Talk to us
by OpenTextTechBag Intel Page

OpenText Core Endpoint Protection

A shared PC in a branch office runs an unknown installer. Reimaging it shouldn’t be the only fix — OpenText Core Endpoint Protection, formerly Webroot Business Endpoint Protection, takes file verdicts from the cloud, journals what unknown files do and rolls their changes back — run by you or your MSP from one console.

Cloud verdicts, no signature filesJournaling and automatic rollbackQuoted; 30-day free trial

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no price, and its online cart sells only in the US; partners quote per seat
Quote
Reviews
SoftwareAdvice rating from 217 reviews, as shown on OpenText’s own product page
4.5 / 5
Trial
Unlimited endpoints and no credit card, according to OpenText’s product page
30 days
India
No Indian console region is listed; ask where telemetry and logs are stored
Not documented

Quick answer

OpenText Core Endpoint Protection (formerly Webroot Business Endpoint Protection) is cloud-managed antivirus for small firms and their MSPs: a light Windows and macOS agent gets file verdicts from cloud machine learning and BrightCloud intelligence, journals unknown files and rolls back their changes. Core EDR adds detection and response without redeploying. It is quote-only, with a free 30-day trial. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Core Endpoint Protection — the endpoint agent, with Core EDR and Core MDR as paid add-ons. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
This page.
You’re here
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Cloud-managed endpoint protection for SMBs and MSPs, formerly Webroot Business Endpoint Protection
Maker
OpenText, headquartered in Waterloo, Canada (OTEX on NASDAQ and TSX); Ayman Antoun became CEO on 20 April 2026
Status
Windows agent 9.0.41.32 took the OpenText name in August 2025; Mac build 9.7.7.49 shipped in January 2026
Price
No public price; the online cart serves US buyers only, so elsewhere it is quoted, mostly by MSPs
Engine
Cloud machine learning plus BrightCloud threat intelligence, which OpenText says 140+ vendors rely on
Recovery
Unknown files are monitored and journaled; if judged malicious, their changes to local drives are rolled back
Add-ons
Core EDR (built-in SIEM and SOAR) and Core MDR (24/7, co-managed), each sold separately
Integrations
40+ third-party RMM and automation tools, a REST API and a multi-site cloud console
India
No Indian data region is documented for the console; OpenText employs about 6,500 people in India
In India via
TechBag — trial on a pilot group, MSP or direct quote in INR with GST, agent rollout
Part 02 · Learn

Understand cloud-managed endpoint agents before you pick one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is cloud-managed endpoint protection?

A small agent asks the cloud for a verdict on each file instead of storing signatures locally.

Signature antivirus on every PC vs OpenText Core Endpoint Protection — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSignature antivirus, PC by PCOpenText Core Endpoint Protection
Threat updatesDaily signature downloads to every PCVerdicts from the cloud, no definition files
An unknown file runsOne chance to allow it or block itJournaled until the cloud rules on it
After an infectionReimage the machine, restore from backupLocal changes rolled back automatically
Running 20 client sitesTwenty consoles or a visit to eachOne multi-site console linked to your RMM
Investigating a hitGuesswork from an alert nameProcess tree, isolation, Core EDR if added
What it is NOT—Linux cover, a published price, or a 24/7 team without Core MDR

The cheapest test is the free trial: put the agent on ten PCs, retire the old antivirus there, and practise isolating one from the console.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where files are judged and watched

Agent

OpenText endpoint agent

A small agent on each Windows or Mac endpoint asks the cloud for a verdict instead of holding a signature database; OpenText says agent updates usually take about three seconds.

02
Where the heavy analysis runs

Cloud

Cloud classification and BrightCloud

Machine learning in OpenText’s cloud does the intensive malware analysis, drawing on BrightCloud threat intelligence, so verdicts change in real time without definition downloads.

03
Where sites and policies are run

Console

Cloud console and Global Site Manager

One web console holds devices, policy templates and remote agent commands; the Global Site Manager view lets an MSP run many customer sites, and a REST API feeds other tools.

04
How detection and response are added

Add-ons

Core EDR and Core MDR

Core EDR switches on in the same agent with no redeployment, adding SIEM correlation, SOAR playbooks and CVE checks; Core MDR puts a 24/7 co-managed team on top.

A small agent on each PC, verdicts from OpenText’s cloud — and one multi-site console an MSP can run for every customer.

Part 03 · Evaluate

Nine capabilities. Prevent, recover, respond.

OpenText Core Endpoint Protection blocks threats with cloud verdicts and undoes what an unknown file changed.

Prevent
Cloud ML

Verdicts from the cloud

Real-time machine learning in OpenText’s cloud classifies files, so there are no signature files to push and the agent stays small.

Prevent
Shields

Several shields, one agent

Behaviour, core-system, web-threat, identity, evasion and offline shields each watch a different route an attack can take in.

Prevent
Script Shield

Stops hostile scripts

Evasion Shield catches file-based, fileless and obfuscated scripts, and Script Shield halts malicious PowerShell, JavaScript and VBScript.

Recover
Journaling

Watches the unknown

A file the cloud cannot yet classify may run, but the agent monitors and journals each change it makes until a verdict comes back.

Recover
Rollback

Undo what malware changed

If a journaled file is ruled a threat, the changes it made to local drives are rolled back to their state before the infection.

Recover
Offline

Cover off the network

OpenText’s datasheet says monitoring, journaling and containment carry on when a laptop is offline, through a dedicated offline shield.

Respond
Isolation

Cut a device off fast

Device isolation fences an infected machine off the network to stop the spread, while keeping the link the console needs to manage it.

Respond
Process tree

See how it ran

Process tree visualisation traces where each process came from and what it started, which OpenText says can help with cyber-insurance forms.

Respond
Core EDR

EDR without a reinstall

Core EDR brings a built-in SIEM, SOAR playbooks and CVE-based vulnerability checks to the same agent, with no new deployment scripts.

See it, don’t just read it

Watch OpenText Core Endpoint Protection in action

An MSP-focused explainer, a technical deep dive and a healthcare customer story, all from the official Webroot channel OpenText now owns, recorded in 2021 and 2022 before the product took the OpenText name.

Webroot channel (official, now OpenText)·Explainer, January 2021

Webroot® Business Endpoint Protection: Purpose-built for MSPs

How the agent and console serve MSPs, filmed in 2021 when the product was still sold under the Webroot name.

Webroot channel (official, now OpenText)·Deep dive, April 2021

Webroot Endpoint Protection: Technical Deep Dive

A 48-minute walk through the agent, console and policies, recorded in 2021 before the OpenText rename.

Webroot channel (official, now OpenText)·Customer story, November 2022

Nationwide Healthcare Services Rests Easier with Webroot Endpoint Protection

A US healthcare firm on running the agent day to day; OpenText still quotes its IT director on today’s product page.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Core Endpoint Protection

Small offices rarely have a security team. This agent undoes damage and lets an MSP watch every site.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Rollback for what slips past

Most agents get one chance to block a file. OpenText lets an unknown file run under watch: the agent journals every change it makes, and if the cloud later rules it malicious, those changes to local drives are reversed. That suits small offices, where reimaging a PC costs a working day.

02

Made for MSPs with many small customers

The cloud console runs many sites from one login, with policy templates and remote agent commands. OpenText lists 40+ third-party RMM and automation integrations and a REST API, and its community hosts integration forums for ConnectWise Automate and Manage, Kaseya VSA and N-able.

03

Grow into EDR and MDR on one agent

Core EDR is added to an existing deployment without redeploying or changing scripts, and brings SIEM correlation, SOAR playbooks and CVE-based checks. Core MDR adds a 24/7 team on a co-managed model with 500+ integrations, so the in-house IT team keeps full sight of alerts.

04

Where it stops

No price is published, and the online cart sells only in the US. No Linux agent or Indian data region is documented, and OpenText cites no analyst ranking for it. OpenText classes its SMB and consumer security line as non-core and says it is divesting non-core units, so ask about the roadmap.

The idea
Cloud verdicts, rollback for the rest
The buyer
Small offices and the MSPs serving them
The price
Quote only; 30-day free trial
Proof, not promises

The numbers behind the platform

40+
third-party integrations, RMM and automation tools among them, beside a REST API
— Vendor
140+
network, security and technology vendors that OpenText says rely on BrightCloud
— Vendor
3 seconds
the typical time OpenText gives for an automatic agent update, unseen by the user
— Vendor
30 days
of free trial on unlimited endpoints, with no credit card asked for at sign-up
— Vendor
500+
integrations OpenText cites for Core MDR, the 24/7 co-managed service on top
— Vendor
217 reviews
behind the 4.5-star SoftwareAdvice rating OpenText shows on its product page
— Review site

What your OpenText Core Endpoint Protection rollout looks like

Week 1Model

Count and sort the endpoints

List Windows PCs, servers and Macs per site, flag any Linux machines, and decide whether to buy direct or via an MSP.

Week 2Pilot

Start the free trial

Open the 30-day trial for a pilot group, deploy by MSI or Group Policy, and remove the old antivirus as each PC joins.

Week 3Prove

Test rollback and isolation

Check how journaled changes and rollbacks show in the console, then practise isolating and releasing a lab device.

Month 2Decide

Decide on EDR and MDR

Weigh Core EDR’s playbooks and Core MDR’s 24/7 team against the staff you have, then ask for one itemised quote.

Month 3Commit

Roll out and wire the RMM

Push the agent to every site, apply policy templates, connect your RMM or PSA, and schedule monthly reports.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
48+ reviews*
82% would recommend
Ease of deployment4.5
Light footprint4.4
Multi-site console4.2
Ransomware recovery4.0
Detection depth3.6
5★
46%
4★
35%
3★
13%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
IT Services
“We look after thirty small clients from one console. Policy templates mean a new clinic is covered the day it signs.”
MSP Technical Lead
IT Services
Distribution
“An unknown installer ran on a sales laptop. Once it was flagged, its file changes were undone and we skipped the reimage.”
IT Manager
Distribution
Healthcare
“Our older billing PCs no longer stall during scans, which was the complaint that started our search for a new tool.”
Systems Administrator
Healthcare
Manufacturing
“We isolated one infected workstation remotely, then used the process tree to see which download had started it all.”
Security Analyst
Manufacturing
BFSI
“Ask where telemetry is stored before you sign. Our auditor wanted an answer on DPDP and it took weeks to get one.”
Compliance Officer
BFSI
Logistics
“Two Ubuntu servers needed a different product because no Linux agent is offered, so budget for a second licence.”
Infrastructure Engineer
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint protection market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint Protection Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText Core Endpoint ProtectionThis page

Quoted per seat, mostly through MSPs; the online cart is US-only.

Grid 02 · The architecture

MSP Fit × Response Depth

The grid nobody publishes — how well an MSP can run the product across many customers vs how deep its detection, investigation and managed response go.

Analyst-grade EDRMSP-ready EDR platformsSingle-site antivirusMSP-first prevention
OpenText Core Endpoint ProtectionThis page

40+ integrations and a multi-site console; EDR and MDR are add-ons.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText Core Endpoint Protection vs the endpoint field

Against SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Bitdefender GravityZone and ESET PROTECT — on platforms, price, rollback, response, MSP fit and India.

DimensionOpenText Core Endpoint ProtectionSentinelOne Singularity EndpointCrowdStrike FalconMicrosoft Defender for EndpointBitdefender GravityZoneESET PROTECT
What it isCloud AV for SMBs, MSPsAutonomous EPP + EDRFalcon bundlesEPP + EDR in DefenderTiered GravityZoneTiered PROTECT
Deployment and consoleCloud console onlySaaS console onlyCloud onlyDefender portalCloud or on-premCloud or your server
Platforms coveredWindows and macOSWin, Mac, LinuxWin, Mac, LinuxFive platformsWin, Mac, LinuxWin, Mac, Linux, Android
Pricing modelPer seat, quotedPer endpoint, partnersPer device, yearlyPer user or bundledPer device, yearlyPer device, yearly
Published entry priceNot published$179.99/endpoint/yr$59.99/device/year$3/user/month$57/device/year$42.20/device/year
Included vs add-onEDR and MDR extraMDR, mobile extraEDR from EnterpriseEDR needs Plan 2Full EDR in EnterpriseXDR only in Elite
Sizing and minimumsTrial: any device countList for 5–100Breaks at 500+Business: 300 usersPromo, then renewal5-pack; Elite 25
Ransomware recoveryJournal and rollbackOne-click rollbackNo file rollbackNo agent rollbackRansomware MitigationRansomware Remediation
Detection and responseIsolation; EDR add-onStoryline EDRInsight XDRPlan 2 huntingEnterprise EDRESET Inspect
Managed SOC optionCore MDR, 24/7Wayfinder MDRFalcon CompleteDefender ExpertsBitdefender MDRESET MDR
Integrations and MSP fit40+ tools, multi-siteMulti-tenant SaaSFlight Control tenantsLighthouse, ≤2,500 usersRMM and PSA plug-insRMM plug-ins
India data regionNone documentedMumbai regionAnnounced, not liveNot verifiedOn-prem console optionSelf-hosted server
Lock-in and exitCloud console onlySaaS onlyCloud-only platformMicrosoft estateSelf-host optionCloud or on-prem exit
Best fitMSP-run small officesLean teams, rollbackTeams that will huntMicrosoft 365 shopsPrice-led mixed fleetsLight agent, list prices
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText Core Endpoint Protection if…

  • ✓You are an MSP, or buy through one, and want many small sites in one cloud console tied to the RMM you already run
  • ✓Older PCs and branch laptops need a light agent that takes verdicts from the cloud instead of downloading definitions
  • ✓You want the agent to undo a bad file’s changes, and to add Core EDR or Core MDR later without reinstalling

Compare alternatives if…

  • ✓Linux servers must sit under the same agent — SentinelOne, CrowdStrike, Bitdefender and ESET all cover Linux
  • ✓You want a price before a sales call — CrowdStrike, Bitdefender and ESET publish per-device prices
  • ✓Console data must stay in India — SentinelOne has a Mumbai region; Bitdefender and ESET can run the console on premises

Do not expect…

  • ✓A public price, or an online store that sells outside the US
  • ✓An analyst ranking — OpenText cites none for this product
  • ✓A documented Indian data region for the console or its telemetry

OpenText Core Endpoint Protection is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does cleaning up infections cost you?

Drag the sliders (endpoints protected; IT-hour cost). Estimates model IT time spent cleaning up infections, reimaging PCs and chasing definition updates at an assumed 1.5 hours per endpoint a year, with 70% of it removed by cloud verdicts, rollback and remote isolation. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual infection clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. OpenText shows no price for Core Endpoint Protection, its online cart sells only to US buyers, and no rupee price exists. It is an annual per-seat subscription, usually bought through an MSP, with Core EDR and Core MDR priced on top. The 30-day trial covers unlimited endpoints with no card. TechBag sizes the Windows and Mac estate first, then gets the quote itemised in INR with GST.

Core Endpoint Protection

Best for small offices and MSP-run estates

  • Quoted per seat, annual term
  • Journaling, rollback and device isolation
  • 30-day trial on unlimited endpoints

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Core EDR and Core MDR

Best when someone must investigate or watch 24/7

  • Each quoted on top of the agent
  • EDR adds SIEM, SOAR and CVE checks
  • MDR: 24/7, co-managed, 500+ integrations

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Platforms

Are all endpoints Windows or macOS? No Linux agent is documented, so plan other cover for Linux servers.

2
Buying route

Will you buy direct or through an MSP? The online cart is US-only, so Indian buyers need a partner quote.

3
Rollback

Has the pilot shown how journaled changes are rolled back, and on which operating systems that applies?

4
Response depth

Do you need Core EDR’s SIEM and SOAR, or are isolation and process trees enough for your team?

5
Night cover

Who watches alerts out of hours? If nobody does, price Core MDR’s 24/7 co-managed service alongside.

6
Integrations

Is your RMM or PSA among the 40+ integrations, and does the REST API cover the reports you need?

7
Data location

Where are console data and telemetry stored? Get it in writing if DPDP or a sector regulator asks.

8
Licence

Does the quote list seats, term and add-ons in INR with GST, and what does OpenText commit on roadmap?

FAQ

Questions buyers ask

It is OpenText’s cloud-managed antivirus for small and mid-sized businesses and the MSPs that run their IT, formerly sold as Webroot Business Endpoint Protection. A light agent gets file verdicts from cloud machine learning and BrightCloud intelligence, journals unknown files and rolls back their changes.

Ready to evaluate OpenText Core Endpoint Protection?

Count your Windows and Mac devices first, or let a TechBag advisor run the 30-day trial on a pilot group and get one quote in INR covering the agent, EDR and MDR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.