build 93162979 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 232 | 0 skipped |
Solution · VMware

Carbon Black

The vendor calls it: Carbon Black Cloud vendorName: Carbon Black Cloud

Endpoint detection and response. Watches what a system actually does, rather than comparing files against a list of signatures.

VMware Pinnacle Partner · soultec.ch/partner, verbatim

Topics capabilities · idf weight Security security 2.14 Endpoint Security endpoint-security 3.40
Vendors vendors · idf weight VMware vmware 0.91
04Services
06Posts
02Capabilities
232Corpus

What it is

Carbon Black watches process behaviour on an endpoint and reports what does not fit. A sensor on the machine supplies the events; the analysis runs in the cloud.

The difference from classic antivirus is the question being asked. Not “do I recognise this file”, but “why is this Office document starting PowerShell”.

What it is for

Estates that want not only to stop an incident but to reconstruct it. Much of the value is in the recording: after something happens, you can work out what happened.

That assumes somebody is looking. EDR with nobody assigned to it is a data store.

What changed

Broadcom’s acquisition of VMware moved the product into a different business unit. That changes little about the product in the short term and quite a lot about contracts and who you talk to. Check both before the next renewal.

What we do with it

Draft, unreviewed practiceReview: true

Draft, not yet reviewed. The first week after a rollout is always a tidy-up week: backup agents, monitoring tools and home-grown scripts all look like attackers to an EDR. Exceptions that go in undocumented become a rule set nobody wants to touch two years later.

This paragraph is a draft and nobody at soulTec has confirmed it yet. Everything above it describes the product and is checkable against the vendor.

Posts about it

VMware Security Advisory

Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale.

2024-09-18 · posts/vmware-security-advisory.md · 133 words · 1 min · daniel-stadelmann

Security security 2.14

VMware Security Advisory

VMware has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0012. The issues are rated 7.8 to 9.8 on the CVSS scale.

2024-06-19 · posts/vmware-security-advisory-vmsa-2024-0012.md · 129 words · 1 min · daniel-stadelmann

Security security 2.14

VMware Security Advisory

VMware has disclosed new vulnerabilities, covered by VMware Security Advisory 2022-0030 and 2021-0025. They are rated 7.1 to 7.5 on the CVSS scale.

2022-12-09 · posts/vmware-security-advisory-vmsa-2022-0030.md · 128 words · 1 min · dario-doerflinger

Security security 2.14

VMware Security Advisory

VMware has disclosed new vulnerabilities in VMware Security Advisory 2022-0021. They are rated 4.7 to 9.8 on the CVSS scale.

2022-08-05 · posts/vmware-security-advisory-2022-021.md · 107 words · 1 min · dario-doerflinger

Security security 2.14

Renew the STS Signing Root Certificate in vCenter

I recently had a call from a customer that received multiple alerts about their ESXi Hosts certificate was about to expire.

2025-05-23 · posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter.md · 357 words · 2 min · dario-doerflinger

Virtualization virtualization 1.54 Security security 2.14

Broadcom Download Token

From now on your vCenter or SDDC Manager needs a unique token. Without it, from the end of April 2025, no patches for VMware software will download any more.

2025-04-14 · posts/how-to-broadcom-download-token.md · 176 words · 1 min · daniel-stadelmann

Virtualization virtualization 1.54 Security security 2.14

Who works with it