Carbon Black EDR is an incident response and threat hunting solution designed for security operations center (SOC) teams with offline environments or on-premises requirements. Carbon Black EDR continuously records and stores comprehensive endpoint activity data, so that security professionals can hunt threats in real time and visualize the complete attack kill chain. It leverages the VMware Carbon Black Cloud's aggregated threat intelligence, which is applied to the endpoint activity system of record for evidence and detection of these identified threats and patterns of behavior.

Use cases:

  • Threat hunting
  • Incident response
  • Breach preparation
  • Alert validation and triage
  • Root cause analysis
  • Forensic investigations
  • Host isolation


  1. Faster end-to-end response and remediation
  2. Accelerated IR and threat hunting with continuous endpoint visibility
  3. Rapid identification of attacker activities and root cause
  4. Secure remote access to infected endpoints for in-depth investigation
  5. Better protection from future attacks through automated hunting
  6. Unlimited retention and scale for the largest installations
  7. Reduced IT headaches from reimaging and helpdesk tickets