This is another big day for Carbon Black. Earlier, we announced CB ThreatHunter, our newest offering on the CB Predictive Security Cloud (PSC), which delivers powerful threat hunting and incident response (IR) capabilities to the platform.

The announcement of CB ThreatHunter, which will be the fourth service delivered on the PSC in 2018, comes just a year after we first announced the platform itself.

Introducing Advanced Threat Hunting to the PSC

Inspired by CB Response, our EDR market pioneer with more than 2,000 active customers­, CB ThreatHunter is a brand new product, built from the ground up on the PSC, offering security teams advanced threat hunting and IR capabilities.

This new advanced threat hunting tool is delivered through the PSC, Carbon Black’s powerful endpoint protection platform that consolidates prevention, detection, response, threat hunting and managed services into a single platform with a single agent and single console. This enables security & IT teams to simplify their endpoint stack by consolidating multiple critical capabilities onto a single agent and single cloud-based console.

Threat Hunting Powered by Continuous Collection of Unfiltered Data

Most endpoint detection and response (EDR) and IR tools on the market collect only a limited set of historical data. As a result, SOCs and IR teams struggle to get their hands on the information they need to investigate, proactively hunt and remediate.

CB ThreatHunter solves this problem by continuously collecting unfiltered data, giving security teams all the information they need to: proactively hunt threats, uncover suspicious behavior, disrupt active attacks, repair damage quickly and address gaps in defenses. Investigations that often take days or weeks can be completed in just minutes with CB ThreatHunter.

More Powerful Search Fields: CB ThreatHunter equips security teams with the ability to flexibly hunt threats, even if an endpoint is offline. With this level of visibility, researchers can see what happened at every stage of an attack with intuitive attack-chain visualizations, and uncover advanced threats, while minimizing attacker dwell time. This insight provides immediate answers with comprehensive behavioral context to stop attacks as quickly as possible.

Enhanced Threat Intel Matching: CB ThreatHunter’s sophisticated detection combines custom and cloud-native threat intel, automated watchlists and integrations with the rest of the security stack to efficiently scale hunting across the enterprise. This advanced level of detection allows security teams to proactively explore environments for abnormal activity, leverage cloud-native threat intelligence and automate repeat hunts. Additionally, the PSC’s platform extensibility allows developers to create custom watchlists to power real-time detection and correlate data across the security stack.

Elastic Cloud Scalability: CB ThreatHunter is natively built on the PSC, allowing security teams to rapidly deploy and scale the solution across their enterprise without investing in (or maintaining) on-premise infrastructure. By eliminating these costs and processes, CB ThreatHunter enables teams to simplify their operations and focus their energy on hunting and responding to threats.

The Inspiration Behind the Announcement

Over the last decade, we have seen the evolution of the threat hunting and incident response markets. SOC teams continue to become more sophisticated, requiring more scalable solutions to uncover indicators of compromise and reduce dwell time. We’ve also seen this evolution from our IR partners, who have expanded their capabilities to help organizations take back control of their environments after a breach is discovered.

All of this has driven us to evolve as well. While we have a history of developing some of the most sophisticated on-premise solutions in the endpoint security market, it has continued to become more clear that the answer to the increasingly complex world of endpoint security is through the collection and analysis of unfiltered endpoint data.

At Carbon Black we’ve been dedicated to collecting and analyzing more endpoint data than anyone else because we believe the only way to get a long-term sustainable advantage over the adversary is through data. Real cybersecurity requires the best data and we believe the PSC offers the most comprehensive data available today.



CB ThreatHunter will be generally available in November 2018.

Editor’s note: CB Predictive Security Cloud is now VMware Carbon Black Cloud.