ISEC7 Digital Workplace Blog

Solution Highlight: VMware Carbon Black (2021)

Written by Remi Keusseyan | Sep 14, 2021, 7:30:00 AM

Editor's note, October 2026: This article was first published in September 2021, when Carbon Black belonged to VMware, which had acquired it in 2019. Broadcom completed its acquisition of VMware in November 2023 and has since run Carbon Black together with its Symantec security business. VMware Workspace ONE, mentioned below as an integration, has belonged to the independent company Omnissa since July 2024. Product names, architecture and integrations in this article reflect the VMware era. For an overview of today's endpoint protection categories, read Demystifying Security: EPP, EDR and MTD; ISEC7's current services are described under Endpoint Security.

In a recent blog post, we talked about behavior-based security, a new approach to today's security challenges that aims to stop an attack before it happens.

Traditional antivirus and security solutions focus mainly on prevention and rely on long lists of signatures or hashes to detect known viruses, trojans and other threats. That requires a "sacrificial lamb": someone has to experience an attack first so that everyone else can be protected from it later. Because attacks propagate within milliseconds, zero-day protection is now required, so that an attack does not have to hit someone else first before your systems are protected.

Waiting for an attack and then creating a patch or signature file to protect others afterwards, which is how traditional antivirus software has mostly worked, is a strategy that no longer holds up.

In this article, we look at how VMware, a cloud computing company and leader in virtualization technologies for over two decades, addresses these needs with a next-generation cybersecurity solution: VMware Carbon Black.

How does it work?

Unlike traditional antivirus, VMware Carbon Black takes its own approach to endpoint protection.

The more data, the better

First, VMware Carbon Black collects unfiltered endpoint data. It captures everything happening on the endpoints, such as network connections, file and registry modifications and cross-process events, not only when something suspicious happens. This data goes to the Predictive Security Cloud (PSC), which combines it with big data analytics to give broader visibility of threats, known and unknown, and improve prevention. Think of a surveillance camera that records around the clock instead of only when a motion detector is triggered.

Assess over time

Second, the Predictive Security Cloud uses streaming analytics, a type of analytics VMware developed based on event stream processing (ESP), a technology also used in banking for fraud detection and algorithmic trading. These analytics combine behavioral analytics, machine learning (ML), reputation data and other algorithms to predict unknown threats and assess risk over time. This works against malware as well as non-malware attacks that misuse trusted software for malicious purposes.

Architecture: a single console, platform and agent

The VMware Carbon Black architecture protects servers, desktops and laptops with three main components.

Carbon Black sensors

A single lightweight agent runs on the endpoints. According to VMware, its impact on CPU and disk usage stays below 1%. It continuously collects data and sends it securely to the Carbon Black Cloud for analysis. When a threat is detected, it can take remediation actions, such as deleting files, blocking hashes or isolating the endpoint from the network, whether the endpoint is online or offline.

Carbon Black console

All information is available in a central, cloud-based management console that integrates with SIEM platforms, threat intelligence and network security products.

Carbon Black Cloud

Cloud-based AI and ML services analyze the collected data.

Integration with other products

Carbon Black integrated natively with other products in the VMware ecosystem, such as VMware vSphere for virtual machine provisioning and hosting and VMware Workspace ONE for unified endpoint management.

Carbon Black can also integrate with third-party solutions, such as Mobile Threat Defense (MTD) software for mobile endpoints and Security Information and Event Management (SIEM) software. How these product categories fit together is explained in Cybersecurity Products: What's What.

Cyberattacks are part of daily life, and anyone is a potential target, from consumers to small businesses to Fortune 500 corporations. Ransomware, for example, can bypass traditional antivirus solutions, which is why a more proactive approach, using prediction as the best prevention, is needed. That is the approach VMware took with Carbon Black. A comparable suite from another vendor is described in Solution Highlight: BlackBerry Cyber Suite.

Looking for the right endpoint protection or want to improve your security posture in general? Our endpoint security team will help. Contact us.