The purpose of this article is to share the primary differences between SentinelOne vs Cylance vs Carbon Black. All three have a core focus on EDR – endpoint detection and response. Others, like FortiEDR, ESET, and BitDefender have all bolted on EDR to their core products. SentinelOne, Cylance, and Carbon Black were all built from the ground up as EDR solutions. Among the three being reviewed, only SentinelOne remains an independent company. Cylance and Carbon Black have both been acquired from Blackberry and VMware, respectively.

Click here to read our Ultimate Guide to the Top 10 EDR Solutions.
Another big difference between SentinelOne, Cylance and Carbon Black is where they play. SentinelOne and Carbon Black are more predominant in the enterprise space where Cylance has a heavier focus on mid-market-sized companies. That’s at least according to G2.com.
To recap so far:
- SentinelOne, Cylance, and Carbon Black are all EDR-focused companies at their core
- Cylance and Carbon Black have both been acquired by other companies
- SentinelOne and Carbon Black have a heavier presence than Cylance in the enterprise space
Contact an EDR Specialist
If you prefer to talk to an EDR specialist who can help you find an EDR solution based on your goals and environment, please fill out the form below (U.S. based only).
SentinelOne Differences
SentinelOne packages their products in three bundles, with the option to turn on a multitude of additional tools at a cost. The three bundles include Core, Control, and Complete.
SentinelOne Core
The Core product is branded as a Next-Gen Antivirus and Endpoint Protection Platform. It does, however, contain some EDR functions. Core gives you a storyline to help you understand the timeline of an attack. This gives you information about what happened and when, and who was affected. You can automate remediation by defining basic steps once a threat has been validated. Those steps include: Kill, Quarantine, Remediate, and Rollback.
A unique differentiator for SentinelOne is all the operating system support you get. SentinelOne supports Windows all the way back to Windows Server 2003 SP2+ and Windows XP SP3+. It also supports MacOS, 12 major Linux distributions, cloud platforms such as Google, AWS, and Azure, and VMware, Hyper-V and Citrix Hypervisors.
SentinelOne Control
Moving up the stack to SentinelOne’s Control product will give you Network Control, Device Control, and Rogue Device Discovery. You would use these features if you wanted to, for example, automatically shut down network traffic from a device where malware is detected. Or, disable USB ports on a controlled device. And find devices on the network that are not controlled today.
SentinelOne Complete
The SentinelOne Complete product is the true EDR solution because it gives you the ability to hunt for threats using search queries across your environment. It comes with everything that the Core and Control products as well. It also maps its data collection to the MITRE ATT&CK framework.
Key Differences
- SentinelOne stores log data for 365 days.
- Supports 12 Linux distributions, Mac IOS, and Windows versions dating back to XP SP3 and Windows Server 2003
- Has a multitude of other add-on options like Hologram which is a honeypot to lure and misdirect threat actors into revealing themselves
- 2022 MITRE ATT&CK Engenuity
- Visibility Count: 108 of 109 sub-steps
- Telemetry Coverage: 0 of 109 sub-steps
- Analytic Coverage: 108 of 109 sub-steps
Carbon Black Differences
Carbon Black comes out of the box with the ability to 1) record events for analysis, 2) search and hunt for threats, 3) conduct remote remediation, and 4) visualize the attack chain. This is different from SentinelOne, which has three products to choose from and only the highest-level (Complete) gives you the ability to hunt for threats. Carbon Black does not support as many operating system versions as SentinelOne. You should make sure all your workloads are covered by whichever EDR product you choose.
Carbon Black does also offer a vCenter plugin which increases its integration with VMware over its competitors. You can also create network-level remediation policies if you have VMware NSX to automatically do things like deny all traffic to a specific group of target devices, or only allow traffic to flow to Carbon Black from a specific group of targets. This is not a huge differentiator to either Cylance or SentinelOne as they can perform similar functions, just not through NSX.
Key Differences
- Carbon Black stores log data for 30 days unless it is associated with an alert. Then it is stored for 180 days.
- Integration with VMware vCenter and VMware NSX
- 2022 MITRE ATT&CK Engenuity
- Visibility Count: 90 of 109 sub-steps
- Telemetry Coverage: 33 of 109 sub-steps
- Analytic Coverage: 57 of 109 sub-steps
Cylance Differences
Cylance sells their EDR solution as CylanceOPTICS. CylancePROTECT is an Endpoint Protection solution that is required for CylanceOPTICS. Unlike SentinelOne, you only need to buy one product to get the full suite of EDR capabilities. Like SentinleOne you can control the use of USB drives and network access. However, after the acquisition Cylance is much more geared to existing BlackBerry customers. Looking at their datasheet for CylancePROTECT, they tout core capabilities around scanning apps in the UEM BlackBerry store, and IOS app integrity checking for BlackBerry Dynamics SDK apps.
CylanceOPTICS offers threat detection, threat hunting, threat recording, and automated playbooks for incident response.
Key Differences
- CylanceOPTICS stores log data for 30 days
- Integration with BlackBerry Store and other BlackBerry product suites
- 2022 MITRE ATT&CK Engenuity
- Visibility Count: 89 of 109 sub-steps
- Telemetry Coverage: 24 of 109 sub-steps
- Analytic Coverage: 71 of 109 sub-steps
Contact an EDR Specialist
If you prefer to talk to an EDR specialist who can help you find an EDR solution based on your goals and environment, please fill out the form below (U.S. based only).