Detect and Respond to Advanced Attacks at Scale

Threat hunting and incident response (IR) solution delivering continuous visibility into hybrid deployments for top security operations centers (SOC) and IR teams.

Continuous Visibility

Investigations that typically take days or weeks can be completed in just minutes. Carbon Black EDR collects and visualizes comprehensive information about endpoint events, giving security professionals greater visibility into their environments.


  • Access the complete activity record of every endpoint, even if it’s offline.
  • See what happened at every stage of an attack with intuitive attack chain visualizations.
  • Uncover advanced threats and minimize attacker dwell time.

Proactive Threat Hunting

Carbon Black EDR’s sophisticated detection combines custom and cloud-delivered threat intel, automated watchlists, and integrations with the rest of your security stack to efficiently scale your hunt across the enterprise.


  • Fast search, zoom, and visualization of process trees and timelines to pinpoint threats.
  • Consolidate threat intelligence for your environment to automatically detect suspicious behavior.
  • Correlate network, endpoint, and SIEM data through open APIs and out-of-the-box integrations.

Threat Hunting and IR are now available on the VMware Carbon Black Cloud

Enterprise EDR is the latest addition to the VMware Carbon Black Cloud. It delivers advanced threat hunting and incident response capabilities to the same single agent that powers our breakthrough preventing and industry-leading detection and response.

Respond Immediately

An attacker can compromise your environment in an hour or less. Carbon Black EDR gives you the power to respond and remediate rapidly, containing threats and repairing damage quickly.