Your laptops work from homes, branches and client sites. An investigation shouldn’t need the device on your desk — Carbon Black Cloud Endpoint puts next-gen antivirus, behavioural EDR and threat hunting on one sensor, with a cloud console where analysts trace attacks and fix laptops remotely.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Carbon Black Cloud Endpoint — Foundations through Enterprise EDR. The rest of Broadcom:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
One sensor blocks attacks on the device and records what happens, and a cloud console lets analysts investigate it.
What consolidation actually replaces, dimension by dimension.
| Dimension | Signature antivirus, manual forensics | Carbon Black Cloud Endpoint |
|---|---|---|
| What gets recorded | Only files the scanner flagged | Unfiltered process, binary and logon data |
| How an attack is traced | Log exports stitched together by hand | An attack chain you expand stage by stage |
| Fixing a remote laptop | Ship it back or remote-desktop in | A Live Response shell from the console |
| Agents on each device | AV, USB control and firewall apart | One sensor; modules switched on later |
| Proving controls to audit | Scripts and screenshots per quarter | Scheduled Live Query reports |
| What it is NOT | — | An on-premises console, or a public price list |
The cheapest test is a monitor-only pilot: a mixed group of Windows, macOS and Linux machines, one Live Response drill, and a clear look at what the sensor flags.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
One lightweight sensor on Windows, macOS and Linux endpoints and Windows servers collects activity continuously and enforces whatever prevention policy the console assigns.
A single SaaS console holds prevention policies, alerts, attack chains and investigations. Buyers who need an on-premises server are looking at Carbon Black EDR, a separate product.
Endpoint Foundations brings NGAV and behavioural EDR; Enterprise EDR adds unfiltered hunting data and Live Response; Live Query, firewall and MDR switch on without new agents.
Alerts and the events tied to them stay 180 days; other events and watchlist hits stay 30 days. Broadcom sells longer retention as a separate add-on for investigations.
One sensor, one cloud console — prevention, hunting and remote response switched on as modules, not new agents.
Carbon Black Cloud Endpoint blocks attacks on the device and keeps the evidence for analysts in one cloud console.
File reputation, heuristics, machine learning and behavioural models examine activity on the device and block attacks before they spread.
Prevention watches the chains of events that precede a ransomware outbreak, aiming to stop unknown and fileless variants as well as known ones.
Allow or block named USB devices on Windows endpoints and set read, write and execute rights for removable storage from the console.
Enterprise EDR searches unfiltered process, binary and authentication records sent continuously to the cloud, not only the events that fired alerts.
Built-in and custom detection rules work beside Broadcom and third-party threat-intelligence feeds, with watchlists that flag matches automatically.
An interactive attack-chain view expands stage by stage, so an analyst traces a detection back to its root cause instead of rebuilding it by hand.
A secure remote session lets a responder pull or push files, kill processes and take a memory dump, wherever the laptop happens to be.
Isolate a compromised endpoint from the network in one action, then keep investigating it through the same console and sensor.
A separately licensed module: ad hoc or scheduled SQL queries report patch levels, user privileges and disk encryption across the estate.
Threat Tracer for Enterprise EDR, where NGAV ends and Enterprise EDR begins, and a technical tour of the Endpoint Standard console.
Broadcom’s July 2025 introduction of Threat Tracer, a newer addition to the Enterprise EDR module.
Where the prevention edition stops and the hunting module starts; watch it before choosing an edition.
A 2023 console walkthrough, recorded before the Broadcom acquisition of VMware closed that November.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Carbon Black Cloud starts as NGAV with behavioural EDR in Endpoint Foundations. Enterprise EDR, Live Query, the Host-based Firewall and MDR are switched on later for the same sensor, without new agents or servers. An estate can replace its antivirus first and add threat hunting when it has the people to use it.
Enterprise EDR keeps unfiltered process, binary and authentication records, so a hunt can find activity that never set off an alert. Identity intelligence adds logons, logoffs, account changes and privilege escalation to the same timeline, and the attack-chain view walks each stage back to its root cause.
Live Response opens a secure shell to a host on any network: pull evidence, push a fix, kill a process or dump memory. Quarantine cuts a device off while you work. With Live Query, the same console can run SQL across endpoints on a schedule to check patch levels and disk encryption.
Broadcom prints no price, and no Indian data region is listed, so residency is a question for the contract. Ordinary events last 30 days unless you buy more retention. It is cloud-only; the on-premises product is Carbon Black EDR. CBX, the XDR announced in March 2026, had not shipped when this page was written.
Ask Broadcom in writing which region will hold your telemetry, and check that answer against your DPDP and sector rules.
Foundations if you only need prevention and alerts; Enterprise EDR if analysts will hunt and run Live Response sessions.
Put the sensor on a mixed group of Windows, macOS and Linux machines in a monitor-only policy and review what it flags.
Move the pilot to blocking policies, then quarantine a test host and open a Live Response session against it.
Deploy to the estate, retire the old agent, and decide whether 30 days of ordinary events is enough or retention is needed.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We hunted for a suspicious PowerShell pattern across 2,000 laptops and found three hosts that had never raised an alert.”
“Live Response let us pull a memory dump from a sales laptop in Jaipur without asking anyone to courier it to Mumbai.”
“We started on Foundations to retire our old antivirus, then turned on Enterprise EDR a year later with no reinstall.”
“Scheduled Live Query reports on disk encryption now go to audit every Monday instead of a spreadsheet chase.”
“Thirty days of plain events is short for our investigations. Price the retention add-on before you compare quotes.”
“Our legal team asked where telemetry is stored and the first answer was not India. Get that in writing early.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only through partners; no list price.
The grid nobody publishes — where the console and telemetry can live, India included, vs how deep hunting and response go.
Cloud-only, no Indian region listed; unfiltered hunting and Live Response.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X with XDR and Bitdefender GravityZone EDR — on console, price, retention, hunting, recovery and India.
| Dimension | Carbon Black Cloud Endpoint | CrowdStrike Falcon Insight XDR | SentinelOne Singularity Endpoint | Microsoft Defender for Endpoint | Sophos Intercept X Advanced with XDR | Bitdefender GravityZone EDR |
|---|---|---|---|---|---|---|
| What it is | Cloud NGAV + EDR | EDR/XDR in Falcon | Autonomous EPP + EDR | Plan 1 or Plan 2 | Intercept X + XDR | EDR in Enterprise tier |
| Deployment and console | SaaS console only | Cloud console only | SaaS; on-prem announced | Defender portal | Sophos Central only | Cloud or on-prem |
| OS coverage | Win, Mac, Linux | Win, Mac, Linux | Win, Mac, Linux, K8s | Five platforms | Win, Mac, Linux | Win, Mac, Linux, VMs |
| Pricing model | Quote via partners | Per device, yearly | Per endpoint, partners | Per user or in E3/E5 | Quote, per user | Per device, by package |
| Published entry price | Not published | $184.99/device/yr | $179.99/endpoint/yr | $3 and $5.20/user/mo | ~$48/user, reported | EDR tier unlisted |
| Included vs add-on | Hunting is a module | SIEM, identity in | Hunting, MDR by tier | EDR needs Plan 2 | MDR and storage extra | Many paid add-ons |
| Telemetry retention | 180 alerts / 30 events | Default unpublished | 14 or 90 days | 180 days in Plan 2 | 90-day data lake | 3 days raw, 90 alerts |
| Hunting and investigation | Unfiltered + identity | Forensic timeline | Storyline | Advanced hunting | Data lake queries | Cross-endpoint search |
| Response and recovery | Live Response shell | Real Time Response | Rollback on Windows | Auto-remediation, P2 | CryptoGuard revert | Ransomware Mitigation |
| Integrations | Splunk, ServiceNow, IBM | 260+ marketplace apps | API-first marketplace | Sentinel, Intune, Entra | RMM and PSA links | Many RMM plug-ins |
| India data region | None listed | Planned, undated | Mumbai region | India location | Mumbai, live | No India; on-prem |
| Support and MDR | MDR module, partners | Falcon Complete | Wayfinder MDR | Defender Experts | Sophos MDR, 24/7 | Bitdefender MDR |
| Lock-in and exit | Cloud data, 30 days | 30-day refund, Flex | Annual, via partners | Microsoft estate | Data deleted at exit | Auto-renews; 50 min |
| Best fit | SOCs that hunt and fix | One sensor, many modules | Lean team, Mumbai data | Microsoft 365 estates | Sophos-run mid-market | Price-led, on-prem |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Carbon Black Cloud Endpoint is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints in scope; analyst-hour cost). Estimates model analyst and IT time spent investigating alerts and recovering devices by hand at an assumed 1.5 hours per endpoint a year, with 70% of it removed by remote investigation and response from one console. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Broadcom lists no price for Carbon Black Cloud Endpoint and sells it through partners, with Westcon-Comstor distributing in India since 2024. Endpoint Foundations covers NGAV and behavioural EDR; Enterprise EDR adds hunting and Live Response; Live Query, the Host-based Firewall, MDR and extended retention are add-ons. TechBag scopes the edition and modules, then quotes in INR with GST.
Best for replacing legacy antivirus
Best for a broader rollout
Best for SOC teams that hunt
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which Carbon Black Cloud region will hold our telemetry, and will Broadcom put that in the contract?
Do we need Enterprise EDR hunting and Live Response, or does Foundations cover what our team will actually use?
Are 30 days of ordinary events and 180 days of alerts enough for our investigations and audit cycle?
Is every OS in scope supported — Windows 7–11, Server 2008 R2–2022, macOS 10.12+ and our Linux builds?
Which of Live Query, the Host-based Firewall and MDR do we want now, and how is each priced in the quote?
How will we restore encrypted files, given that the product pages describe no file-rollback mechanism?
Will alerts reach our SIEM and ticketing — Splunk, ServiceNow or IBM — through the built-in links?
What unit is the quote counted in, what is the term, and is it itemised in INR with GST?
Settle the data-region question and the edition first, or let a TechBag advisor scope a pilot beside your current antivirus.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.