud portal | Native, via Intune | SaaS for Windows, Mac |
| Platforms covered | Windows, macOS, Linux | Servers to POS | XP SP3 to macOS 26 | Windows, macOS, Linux | Windows only | Windows, macOS, Linux |
| How enforcement works | Five graded levels | Observe, then lock | Deny, with OTP escape | Learn, then deny | Enforce or audit | Allow, block, contain |
| Trust sources | Publishers, cloud, rules | Trusted channels | Signing and publishers | Peer data, fast replies | Installer tags, ISG | Templates, exceptions |
| Beyond executables | Files, memory, devices | Change Control | Scripts and libraries | Ringfencing, storage | DLLs, drivers, scripts | Admin rights removed |
| Legacy and fixed devices | ATMs, POS, EOL OS | Kiosks and POS | Back to Windows XP | Not published | Windows 10 1903+ | Desktops first |
| Air-gapped sites | Named use case | Works disconnected | On-prem server | Cloud-managed | Local once applied | Ask BeyondTrust |
| Pricing model | Partner quote | Partner quote | Direct or partner | Custom, MSP-led | In the Windows licence | Quote, per endpoint |
| Published entry price | Not published | Not published | Not published | Not published | No separate fee | Not published |
| Integrations | CB Cloud, CB EDR | ePO single console | SIEM outputs | One agent, modules | Intune and Defender | PAM platform |
| Audit evidence | PCI DSS 4.0 mapping | Change tracking | SOC 2, ISO, IRAP | Expiring approvals | Intune reports | Least-privilege proof |
| India data location | Your server in India | Your ePO server | On-prem keeps it here | Region not published | Tenant decides | Ask about region |
| Best fit | ATMs, POS, old servers | Trellix ePO estates | Strict allowlisting | MSP-run estates | Intune-managed fleets | Removing local admin |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Carbon Black App Control is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (machines to lock down; engineer-hour cost). Estimates model engineering time spent on emergency patching, clean-up and chasing unknown software on fixed-function and legacy machines at an assumed 1.5 hours per machine a year, with 70% of it removed by approved-only execution. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Broadcom sells Carbon Black App Control through partners and prints neither a price nor a licence unit. The quote depends on the machines in scope and the support term; the server, SQL Server and Windows licences you run it on are separate costs. TechBag scopes the estate first, then quotes in INR with GST.
Best for one ATM, POS or plant fleet
Best for a broader rollout
Best for regulated, multi-site estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which machines are fixed-function or end-of-life, and which are busy desktops that may never suit High enforcement?
Does every target OS, including embedded Windows builds, appear in the current agent support list from Broadcom?
Who will run the App Control Server, its SQL Server database and IIS, and on which version of each?
Will the server sit in your Indian data centre, a closed network, or your own AWS, Azure or Google Cloud account?
Which publishers, rules and sources will approve software, and who approves the in-house tools nobody signs?
How long will each group stay in Visibility and Low before it moves up, and who handles the user prompts?
What gives you EDR and hunting alongside lockdown — Carbon Black Cloud, on-prem Carbon Black EDR, or another sensor?
What unit does the partner quote count, and does it cover support and upgrades? Ask for INR with GST itemised.
Model the machines you need to lock down first, or let a TechBag advisor scope a pilot that runs one fleet in Visibility before anything is blocked.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.