Talk to us
by BroadcomTechBag Intel Page

Carbon Black Cloud Endpoint

Your laptops work from homes, branches and client sites. An investigation shouldn’t need the device on your desk — Carbon Black Cloud Endpoint puts next-gen antivirus, behavioural EDR and threat hunting on one sensor, with a cloud console where analysts trace attacks and fix laptops remotely.

One sensor from antivirus to huntingNo Indian data region listedQuote-only through partners

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom prints no Carbon Black price; partners quote after scoping the estate
Quote
Retention
Alerts with their linked events, then everything else; extended retention is sold apart
180 / 30 days
Analysts
A distributor reports Broadcom as a Niche Player in Gartner’s 2026 Endpoint Protection MQ
Niche (reported)
India
Documented regions are outside India; get the storage location in writing
No region listed

Quick answer

Carbon Black Cloud Endpoint is Broadcom’s cloud-run endpoint security: one sensor on Windows, macOS and Linux reports to one console. Endpoint Foundations brings NGAV and behavioural EDR; Enterprise EDR adds hunting on unfiltered data and a Live Response shell. Alerts are kept 180 days, other events 30. It is quote-only, and no Indian data region is listed, so ask where telemetry will sit before you sign. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Carbon Black Cloud Endpoint — Foundations through Enterprise EDR. The rest of Broadcom:

Quick facts

30-second orientation
Product
Cloud-delivered NGAV, behavioural EDR and threat hunting on one sensor and console
Maker
Broadcom Inc., Palo Alto; CEO Hock Tan; run by the Enterprise Security Group beside Symantec
Editions
Endpoint Foundations, Standard and Advanced, with Enterprise EDR as the hunting module
Price
Quote-only; Broadcom publishes no list price and sells through partners
Platforms
Windows 7–11, Windows Server 2008 R2–2022, macOS 10.12+, RHEL, Ubuntu, SUSE, Debian, Amazon Linux
Retention
Alerts and linked events 180 days; other events and watchlist hits 30; more is an add-on
Response
Live Response remote shell, network quarantine, and Live Query SQL across endpoints
Add-ons
Live Query, Host-based Firewall and Managed Detection and Response on the same sensor
India
No Indian data region is listed; Westcon-Comstor has distributed it in India since 2024
In India via
TechBag — edition fit, data-region questions, quote in INR with GST
Part 02 · Learn

Understand cloud EDR before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is cloud EPP with EDR?

One sensor blocks attacks on the device and records what happens, and a cloud console lets analysts investigate it.

Signature antivirus and hand-run forensics vs one cloud sensor — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSignature antivirus, manual forensicsCarbon Black Cloud Endpoint
What gets recordedOnly files the scanner flaggedUnfiltered process, binary and logon data
How an attack is tracedLog exports stitched together by handAn attack chain you expand stage by stage
Fixing a remote laptopShip it back or remote-desktop inA Live Response shell from the console
Agents on each deviceAV, USB control and firewall apartOne sensor; modules switched on later
Proving controls to auditScripts and screenshots per quarterScheduled Live Query reports
What it is NOT—An on-premises console, or a public price list

The cheapest test is a monitor-only pilot: a mixed group of Windows, macOS and Linux machines, one Live Response drill, and a clear look at what the sensor flags.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What runs on each device

Sensor

Carbon Black Cloud sensor

One lightweight sensor on Windows, macOS and Linux endpoints and Windows servers collects activity continuously and enforces whatever prevention policy the console assigns.

02
Where policy and alerts live

Console

Carbon Black Cloud console

A single SaaS console holds prevention policies, alerts, attack chains and investigations. Buyers who need an on-premises server are looking at Carbon Black EDR, a separate product.

03
What you switch on

Modules

Foundations, Enterprise EDR and add-ons

Endpoint Foundations brings NGAV and behavioural EDR; Enterprise EDR adds unfiltered hunting data and Live Response; Live Query, firewall and MDR switch on without new agents.

04
How long evidence lasts

Data

Event store and retention

Alerts and the events tied to them stay 180 days; other events and watchlist hits stay 30 days. Broadcom sells longer retention as a separate add-on for investigations.

One sensor, one cloud console — prevention, hunting and remote response switched on as modules, not new agents.

Part 03 · Evaluate

Nine capabilities. Prevent, detect, respond.

Carbon Black Cloud Endpoint blocks attacks on the device and keeps the evidence for analysts in one cloud console.

Prevent
NGAV

Layered next-gen antivirus

File reputation, heuristics, machine learning and behavioural models examine activity on the device and block attacks before they spread.

Prevent
Ransomware

Event streams, not signatures

Prevention watches the chains of events that precede a ransomware outbreak, aiming to stop unknown and fileless variants as well as known ones.

Prevent
Device control

USB rules on Windows

Allow or block named USB devices on Windows endpoints and set read, write and execute rights for removable storage from the console.

Detect
Unfiltered data

Search what never alerted

Enterprise EDR searches unfiltered process, binary and authentication records sent continuously to the cloud, not only the events that fired alerts.

Detect
Detections

Rules, feeds and watchlists

Built-in and custom detection rules work beside Broadcom and third-party threat-intelligence feeds, with watchlists that flag matches automatically.

Detect
Attack chain

Step through each stage

An interactive attack-chain view expands stage by stage, so an analyst traces a detection back to its root cause instead of rebuilding it by hand.

Respond
Live Response

A shell on the infected host

A secure remote session lets a responder pull or push files, kill processes and take a memory dump, wherever the laptop happens to be.

Respond
Quarantine

Cut a device off the network

Isolate a compromised endpoint from the network in one action, then keep investigating it through the same console and sensor.

Respond
Live Query

SQL across every endpoint

A separately licensed module: ad hoc or scheduled SQL queries report patch levels, user privileges and disk encryption across the estate.

See it, don’t just read it

Watch Carbon Black Cloud Endpoint in action

Threat Tracer for Enterprise EDR, where NGAV ends and Enterprise EDR begins, and a technical tour of the Endpoint Standard console.

Symantec (official, Broadcom)·Feature launch, July 2025

Introducing Threat Tracer for Carbon Black Cloud Enterprise EDR

Broadcom’s July 2025 introduction of Threat Tracer, a newer addition to the Enterprise EDR module.

Carbon Black (official)·Explainer, January 2024

Carbon Black NGAV vs. Enterprise EDR

Where the prevention edition stops and the hunting module starts; watch it before choosing an edition.

Carbon Black (official)·Demo, January 2023

Carbon Black Endpoint Standard - Technical Overview

A 2023 console walkthrough, recorded before the Broadcom acquisition of VMware closed that November.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Carbon Black Cloud Endpoint

Antivirus reports what it blocked. Enterprise EDR keeps the activity that never raised an alert.

Here’s what genuinely sets it apart — and exactly where it stops.

01

From antivirus to hunting on one sensor

Carbon Black Cloud starts as NGAV with behavioural EDR in Endpoint Foundations. Enterprise EDR, Live Query, the Host-based Firewall and MDR are switched on later for the same sensor, without new agents or servers. An estate can replace its antivirus first and add threat hunting when it has the people to use it.

02

Hunting on the data that did not alert

Enterprise EDR keeps unfiltered process, binary and authentication records, so a hunt can find activity that never set off an alert. Identity intelligence adds logons, logoffs, account changes and privilege escalation to the same timeline, and the attack-chain view walks each stage back to its root cause.

03

Fix a laptop without collecting it

Live Response opens a secure shell to a host on any network: pull evidence, push a fix, kill a process or dump memory. Quarantine cuts a device off while you work. With Live Query, the same console can run SQL across endpoints on a schedule to check patch levels and disk encryption.

04

Where it stops

Broadcom prints no price, and no Indian data region is listed, so residency is a question for the contract. Ordinary events last 30 days unless you buy more retention. It is cloud-only; the on-premises product is Carbon Black EDR. CBX, the XDR announced in March 2026, had not shipped when this page was written.

The idea
One sensor from antivirus to hunting
The residency
No Indian region listed; ask first
The price
Quote-only, through partners
Proof, not promises

The numbers behind the platform

180 days
how long alerts, and the events linked to them, stay in the Carbon Black Cloud console
— Vendor
30 days
how long events with no alert and watchlist hits are kept, unless retention is extended
— Vendor
3 OS families
Windows, macOS and Linux, covered by the same sensor and the same console
— Vendor
4 actions
Live Response tasks Broadcom names: pull files, push files, kill processes, dump memory
— Vendor
427%
ROI reported by a Forrester TEI study that Broadcom commissioned; treat it as a vendor figure
— Commissioned
2024
the year India joined Westcon-Comstor’s sole APAC distribution of Carbon Black
— Distributor

What your Carbon Black Cloud Endpoint rollout looks like

Week 1Model

Settle the data question first

Ask Broadcom in writing which region will hold your telemetry, and check that answer against your DPDP and sector rules.

Week 2Decide

Pick the edition by team size

Foundations if you only need prevention and alerts; Enterprise EDR if analysts will hunt and run Live Response sessions.

Week 3Pilot

Pilot beside the old antivirus

Put the sensor on a mixed group of Windows, macOS and Linux machines in a monitor-only policy and review what it flags.

Month 2Prove

Tighten policy, run a drill

Move the pilot to blocking policies, then quarantine a test host and open a Live Response session against it.

Month 3Commit

Roll out and set retention

Deploy to the estate, retire the old agent, and decide whether 30 days of ordinary events is enough or retention is needed.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
46+ reviews*
82% would recommend
Threat hunting depth4.5
Prevention4.2
Remote response4.4
Console usability3.9
Value for money3.7
5★
42%
4★
38%
3★
14%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We hunted for a suspicious PowerShell pattern across 2,000 laptops and found three hosts that had never raised an alert.”
Threat Hunter
BFSI
Pharmaceuticals
“Live Response let us pull a memory dump from a sales laptop in Jaipur without asking anyone to courier it to Mumbai.”
Incident Response Lead
Pharmaceuticals
Manufacturing
“We started on Foundations to retire our old antivirus, then turned on Enterprise EDR a year later with no reinstall.”
IT Security Manager
Manufacturing
Insurance
“Scheduled Live Query reports on disk encryption now go to audit every Monday instead of a spreadsheet chase.”
Compliance Analyst
Insurance
IT Services
“Thirty days of plain events is short for our investigations. Price the retention add-on before you compare quotes.”
SOC Manager
IT Services
Healthcare
“Our legal team asked where telemetry is stored and the first answer was not India. Get that in writing early.”
Head of Information Security
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint detection and response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint Detection and Response Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Carbon Black Cloud EndpointThis page

Quote-only through partners; no list price.

Grid 02 · The architecture

Data Location × Hunting Depth

The grid nobody publishes — where the console and telemetry can live, India included, vs how deep hunting and response go.

Cloud-only huntersHunt with data choiceCloud prevention firstFlexible basics
Carbon Black Cloud EndpointThis page

Cloud-only, no Indian region listed; unfiltered hunting and Live Response.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Carbon Black Cloud Endpoint vs the EDR field

Against CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X with XDR and Bitdefender GravityZone EDR — on console, price, retention, hunting, recovery and India.

DimensionCarbon Black Cloud EndpointCrowdStrike Falcon Insight XDRSentinelOne Singularity EndpointMicrosoft Defender for EndpointSophos Intercept X Advanced with XDRBitdefender GravityZone EDR
What it isCloud NGAV + EDREDR/XDR in FalconAutonomous EPP + EDRPlan 1 or Plan 2Intercept X + XDREDR in Enterprise tier
Deployment and consoleSaaS console onlyCloud console onlySaaS; on-prem announcedDefender portalSophos Central onlyCloud or on-prem
OS coverageWin, Mac, LinuxWin, Mac, LinuxWin, Mac, Linux, K8sFive platformsWin, Mac, LinuxWin, Mac, Linux, VMs
Pricing modelQuote via partnersPer device, yearlyPer endpoint, partnersPer user or in E3/E5Quote, per userPer device, by package
Published entry priceNot published$184.99/device/yr$179.99/endpoint/yr$3 and $5.20/user/mo~$48/user, reportedEDR tier unlisted
Included vs add-onHunting is a moduleSIEM, identity inHunting, MDR by tierEDR needs Plan 2MDR and storage extraMany paid add-ons
Telemetry retention180 alerts / 30 eventsDefault unpublished14 or 90 days180 days in Plan 290-day data lake3 days raw, 90 alerts
Hunting and investigationUnfiltered + identityForensic timelineStorylineAdvanced huntingData lake queriesCross-endpoint search
Response and recoveryLive Response shellReal Time ResponseRollback on WindowsAuto-remediation, P2CryptoGuard revertRansomware Mitigation
IntegrationsSplunk, ServiceNow, IBM260+ marketplace appsAPI-first marketplaceSentinel, Intune, EntraRMM and PSA linksMany RMM plug-ins
India data regionNone listedPlanned, undatedMumbai regionIndia locationMumbai, liveNo India; on-prem
Support and MDRMDR module, partnersFalcon CompleteWayfinder MDRDefender ExpertsSophos MDR, 24/7Bitdefender MDR
Lock-in and exitCloud data, 30 days30-day refund, FlexAnnual, via partnersMicrosoft estateData deleted at exitAuto-renews; 50 min
Best fitSOCs that hunt and fixOne sensor, many modulesLean team, Mumbai dataMicrosoft 365 estatesSophos-run mid-marketPrice-led, on-prem
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Carbon Black Cloud Endpoint if…

  • ✓Your analysts will hunt in unfiltered process and logon data rather than wait for alerts to come to them
  • ✓You want to replace antivirus first and add hunting, Live Query or a host firewall later on the same sensor
  • ✓Remote responders need a shell to pull evidence and fix laptops on any network, without shipping devices back

Compare alternatives if…

  • ✓Telemetry must be stored in India — SentinelOne and Sophos document Mumbai regions today
  • ✓You want a list price before talking to sales — CrowdStrike, SentinelOne and Microsoft publish theirs
  • ✓You need automatic file rollback after encryption — SentinelOne, Sophos and Bitdefender document it

Do not expect…

  • ✓An Indian Carbon Black Cloud region, or more than 30 days of ordinary events without the retention add-on
  • ✓A self-hosted Carbon Black Cloud console — on-premises means the separate Carbon Black EDR
  • ✓CBX as a product you can buy today — Broadcom announced it in March 2026

Carbon Black Cloud Endpoint is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does hands-on endpoint response cost you?

Drag the sliders (endpoints in scope; analyst-hour cost). Estimates model analyst and IT time spent investigating alerts and recovering devices by hand at an assumed 1.5 hours per endpoint a year, with 70% of it removed by remote investigation and response from one console. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual investigation and recovery cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Broadcom lists no price for Carbon Black Cloud Endpoint and sells it through partners, with Westcon-Comstor distributing in India since 2024. Endpoint Foundations covers NGAV and behavioural EDR; Enterprise EDR adds hunting and Live Response; Live Query, the Host-based Firewall, MDR and extended retention are add-ons. TechBag scopes the edition and modules, then quotes in INR with GST.

Endpoint Foundations

Best for replacing legacy antivirus

  • NGAV with behavioural EDR on one sensor
  • USB device control and attack-chain views
  • Quote-only through partners

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Enterprise EDR

Best for SOC teams that hunt

  • Unfiltered process, binary and logon data
  • Live Response shell and quarantine
  • Quote-only; retention add-on extra

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Data region

Which Carbon Black Cloud region will hold our telemetry, and will Broadcom put that in the contract?

2
Edition

Do we need Enterprise EDR hunting and Live Response, or does Foundations cover what our team will actually use?

3
Retention

Are 30 days of ordinary events and 180 days of alerts enough for our investigations and audit cycle?

4
Platforms

Is every OS in scope supported — Windows 7–11, Server 2008 R2–2022, macOS 10.12+ and our Linux builds?

5
Add-ons

Which of Live Query, the Host-based Firewall and MDR do we want now, and how is each priced in the quote?

6
Recovery

How will we restore encrypted files, given that the product pages describe no file-rollback mechanism?

7
Integrations

Will alerts reach our SIEM and ticketing — Splunk, ServiceNow or IBM — through the built-in links?

8
Licence

What unit is the quote counted in, what is the term, and is it itemised in INR with GST?

FAQ

Questions buyers ask

It is Broadcom’s cloud-delivered endpoint protection. One sensor on Windows, macOS and Linux reports to one SaaS console. Endpoint Foundations brings next-gen antivirus with behavioural EDR, and Enterprise EDR adds threat hunting on unfiltered data plus Live Response. It came to Broadcom with VMware in November 2023.

Ready to evaluate Carbon Black Cloud Endpoint?

Settle the data-region question and the edition first, or let a TechBag advisor scope a pilot beside your current antivirus.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.