What are the core benefits of ThreatDown Powered by Malwarebytes Advanced Corporate?
Central console – All endpoints managed from one cloud console.
EDR included – Suspicious activity monitoring, endpoint isolation and rollback.
Ransomware rollback – Restores encrypted files up to seven days.
Patch management – Patches Windows and third-party applications automatically.
Single agent – One lightweight agent for Windows and macOS.
Important note – Servers and Linux require the Server Protection add-on.
Nebula cloud console – Central policy management, deployment and reporting for all endpoints.
Endpoint Detection and Response – Suspicious activity monitoring, endpoint isolation and cloud sandbox.
Ransomware Rollback – Restores files encrypted or changed up to seven days.
Patch Management – Scans for vulnerabilities, then patches operating systems and applications.
Managed Threat Hunting – Vendor analysts escalate critical alerts with remediation guidance.
Important – Servers and all Linux endpoints require the Server Protection add-on.
Advanced is the second of four ThreatDown bundles, the business line Malwarebytes launched in November 2023 to replace its earlier Malwarebytes for Business endpoint products, so buyers still searching for that name will land here. Every endpoint is managed from the cloud-based Nebula console, with the multi-tenant OneView console used instead by managed service providers.
One agent – A single lightweight agent covers protection, EDR and patching.
Rollback instead of reimaging – Restores encrypted files without rebuilding the workstation.
Patching without extra tooling – Closes vulnerabilities the scan found, from one console.
Fewer alert queues – Managed Threat Hunting escalates only the critical detections.
Host firewall control – Inbound and outbound rules set centrally per policy.
Device and application control – USB access and unwanted applications blocked by policy.
Advanced is built around a small IT team that has no dedicated security staff, which is why the alert triage is handed to the vendor rather than to an internal analyst. The table below shows which obligations typically apply at each size and where this bundle stops being sufficient on its own.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Exceptions only | By sector | By sector |
| Security questionnaire from large customers | If supplier | ✓ | ✓ |
| Servers and Linux in scope | Often | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partial |
The revised Information Security Act obliges operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means most companies outside the designated sectors are not covered at all. For a company that is covered, the practical question is whether it can notice an incident and describe it accurately inside that window. Advanced supports exactly that part: suspicious activity monitoring and MITRE ATT&CK mapping give the incident a shape, endpoint isolation limits it while you write the report, and the Nebula console exports a timestamped record of what was detected and what the agent did about it. What it does not do is watch your environment for you, because 24x7 monitoring only begins with the Elite bundle, and it does not see your servers or Linux machines at all unless the Server Protection add-on is purchased, which is where an incident usually starts. Nebula also keeps detection data only for a limited period, so if you need to produce evidence months later, the syslog or SIEM export has to be configured up front rather than after the fact. This describes product capabilities and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes a company NIS 2 compliant, because the directive is assessed against your organisation and its processes rather than against a licence you hold. NIS 2 requires entities in the covered sectors to put risk management measures in place across incident handling, business continuity, supply chain security, vulnerability handling and disclosure, basic cyber hygiene and staff training, access control, and policies on the use of cryptography. Advanced contributes directly to three of those: incident handling through EDR detection, endpoint isolation and automated remediation; vulnerability handling through scheduled scanning with CVSS severity ratings followed by patching of operating systems and third-party applications; and cyber hygiene through centrally managed host firewall rules, application blocking and USB device control. It contributes nothing to supply chain assessment, access control and multi-factor authentication, staff training, or the governance documentation an auditor will ask to see, and email and identity coverage are separate add-ons rather than bundle components. Business continuity is the point most often misread here: the seven-day ransomware rollback restores files on a protected endpoint, but it is not a backup and does not replace one.
Yes, for the endpoint section, and it answers that section well. You can evidence malware protection on every managed device, a named EDR capability with isolation and response actions, a documented patch cadence covering operating systems and third-party applications, removable media control, application allow and deny lists, centrally managed host firewall policy, and log export to a SIEM in CEF format. On the vendor side, Malwarebytes publishes an ISO 27001 certification for its information security management system and makes a SOC 2 report available under NDA, which covers the supplier-assurance questions that ask about the manufacturer rather than about you. The items it will not answer are just as specific: multi-factor authentication and identity management, email filtering, backup and disaster recovery, data classification, encryption of servers and macOS devices, penetration testing, 24x7 monitoring, and any question that requires an on-premises or air-gapped management platform, because Nebula is cloud-only. Long log retention is a partial answer at best, since Nebula's native retention is limited and anything beyond it depends on your own SIEM. To close the gaps, moving up to Elite within the same family is normally cheaper and simpler than bolting a second vendor's MDR onto Advanced, and Server Protection, Mobile Security, Email Security and ITDR are all available as add-ons under the same console; backup and multi-factor authentication, however, will have to come from elsewhere.
The decisive difference is patching: Core scans for vulnerabilities but cannot install the updates, so the findings land on someone's to-do list instead of being closed automatically. Advanced adds Patch Management on top of that same scan, together with Ransomware Rollback and Managed Threat Hunting, which is why the vendor sells the tiers as Core Next-Gen AV, Advanced EDR and Elite MDR. The step from Advanced to Elite buys one thing and one thing only: analysts who watch the console around the clock instead of your own team. Server and mobile coverage sit outside all of this and are priced as add-ons at every tier, so they never form part of the tier decision.
| Capability | Core | Advanced | Elite |
|---|---|---|---|
| Vulnerability Assessment | ✓ | ✓ | ✓ |
| Patch Management | ✕ | ✓ | ✓ |
| Ransomware Rollback | ✕ | ✓ | ✓ |
| Managed Threat Hunting | ✕ | ✓ | ✓ |
| 24x7 Managed Detection and Response | ✕ | ✕ | ✓ |
| Server Protection | Add-on | Add-on | Add-on |
| Mobile Security | Add-on | Add-on | Add-on |
| Email Security | Add-on | Add-on | Add-on |
| DNS Filtering | Add-on | Add-on | Add-on |
The most expensive surprise is scope: servers are not covered by the bundle, and because Nebula counts every Linux machine as a server, a single Linux box also triggers the Server Protection add-on. Data location matters for Swiss and European buyers: a European data centre for Nebula does exist, but the vendor limits it to accounts provisioned after 3 August 2026, so most existing accounts run in the standard data centre and you should confirm which one applies before signing anything with a data residency clause. The management platform is cloud-only in either case, with no on-premises or air-gapped option, which rules the product out where a questionnaire demands locally hosted security tooling. Platform coverage is also uneven below the surface: Application Block runs on Windows only and not on macOS, Windows Server Core installations and non-persistent VDI are not supported, and the centrally managed drive encryption enforces BitLocker on Windows workstations, leaving macOS and servers to be encrypted some other way. Finally, treat the seven-day ransomware rollback as damage limitation rather than as a recovery strategy, and plan exclusions in advance for Exchange, SQL Server and domain controller roles, which the vendor documents as needing them.
The agent runs on Windows 11 and Windows 10, including Windows 11 on ARM processors via a separate installer, and on macOS with both Intel and Apple Silicon processors. Linux is supported as well, but every Linux endpoint is counted as a server and therefore requires the Server Protection add-on. Chromebook, Android, iOS and iPadOS devices are covered only through the separate Mobile Security add-on.
Vulnerability scan results are stored and displayed for up to 90 days across all endpoints, while detection and suspicious activity data is retained natively for a limited period only. If you need longer retention for audit or evidence purposes, events can be forwarded in CEF format to a syslog server or pushed to a SIEM such as Microsoft Sentinel or Google Security Operations, which has to be set up before you need the records rather than afterwards.
Deployment uses a single MSI installer that can be run manually, pushed silently by command line, or distributed through Microsoft Intune, SCCM, Group Policy or an RMM tool such as Datto or SolarWinds. A built-in Discovery and Deployment Tool is also available for finding unmanaged devices on the network. Each newly installed agent automatically runs a scan and reports its findings to the console within about 30 minutes.