Talk to us
by BroadcomTechBag Intel Page

Carbon Black App Control

Your ATMs and plant PCs run software nobody can patch. They should run nothing else — Carbon Black App Control lets only approved software run on ATMs, POS terminals, old servers and air-gapped machines, enforced by an agent and managed from a server you host — in India if you choose.

Only approved software runsServer hosted on your own siteBuilt for ATMs, POS and old OS

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom publishes no App Control price; partners quote after scoping the estate
Quote
Default
At High enforcement only approved files run; lower levels prompt or simply log
Deny unknown
Hosting
You run the App Control Server and its SQL database, on-premises or in a cloud account
Self-hosted
India
Policy, inventory and events stay on the server you place, such as an Indian data centre
Your site

Quick answer

Carbon Black App Control is Broadcom’s allowlisting product: under a Positive Security Model, only software you have approved may run. Agents for Windows (desktop, server and embedded), macOS and Linux report to an App Control Server you host, on-premises or in AWS, Azure or Google Cloud. Broadcom aims it at ATMs, point-of-sale terminals, end-of-life systems and air-gapped networks. It is quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Carbon Black App Control — Broadcom’s allowlisting product for servers, desktops and fixed devices. The rest:

Quick facts

30-second orientation
Product
Application allowlisting that lets only approved files execute on servers, desktops and fixed devices
Maker
Broadcom Inc., Palo Alto; Carbon Black sits in the Enterprise Security Group under Jason Rolleston
Model
A Positive Security Model: trusted software runs, and everything else is blocked, prompted or logged
Status
App Control Server 8.11 line; Broadcom advises 8.11.4 or later for a known backlog fix
Price
Not published; Broadcom sells through partners and prints neither a price nor a licence unit
Agents
Windows desktop, Windows Server, Windows embedded, macOS and Linux
Server
Runs on Windows Server with Microsoft SQL Server and IIS, in your data centre or a public cloud
Use cases
ATMs and POS, end-of-life operating systems, critical servers, air-gapped systems, software inventory
India
The server is yours to place; Broadcom lists offices in Bangalore, Hyderabad and Pune
In India via
TechBag — scoping, quote in INR with GST, and the move from Visibility to High enforcement
Part 02 · Learn

Understand application allowlisting before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is application allowlisting?

Instead of hunting for bad files, a machine runs only the software you approved; anything unknown is stopped by default.

Scan-and-hope on old machines vs approved-only execution — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionScan-and-hope on old machinesCarbon Black App Control
What decides if a file runsA scanner’s verdict on whether it looks badWhether you have approved it
An unpatchable old OSAn open door until it is replacedLocked to the software already approved
A new unknown executableRuns until a signature catches upBlocked, prompted or logged, by level
Config file changesFound later, if anyone looksLogged, or blocked, by an integrity rule
Rolling out controlBlock first and field the ticketsVisibility, then Low, Medium and High
What it is NOT—An EDR, an antivirus engine, or a SaaS console

The cheapest test is a Visibility-mode pilot on one group of fixed-function machines: see what High would block before you switch it on.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where policy and inventory live

Server

App Control Server and console

A Windows Server host running IIS holds the web console, with Microsoft SQL Server storing every file, approval and event the agents report back to it.

02
Where execution is decided

Agent

Windows, macOS and Linux agents

An agent on each machine checks every file that tries to run against the policy it holds, so enforcement keeps working when the link to the server drops.

03
How software earns the right to run

Trust

Approvals and software rules

Files are approved by IT and cloud-driven trust, trusted publishers, custom rules or external sources, rather than by a static list someone edits by hand.

04
How it joins the wider stack

Connectors

Carbon Black Cloud and EDR links

A connector links file and computer pages to the Carbon Black Cloud console when its sensor is installed; on-premises Carbon Black EDR can integrate as well.

One server you host, an agent on every machine — files run only after publishers, rules or IT have approved them.

Part 03 · Evaluate

Nine capabilities. Allow, guard, prove.

Carbon Black App Control decides what may run by approval, not by spotting what looks malicious.

Allow
Positive model

Only approved files run

At High (Block Unapproved) enforcement, a file with no approval simply does not execute, whatever a malware scanner thinks of it.

Allow
Enforcement levels

Five steps to lockdown

High blocks, Medium prompts the user, Low monitors, and two None settings give pure visibility or switch enforcement off.

Allow
Trusted sources

Approvals that keep up

Trusted publishers, IT and cloud-driven trust, custom rules and external sources approve new software without hand-kept lists.

Guard
File integrity

Watch files that never run

File Integrity Control rules log every access to chosen configuration or data paths and, if you choose, block the attempt.

Guard
Memory rules

Shield running processes

Memory Rules stop other processes from reading or altering a protected process, closing a route that allowlisting alone leaves.

Guard
Device control

Rein in removable media

Policy can block or limit some removable devices on Windows and Mac machines, set alongside each policy’s enforcement level.

Prove
Inventory

Know every file in use

Agents report the software found on each machine, giving the real-time picture Broadcom positions for software asset management.

Prove
PCI DSS 4.0

A mapping for assessors

Broadcom publishes a document mapping App Control to PCI DSS 4.0, useful when card terminals and payment servers are in scope.

Prove
Visibility mode

Rehearse before you block

In Visibility, block and ban settings are recorded but not enforced, so you can see what High would stop before you turn it on.

See it, don’t just read it

Watch Carbon Black App Control in action

A 2024 console demo of approvals, policy and blocking, and a 2021 technical overview of the server, agents and rules.

Carbon Black (official channel)·Demo, September 2024

Carbon Black App Control Demo

A walk through the console: approving software, setting policy and watching what agents block.

Carbon Black (official channel)·Demo, October 2021

Carbon Black App Control Technical Overview Demo

An older technical tour of the server, agents and rules; product names on screen predate Broadcom.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Carbon Black App Control

Old, fixed machines cannot be patched forever. App Control lets only approved software run on them.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Locks down machines that can no longer be patched

Broadcom aims App Control at systems that cannot simply be upgraded: end-of-life operating systems running proprietary software, critical servers, and fixed-function ATMs and POS terminals. With only approved files allowed to run, a missing patch matters far less.

02

A graded path from watching to blocking

The rollout does not have to start with blocking. Visibility records what policy would stop without stopping it, Low monitors unapproved files, Medium asks the user, and High blocks. Teams move groups of machines up a level at a time, once their approvals cover real use.

03

Everything stays on infrastructure you control

The App Control Server, its SQL Server database and every event live where you install them: an Indian data centre, a closed network, or your own AWS, Azure or Google Cloud account. Broadcom names air-gapped systems as a target use case, so no cloud dependency is built in.

04

Where it stops

It is not an EDR or antivirus engine; detection and hunting come from Carbon Black Cloud or another agent. You run and patch the server and SQL database yourself. Busy desktops need steady approvals, Broadcom prints no price, and the newest official demo is from 2024.

The idea
Only approved software runs
The residency
Your server, your Indian site
The price
Quote-only through partners
Proof, not promises

The numbers behind the platform

5 levels
of enforcement, from High (Block Unapproved) down to None (Disabled)
— Vendor
3 OS families
carry agents: Windows (desktop, server, embedded), macOS and Linux
— Vendor
3 public clouds
Broadcom names for hosting it — AWS, Azure and Google Cloud — besides on-premises
— Vendor
PCI DSS 4.0
the payment-card standard Broadcom maps App Control controls against in a published document
— Vendor
2023
the year Broadcom closed its VMware deal, which brought Carbon Black with it
— Filing
2024
the year Westcon-Comstor, Broadcom’s sole APAC security distributor, added India
— Distributor

What your Carbon Black App Control rollout looks like

Week 1Model

List the machines to lock down

Pick the ATMs, POS terminals, old servers and plant PCs first, and note each one’s OS, its owner and how often it changes.

Week 2Decide

Stand up the server

Install App Control Server with SQL Server and IIS in your Indian data centre or cloud account, then size the database.

Weeks 3–6Pilot

Run in Visibility

Deploy agents in Visibility, let the inventory fill, and approve software by publisher and rule rather than file by file.

Month 2Prove

Step up the enforcement

Move one group at a time from Low to Medium to High, watching blocked-file events and the user prompts each step brings.

Month 3Commit

Add rules and evidence

Turn on file integrity, memory and device rules where needed, and file the PCI DSS 4.0 mapping with your assessor.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
41+ reviews*
82% would recommend
Lockdown strength4.6
Legacy and fixed devices4.5
Console and reporting3.8
Effort to tune policy3.5
Value for money3.7
5★
45%
4★
35%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our branch ATMs still run an old Windows build. At High enforcement, a USB-borne tool simply would not start on them.”
Head of Channel Security
BFSI
Manufacturing
“We spent six weeks in Visibility before blocking anything. The event list showed exactly which plant tools still lacked approvals.”
OT Security Lead
Manufacturing
Retail
“The PCI DSS 4.0 mapping shortened our assessor’s questions about the POS fleet considerably.”
Compliance Manager
Retail
IT Services
“Trusted publishers did most of the work. Our in-house tools needed custom rules, and those took longer than planned.”
Endpoint Engineer
IT Services
Pharma
“File integrity rules on the lab system’s config folder caught a vendor engineer’s change before it went live.”
IT Manager
Pharma
Healthcare
“Strong once tuned, but the SQL database needs a real DBA, and developer laptops were too dynamic for High.”
Infrastructure Architect
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application control market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Application Control Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Carbon Black App ControlThis page

Quote-only through Broadcom partners; self-hosted server.

Grid 02 · The architecture

Legacy Reach × Control Depth

The grid nobody publishes — how far down old, fixed and offline systems a product reaches vs how much it controls beyond running a file.

Deep but modern-onlyLockdown specialistsPrivilege-first toolsLegacy-reach basics
Carbon Black App ControlThis page

EOL OS, ATMs and air-gapped sites; integrity, memory and device rules.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Carbon Black App Control vs the application-control field

Against Trellix Application Control, Airlock Digital, ThreatLocker, Microsoft App Control for Business and BeyondTrust EPM — on deployment, platforms, enforcement, legacy reach, price and India.

DimensionCarbon Black App ControlTrellix Application ControlAirlock DigitalThreatLocker AllowlistingMicrosoft App Control for BusinessBeyondTrust Endpoint Privilege Management
What it isAllowlisting serverDynamic whitelistingAllowlisting specialistDeny-by-default agentBuilt into WindowsPrivilege tool + control
DeploymentYour server, any siteePO On-PremOn-prem, cloud, hostedCloud portalNative, via IntuneSaaS for Windows, Mac
Platforms coveredWindows, macOS, LinuxServers to POSXP SP3 to macOS 26Windows, macOS, LinuxWindows onlyWindows, macOS, Linux
How enforcement worksFive graded levelsObserve, then lockDeny, with OTP escapeLearn, then denyEnforce or auditAllow, block, contain
Trust sourcesPublishers, cloud, rulesTrusted channelsSigning and publishersPeer data, fast repliesInstaller tags, ISGTemplates, exceptions
Beyond executablesFiles, memory, devicesChange ControlScripts and librariesRingfencing, storageDLLs, drivers, scriptsAdmin rights removed
Legacy and fixed devicesATMs, POS, EOL OSKiosks and POSBack to Windows XPNot publishedWindows 10 1903+Desktops first
Air-gapped sitesNamed use caseWorks disconnectedOn-prem serverCloud-managedLocal once appliedAsk BeyondTrust
Pricing modelPartner quotePartner quoteDirect or partnerCustom, MSP-ledIn the Windows licenceQuote, per endpoint
Published entry priceNot publishedNot publishedNot publishedNot publishedNo separate feeNot published
IntegrationsCB Cloud, CB EDRePO single consoleSIEM outputsOne agent, modulesIntune and DefenderPAM platform
Audit evidencePCI DSS 4.0 mappingChange trackingSOC 2, ISO, IRAPExpiring approvalsIntune reportsLeast-privilege proof
India data locationYour server in IndiaYour ePO serverOn-prem keeps it hereRegion not publishedTenant decidesAsk about region
Best fitATMs, POS, old serversTrellix ePO estatesStrict allowlistingMSP-run estatesIntune-managed fleetsRemoving local admin
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Carbon Black App Control if…

  • ✓ATMs, POS terminals or plant systems run old operating systems you cannot upgrade, and only known software should ever start on them
  • ✓The management server must sit inside your own data centre or an air-gapped network rather than in a vendor’s cloud
  • ✓You want a graded rollout — Visibility, then Low, Medium and High — plus integrity, memory and device rules on the same agent

Compare alternatives if…

  • ✓Your fleet is modern Windows managed by Intune — Microsoft App Control for Business comes with the Windows licence
  • ✓You want allowlisting run from a vendor cloud portal, often by an MSP — ThreatLocker is built for that
  • ✓Removing local admin rights is the real goal — BeyondTrust EPM leads with privilege, not lockdown

Do not expect…

  • ✓A Broadcom-hosted console: the App Control Server and its SQL Server database are yours to run and patch
  • ✓Threat hunting or EDR telemetry from this agent alone; that comes from Carbon Black Cloud or another sensor
  • ✓Busy developer or office desktops to sit at High untouched; they need a steady stream of new approvals

Carbon Black App Control is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do unlocked legacy machines cost you?

Drag the sliders (machines to lock down; engineer-hour cost). Estimates model engineering time spent on emergency patching, clean-up and chasing unknown software on fixed-function and legacy machines at an assumed 1.5 hours per machine a year, with 70% of it removed by approved-only execution. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual legacy-machine upkeep cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Broadcom sells Carbon Black App Control through partners and prints neither a price nor a licence unit. The quote depends on the machines in scope and the support term; the server, SQL Server and Windows licences you run it on are separate costs. TechBag scopes the estate first, then quotes in INR with GST.

Pilot scope

Best for one ATM, POS or plant fleet

  • Partner quote; no public price
  • Start in Visibility before any blocking
  • Server and SQL Server on your own site

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Estate-wide

Best for regulated, multi-site estates

  • Quoted after a scoping call
  • Integrity, memory and device rules
  • Carbon Black Cloud connector optional

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Scope

Which machines are fixed-function or end-of-life, and which are busy desktops that may never suit High enforcement?

2
Operating systems

Does every target OS, including embedded Windows builds, appear in the current agent support list from Broadcom?

3
Server

Who will run the App Control Server, its SQL Server database and IIS, and on which version of each?

4
Hosting

Will the server sit in your Indian data centre, a closed network, or your own AWS, Azure or Google Cloud account?

5
Trust model

Which publishers, rules and sources will approve software, and who approves the in-house tools nobody signs?

6
Rollout

How long will each group stay in Visibility and Low before it moves up, and who handles the user prompts?

7
Detection

What gives you EDR and hunting alongside lockdown — Carbon Black Cloud, on-prem Carbon Black EDR, or another sensor?

8
Licence

What unit does the partner quote count, and does it cover support and upgrades? Ask for INR with GST itemised.

FAQ

Questions buyers ask

It is Broadcom’s application allowlisting product. Under a Positive Security Model, an agent on each machine lets a file run only once it is approved, by publisher, rule, cloud trust or IT. Everything else is blocked, prompted or logged, by the enforcement level in that machine’s policy.

Ready to evaluate Carbon Black App Control?

Model the machines you need to lock down first, or let a TechBag advisor scope a pilot that runs one fleet in Visibility before anything is blocked.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.