VMware Carbon Black Cloud for Security Operations
by VMware LLC
Streamline security operations workflows with Carbon Black Cloud endpoint context and response actions directly in ServiceNow SecOps
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2025-11-02 | 10 | - |
| 150 days of no change | ||
| 2025-06-04 | 9 | +1 |
About
The VMware Carbon Black Cloud for Security Operations app automates ticket creation and orchestrates response actions to streamline incident management for security teams.
By integrating Carbon Black Cloud alerts and response actions directly into ServiceNow SecOps, security teams can triage alerts, automatically create security incident tickets, and respond to incidents more quickly without having to manually correlate data between systems. This application delivers full access to endpoint response actions to enable analysts to seamlessly gather context and orchestrate remediation actions all from a single console.
Users should install this app along with the VMware Carbon Black Cloud app to access the full capabilities of this integration, including ingestion of Carbon Black Cloud inventory data to the ServiceNow Configuration Management Database (CMDB) module.
VMware Carbon Black Cloud:
* The VMware Carbon Black Cloud is a cloud-native endpoint, workload, and container protection platform that combines the intelligent system hardening and behavioral prevention needed to keep emerging threats at bay, using a single, easy-to-use console. By analyzing more than 1 trillion security events per day, VMware Carbon Black Cloud proactively uncovers attackers’ behavior patterns and empowers defenders to detect and stop emerging attacks.
* https://www.vmware.com/products/carbon-black-cloud-endpoint.html
Key Features
Dashboard
* Dashboard for viewing metrics related to alerts, assets, incidents, security incidents and vulnerabilities.
Carbon Black Cloud Alert Ingestion
* Customizable alert ingestion from Carbon Black Cloud to ServiceNow via the Alerts API or Data Forwarder.
* Multi-tenancy: domain separation to configure ingestion and isolation of Alerts data from multiple Carbon Black Cloud organizations.
Carbon Black Cloud Asset Inventory Ingestion
* Creation of ServiceNow Configuration Items based on Carbon Black Cloud endpoints and workloads.
* Synchronization of asset context from Carbon Black Cloud to the ServiceNow Configuration Management Database (CMDB).
* Attachment of Carbon Black Cloud Assets to ServiceNow SecOps and VR ticket types.
Streamlined ServiceNow SecOps Security Incident Creation and Lifecycle Management
* Automated and manual ServiceNow SecOps Security Incident ticket creation based on Carbon Black Cloud Alerts.
* Customizable field mappings between Carbon Black Cloud Alerts and ServiceNow SecOps Security Incident tickets.
* Automated, bi-directional updates between Carbon Black Cloud and ServiceNow for alerts, updates, and dismissal.
SOAR Capabilities
* Built-in context and remediation actions for Security Orchestration, Automation, and Response (SOAR) workflows. Examples include:
* Quarantine Asset
* Ban Process Hash
* Update Asset Policy
* Get Process Metadata
* Kill Process
* MITRE ATT&CK framework visualization of TTP’s from Carbon Black Cloud alerts in ServiceNow Security incident tickets.
* Automated logging and record keeping of incident response actions in SecOps Security Incident ticket work notes.