Carbon Black vs Acunetix

Last Updated:

Our analysts compared Carbon Black vs Acunetix based on data from our 400+ point analysis of Endpoint Security Software, user reviews and our own crowdsourced data from our free software selection platform.

Product Basics

Formerly known as Bit9 + Carbon Black, Carbon Black Enterprise Protection is an endpoint protection software developed specifically to protect enterprises from advanced security threats.

CBEP is comprised of three components, delivering comprehensive protection for businesses. CB Protection stops malware, ransomware and non-zero day attacks. CB Response is an advanced endpoint detection and response (EDR) tool, built around scalability and attack review. CB Defense is an antivirus combined with an EDR solution, delivered via the cloud.
read more...
Acunetix is an application security testing platform that helps its users safeguard web applications, websites and APIs. It combines dynamic and static scanning technologies and utilizes a separate monitoring agent to detect vulnerabilities.

It offers vulnerability management and compliance reporting functionalities. It is designed for small businesses, pentesters, web professionals and enterprise customers to address vulnerabilities across their critical web assets.
read more...
$36/Endpoint, Annually
Get a free price quote
Tailored to your specific needs
$1,995/User, Annually
Get a free price quote
Tailored to your specific needs
Small 
i
Medium 
i
Large 
i
Small 
i
Medium 
i
Large 
i
Windows
Mac
Linux
Android
Chromebook
Windows
Mac
Linux
Android
Chromebook
Cloud
On-Premise
Mobile
Cloud
On-Premise
Mobile

Product Assistance

Documentation
In Person
Live Online
Videos
Webinars
Documentation
In Person
Live Online
Videos
Webinars
Email
Phone
Chat
FAQ
Forum
Knowledge Base
24/7 Live Support
Email
Phone
Chat
FAQ
Forum
Knowledge Base
24/7 Live Support

Product Insights

  • Enhanced Threat Detection: Carbon Black utilizes advanced behavioral analytics and machine learning to identify and alert on potential threats more accurately, reducing the chances of false positives and ensuring that real threats are promptly addressed.
  • Improved Response Times: With its automated response capabilities, Carbon Black can quickly isolate infected endpoints, preventing the spread of malware or other threats across the network, thereby minimizing potential damage.
  • Comprehensive Visibility: Offering deep visibility into endpoint activities, Carbon Black enables IT teams to track and analyze every process, network connection, and registry key change, facilitating detailed forensic investigations and threat hunting.
  • Scalable Protection: Designed to protect environments of all sizes, from small businesses to large enterprises, Carbon Black scales seamlessly with your organization, ensuring consistent security posture regardless of your growth rate.
  • Cloud-Based Architecture: Leveraging a cloud-native platform, Carbon Black simplifies deployment and management of endpoint security, eliminating the need for additional infrastructure and reducing the overall complexity and cost.
  • Customizable Policies: Carbon Black allows for the creation of tailored security policies that can adapt to the unique needs of different departments or user groups within an organization, ensuring that security measures do not hinder productivity.
  • Reduced IT Workload: By automating routine security tasks and providing a centralized management console, Carbon Black reduces the burden on IT staff, allowing them to focus on strategic initiatives rather than constant firefighting.
  • Regulatory Compliance: Carbon Black helps organizations meet various regulatory requirements by providing comprehensive logging, reporting, and data protection capabilities, ensuring that sensitive information is safeguarded against breaches.
  • Integration Capabilities: With its open API, Carbon Black integrates smoothly with other security tools and systems, enhancing the overall security ecosystem and enabling a more coordinated defense strategy against threats.
  • Proactive Risk Management: By continuously monitoring for and analyzing suspicious behaviors, Carbon Black enables organizations to proactively manage their risk posture, staying one step ahead of potential security breaches.
read more...
  • Vulnerability Scanner: Includes web vulnerability tests in SecDevOps processes to save resources and avoid late patching. Uses a unique scanning algorithm, SmartScan, to quickly find vulnerabilities and save resources during penetration testing due to low false-positive rates. It can be deployed locally on macOS, Microsoft Windows and Linux operating systems. 
  • Manage Security: Discover multiple vulnerabilities, including weak passwords, misconfigurations, exposed databases, XSS, SQL injections and out of the band vulnerabilities. Scan complex multi-level forms and password-protected areas through advanced micro-level technology. 
  • Improved Results: Verifies real vulnerabilities and assesses the severity of issues to provide actionable insights. Eliminates lengthy setups and onboarding times to facilitate quick scanning, preventing network hogging and server overloading. 
  • Enables Automation: Schedule and prioritize full or incremental scans according to traffic load and business needs. Handle identified issues using built-in management functionality or integration with its current tracking systems. Scan new builds with the latest CI tools like Jenkins and import pre-seed crawl data from Burp, Fiddler, Postman, Paros and more. 
  • Seamless Integrations: Track and protect against identified vulnerabilities through integrations with third-party applications. Development teams can streamline collaboration and manage work using issue trackers. Create appropriate rules to protect against attacks targeting vulnerabilities with web application firewall integrations. Offers a Jenkins plugin to discover and track vulnerabilities early on in the software development lifecycle.  
read more...
  • Central Whitelist: CBEP operates with a central database of whitelisted software. Meaning that software is analyzed for threats and then ranked in the program’s database, preventing rogue software from taking over.
  • Continuous Monitoring: Carbon Black employs a “continuous monitoring” technique, meaning it is always watching to ensure threats don’t sneak by. CBEP constantly records threats giving you instant feedback on your current security configuration.
  • Visualization Chains: Scrutinize every angle of an attack with visualization chains, showing how the threat entered, and where it went after that.
  • Installation Diversity: Carbon Black Enterprise Security is built to run on Windows, MacOS, Red Hat Linux and CentOS.
read more...
  • Automated Penetration Testing: Manually identify web application vulnerabilities like cross-site scripting, SQL injections and more before starting a penetration test. Allows vulnerability assessment and management with integration options, including an API for building personal integrations. Follow up with further manual tests using GUI-based and command-line penetration testing tools. 
  • Website Security Scanner: Run scans to probe sites and find application risks. Examine web applications built with Java frameworks like Struts, Spring and Java Server Faces. Scan password-protected pages automatically using the Login Sequence Recorder. Utilizes AcuSensor technology to inspect web application’s source code. Replicates user actions to execute scripts like a browser. Employs black and gray box testing to focus on the entire attack surface. 
  • External Vulnerability Scanner: Scans perimeters for network-layer vulnerabilities and misconfigurations. Provides options to schedule external vulnerability scans at a specific time to run regular scans. Generates technical, regulatory and compliance reports like OWASP top 10, PCI DSS, HIPAA and more. Export vulnerabilities to third-party issue trackers such as GitHub, GitLab, Atlassian JIRA, Bugzilla, Mantis and Microsoft TFS. 
  • Web Application Security: Defends against known and website or web application vulnerabilities that include sites built with hard to scan HTML5 and JavaScript SPAs. Scan website files through custom form authentication or other access controls and session management. Assess and minimize security risks with out-of-the-box vulnerability management tools, including prioritization and historic trends. 
  • AcuSensor Technology: Enables interactive application security testing and works with applications written in PHP, ASP.NET and Java. Provides additional information from the server back end during web application scanning to offer ease of remediation, greater precision and full coverage. It can be installed on staging servers to perform IAST analysis. 
  • AcuMonitor Technology: Increases the scope of vulnerabilities detected by Acunetix scanner and enables out of the band detection. Identifies vulnerabilities like host header attacks, blind XSS, blind server-side XML/SOAP injection, out of the band remote code execution and SQL injection, email header injection, server-side request forgery and XML external entity injection. 
read more...

Product Ranking

#15

among all
Endpoint Security Software

#53

among all
Endpoint Security Software

Find out who the leaders are

User Sentiment Summary

Excellent User Sentiment 201 reviews
Excellent User Sentiment 64 reviews
93%
of users recommend this product

Carbon Black has a 'excellent' User Satisfaction Rating of 93% when considering 201 user reviews from 4 recognized software review sites.

90%
of users recommend this product

Acunetix has a 'excellent' User Satisfaction Rating of 90% when considering 64 user reviews from 2 recognized software review sites.

4.6 (42)
n/a
n/a
4.5 (32)
5.0 (4)
4.5 (32)
4.7 (148)
n/a
4.2 (7)
n/a

Awards

Carbon Black stands above the rest by achieving an ‘Excellent’ rating as a User Favorite.

User Favorite Award

Acunetix stands above the rest by achieving an ‘Excellent’ rating as a User Favorite.

User Favorite Award

Synopsis of User Ratings and Reviews

Management Console: It has an intuitive management console that helps with policy management.
Client Performance: It is lightweight and does not affect client system performance.
Zero-Day Threats: It protects against zero-day threats.
Security Policies: Security policies can be set up across the entire network.
Show more
Automated Vulnerability Detection: Acunetix excels at automatically finding vulnerabilities like SQL injections and cross-site scripting, which are common ways hackers exploit websites.
API Security Testing: Acunetix can automatically test the security of RESTful APIs, including those without a web front end, ensuring comprehensive API protection.
Detailed Reporting and Remediation Guidance: Acunetix provides detailed reports with proof of exploit and clear remediation guidance, enabling developers to understand and fix security issues efficiently.
Integration with Development Workflows: Acunetix integrates with popular CI/CD pipelines and issue tracking systems like Jira and GitHub, streamlining security processes and facilitating DevSecOps practices.
Show more
Reporting: It does not have comprehensive reporting capabilities.
Time-Consuming: The deployment or removal of software is time-consuming.
Updates: Users report that its dashboard and notifications can be slow.
Navigation: It can be difficult to navigate through different options and tools on the console.
Show more
Limited Customization: While Acunetix offers various scan types, users have reported limited control over specific vulnerability checks within those scans, potentially leading to less targeted assessments.
False Positives: Acunetix may occasionally flag vulnerabilities that are not genuine issues, requiring manual verification and potentially slowing down remediation efforts.
Scan Duration: Some users have found Acunetix scans to be time-consuming, particularly for large and complex applications, which could impact development and deployment cycles.
Supplementary Testing Required: Acunetix recommends additional security measures, such as manual testing and network mapping, suggesting its automated scans may not be as comprehensive as some users expect.
Show more

Carbon Black Endpoint protection provides its users with protection against a full spectrum of advanced cyber threats. It captures and stores endpoint activity, which provides comprehensive information of any suspicious activity and allows users to keep their devices safe. Enterprises facing advanced security threats should consider this software suite.

Show more

User reviews from the past year suggest that Acunetix, developed by Invicti, is a well-regarded tool for managing endpoint security, penetration testing, and website security. Users have praised its comprehensive vulnerability scanning capabilities, highlighting its ability to detect a wide range of threats, including SQL injection and cross-site scripting. One user commended Acunetix for its "good OWASP scans and reports and automation," emphasizing its effectiveness in identifying and addressing security risks. Another user lauded its user-friendliness, stating that it "makes me feel a part of the test." However, some users have pointed out limitations. One criticism targets the licensing model, with a user describing it as "the worst I have ever used" due to its inflexibility in reallocating target URLs. Another user cautioned against relying solely on Acunetix, noting that "some vulnerabilities still can't be detected" and recommending manual vulnerability assessments as a supplementary measure. Despite these drawbacks, Acunetix is generally viewed favorably by users, who appreciate its robust features, accuracy, and ease of use. Acunetix appears to be a suitable choice for organizations of all sizes that prioritize web application security. Its comprehensive scanning, automation features, and integration capabilities make it a valuable asset for security professionals and developers alike. However, potential users should carefully consider the licensing model and the need for manual vulnerability assessments to ensure it aligns with their specific requirements and risk tolerance.

Show more

Screenshots

Top Alternatives in Endpoint Security Software


Bitdefender GravityZone

Blackberry Cyber Suite

Carbon Black Cloud

Cisco Secure Endpoint

Cortex XDR

CrowdStrike Falcon

ESET PROTECT MDR

Kaspersky Endpoint Security For Business

Malwarebytes EDR

Microsoft Defender for Endpoint

Sophos Intercept X

Symantec Endpoint Security Complete

Trellix XDR

Trend Micro Vision One

Related Categories

WE DISTILL IT INTO REAL REQUIREMENTS, COMPARISON REPORTS, PRICE GUIDES and more...

Compare products
Comparison Report
Just drag this link to the bookmark bar.
?
Table settings