A shared PC in a branch office runs an unknown installer. Reimaging it shouldn’t be the only fix — OpenText Core Endpoint Protection, formerly Webroot Business Endpoint Protection, takes file verdicts from the cloud, journals what unknown files do and rolls their changes back — run by you or your MSP from one console.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Core Endpoint Protection — the endpoint agent, with Core EDR and Core MDR as paid add-ons. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A small agent asks the cloud for a verdict on each file instead of storing signatures locally.
What consolidation actually replaces, dimension by dimension.
| Dimension | Signature antivirus, PC by PC | OpenText Core Endpoint Protection |
|---|---|---|
| Threat updates | Daily signature downloads to every PC | Verdicts from the cloud, no definition files |
| An unknown file runs | One chance to allow it or block it | Journaled until the cloud rules on it |
| After an infection | Reimage the machine, restore from backup | Local changes rolled back automatically |
| Running 20 client sites | Twenty consoles or a visit to each | One multi-site console linked to your RMM |
| Investigating a hit | Guesswork from an alert name | Process tree, isolation, Core EDR if added |
| What it is NOT | — | Linux cover, a published price, or a 24/7 team without Core MDR |
The cheapest test is the free trial: put the agent on ten PCs, retire the old antivirus there, and practise isolating one from the console.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A small agent on each Windows or Mac endpoint asks the cloud for a verdict instead of holding a signature database; OpenText says agent updates usually take about three seconds.
Machine learning in OpenText’s cloud does the intensive malware analysis, drawing on BrightCloud threat intelligence, so verdicts change in real time without definition downloads.
One web console holds devices, policy templates and remote agent commands; the Global Site Manager view lets an MSP run many customer sites, and a REST API feeds other tools.
Core EDR switches on in the same agent with no redeployment, adding SIEM correlation, SOAR playbooks and CVE checks; Core MDR puts a 24/7 co-managed team on top.
A small agent on each PC, verdicts from OpenText’s cloud — and one multi-site console an MSP can run for every customer.
OpenText Core Endpoint Protection blocks threats with cloud verdicts and undoes what an unknown file changed.
Real-time machine learning in OpenText’s cloud classifies files, so there are no signature files to push and the agent stays small.
Behaviour, core-system, web-threat, identity, evasion and offline shields each watch a different route an attack can take in.
Evasion Shield catches file-based, fileless and obfuscated scripts, and Script Shield halts malicious PowerShell, JavaScript and VBScript.
A file the cloud cannot yet classify may run, but the agent monitors and journals each change it makes until a verdict comes back.
If a journaled file is ruled a threat, the changes it made to local drives are rolled back to their state before the infection.
OpenText’s datasheet says monitoring, journaling and containment carry on when a laptop is offline, through a dedicated offline shield.
Device isolation fences an infected machine off the network to stop the spread, while keeping the link the console needs to manage it.
Process tree visualisation traces where each process came from and what it started, which OpenText says can help with cyber-insurance forms.
Core EDR brings a built-in SIEM, SOAR playbooks and CVE-based vulnerability checks to the same agent, with no new deployment scripts.
An MSP-focused explainer, a technical deep dive and a healthcare customer story, all from the official Webroot channel OpenText now owns, recorded in 2021 and 2022 before the product took the OpenText name.
How the agent and console serve MSPs, filmed in 2021 when the product was still sold under the Webroot name.
A 48-minute walk through the agent, console and policies, recorded in 2021 before the OpenText rename.
A US healthcare firm on running the agent day to day; OpenText still quotes its IT director on today’s product page.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most agents get one chance to block a file. OpenText lets an unknown file run under watch: the agent journals every change it makes, and if the cloud later rules it malicious, those changes to local drives are reversed. That suits small offices, where reimaging a PC costs a working day.
The cloud console runs many sites from one login, with policy templates and remote agent commands. OpenText lists 40+ third-party RMM and automation integrations and a REST API, and its community hosts integration forums for ConnectWise Automate and Manage, Kaseya VSA and N-able.
Core EDR is added to an existing deployment without redeploying or changing scripts, and brings SIEM correlation, SOAR playbooks and CVE-based checks. Core MDR adds a 24/7 team on a co-managed model with 500+ integrations, so the in-house IT team keeps full sight of alerts.
No price is published, and the online cart sells only in the US. No Linux agent or Indian data region is documented, and OpenText cites no analyst ranking for it. OpenText classes its SMB and consumer security line as non-core and says it is divesting non-core units, so ask about the roadmap.
List Windows PCs, servers and Macs per site, flag any Linux machines, and decide whether to buy direct or via an MSP.
Open the 30-day trial for a pilot group, deploy by MSI or Group Policy, and remove the old antivirus as each PC joins.
Check how journaled changes and rollbacks show in the console, then practise isolating and releasing a lab device.
Weigh Core EDR’s playbooks and Core MDR’s 24/7 team against the staff you have, then ask for one itemised quote.
Push the agent to every site, apply policy templates, connect your RMM or PSA, and schedule monthly reports.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We look after thirty small clients from one console. Policy templates mean a new clinic is covered the day it signs.”
“An unknown installer ran on a sales laptop. Once it was flagged, its file changes were undone and we skipped the reimage.”
“Our older billing PCs no longer stall during scans, which was the complaint that started our search for a new tool.”
“We isolated one infected workstation remotely, then used the process tree to see which download had started it all.”
“Ask where telemetry is stored before you sign. Our auditor wanted an answer on DPDP and it took weeks to get one.”
“Two Ubuntu servers needed a different product because no Linux agent is offered, so budget for a second licence.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per seat, mostly through MSPs; the online cart is US-only.
The grid nobody publishes — how well an MSP can run the product across many customers vs how deep its detection, investigation and managed response go.
40+ integrations and a multi-site console; EDR and MDR are add-ons.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Bitdefender GravityZone and ESET PROTECT — on platforms, price, rollback, response, MSP fit and India.
| Dimension | OpenText Core Endpoint Protection | SentinelOne Singularity Endpoint | CrowdStrike Falcon | Microsoft Defender for Endpoint | Bitdefender GravityZone | ESET PROTECT |
|---|---|---|---|---|---|---|
| What it is | Cloud AV for SMBs, MSPs | Autonomous EPP + EDR | Falcon bundles | EPP + EDR in Defender | Tiered GravityZone | Tiered PROTECT |
| Deployment and console | Cloud console only | SaaS console only | Cloud only | Defender portal | Cloud or on-prem | Cloud or your server |
| Platforms covered | Windows and macOS | Win, Mac, Linux | Win, Mac, Linux | Five platforms | Win, Mac, Linux | Win, Mac, Linux, Android |
| Pricing model | Per seat, quoted | Per endpoint, partners | Per device, yearly | Per user or bundled | Per device, yearly | Per device, yearly |
| Published entry price | Not published | $179.99/endpoint/yr | $59.99/device/year | $3/user/month | $57/device/year | $42.20/device/year |
| Included vs add-on | EDR and MDR extra | MDR, mobile extra | EDR from Enterprise | EDR needs Plan 2 | Full EDR in Enterprise | XDR only in Elite |
| Sizing and minimums | Trial: any device count | List for 5–100 | Breaks at 500+ | Business: 300 users | Promo, then renewal | 5-pack; Elite 25 |
| Ransomware recovery | Journal and rollback | One-click rollback | No file rollback | No agent rollback | Ransomware Mitigation | Ransomware Remediation |
| Detection and response | Isolation; EDR add-on | Storyline EDR | Insight XDR | Plan 2 hunting | Enterprise EDR | ESET Inspect |
| Managed SOC option | Core MDR, 24/7 | Wayfinder MDR | Falcon Complete | Defender Experts | Bitdefender MDR | ESET MDR |
| Integrations and MSP fit | 40+ tools, multi-site | Multi-tenant SaaS | Flight Control tenants | Lighthouse, ≤2,500 users | RMM and PSA plug-ins | RMM plug-ins |
| India data region | None documented | Mumbai region | Announced, not live | Not verified | On-prem console option | Self-hosted server |
| Lock-in and exit | Cloud console only | SaaS only | Cloud-only platform | Microsoft estate | Self-host option | Cloud or on-prem exit |
| Best fit | MSP-run small offices | Lean teams, rollback | Teams that will hunt | Microsoft 365 shops | Price-led mixed fleets | Light agent, list prices |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Core Endpoint Protection is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints protected; IT-hour cost). Estimates model IT time spent cleaning up infections, reimaging PCs and chasing definition updates at an assumed 1.5 hours per endpoint a year, with 70% of it removed by cloud verdicts, rollback and remote isolation. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. OpenText shows no price for Core Endpoint Protection, its online cart sells only to US buyers, and no rupee price exists. It is an annual per-seat subscription, usually bought through an MSP, with Core EDR and Core MDR priced on top. The 30-day trial covers unlimited endpoints with no card. TechBag sizes the Windows and Mac estate first, then gets the quote itemised in INR with GST.
Best for small offices and MSP-run estates
Best for a broader rollout
Best when someone must investigate or watch 24/7
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are all endpoints Windows or macOS? No Linux agent is documented, so plan other cover for Linux servers.
Will you buy direct or through an MSP? The online cart is US-only, so Indian buyers need a partner quote.
Has the pilot shown how journaled changes are rolled back, and on which operating systems that applies?
Do you need Core EDR’s SIEM and SOAR, or are isolation and process trees enough for your team?
Who watches alerts out of hours? If nobody does, price Core MDR’s 24/7 co-managed service alongside.
Is your RMM or PSA among the 40+ integrations, and does the REST API cover the reports you need?
Where are console data and telemetry stored? Get it in writing if DPDP or a sector regulator asks.
Does the quote list seats, term and add-ons in INR with GST, and what does OpenText commit on roadmap?
Count your Windows and Mac devices first, or let a TechBag advisor run the 30-day trial on a pilot group and get one quote in INR covering the agent, EDR and MDR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.