What are the essential features of ThreatDown Powered by Malwarebytes Elite Server Corporate?
Central console – All servers managed from the cloud-based Nebula console.
Managed response – ThreatDown analysts monitor and remediate around the clock.
Ransomware rollback – Restores encrypted Windows server files up to seven days.
Patch management – Scheduled patching of operating systems and applications.
Server coverage – Windows Server 2016 to 2025 and Linux.
Important note – DNS filtering and email security cost extra.
Endpoint Protection – Multi-vector prevention against malware, fileless attacks and zero-day exploits.
Endpoint Detection and Response – Suspicious activity monitoring, cloud sandbox, endpoint isolation and MITRE mapping.
Managed Detection and Response – ThreatDown analysts monitor and remediate threats 24x7x365 on your behalf.
Ransomware Rollback – Restores encrypted Windows server files, configurable up to seven days.
Vulnerability and Patch Management – Scheduled or ad hoc scanning and patching of installed software.
Important – DNS Filtering and Email Security are separate add-on purchases.
The Elite bundle combines endpoint protection, EDR and a fully managed 24x7x365 detection and response service for Windows and Linux servers, all administered from the cloud-based Nebula console. The ThreatDown line was formerly named Malwarebytes for Business and was renamed in November 2023, so documentation and partner listings may still use the earlier module names Endpoint Protection for Servers and Endpoint Detection and Response for Servers.
Single agent – One lightweight agent delivers prevention, EDR and patching.
Out-of-hours cover – MDR analysts phone your named super admins during emergencies.
Endpoint isolation – Network, process and desktop isolation contain a compromised server.
Active Response Shell – Remote forensic access to Windows, macOS and Linux endpoints.
Rollback without VSS – Protected cache survives ransomware that deletes shadow copies.
Syslog export – Forwards endpoint events into an existing SIEM for evidence.
Headcount is not what decides this purchase. What decides it is whether your servers hold data whose loss would halt operations, and whether anyone is watching those servers between Friday evening and Monday morning. Note the asymmetry in the table below: the Swiss reporting obligation is triggered by sector rather than by size, while the European NIS 2 Directive works with a size threshold that leaves most micro and small entities outside its scope.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| 24/7 server monitoring without own SOC | ✓ | ✓ | Partial |
| This product fits | ✓ | ✓ | Partial |
No software product meets those requirements on its own, and this one is no exception. Since 1 April 2025 the revised Information Security Act has obliged operators of critical infrastructure — among them energy and drinking water suppliers, transport companies, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations — to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. The 24-hour clock starts at discovery, and that is precisely where the Elite bundle contributes: the MDR team watches around the clock and telephones the super admins you register in Nebula, so an incident found at three on a Sunday morning reaches a decision-maker in time to be reported rather than on Monday. The console also supplies much of the substance a report needs — which servers were affected, the detection timeline, the processes involved, and the isolation and remediation steps taken. What it does not do is equally clear: it does not file the report for you, it sees nothing that never touches a monitored server such as a compromised mailbox, a firewall or an unmanaged NAS, and it holds no record of who inside your organisation decided what, which the reporting process expects. This is a product description and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers or directly with BACS.
No product creates NIS 2 compliance, because the directive asks for organisational measures and evidence that they are applied, not for a particular piece of software. NIS 2 requires risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, procedures to assess whether measures actually work, basic cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This bundle contributes directly to three of those categories: incident handling through detection, isolation, managed remediation and an exportable event trail; vulnerability handling through scheduled scanning and patching of operating systems and installed applications; and asset management, insofar as the console maintains an inventory of the servers running the agent. It contributes nothing to backup and business continuity, supply chain security, staff training, multi-factor authentication, cryptography or access control outside its own console, and it sees nothing that does not run the agent — network devices, mailboxes, identity systems and cloud workloads all remain out of scope. Treat it as evidence for the endpoint portion of your measures, and plan separately for the rest.
Yes, for the endpoint block of a questionnaire, and only that block. It lets you answer, with console evidence rather than assertion, that EDR is deployed on every server, that an external team monitors 24x7x365, that compromised hosts can be isolated at network, process or desktop level, that patching runs on a defined schedule, that vulnerability scans are recurring, that policy is centrally enforced and tamper-protected, that console access is role-based, and that events can be forwarded to a SIEM by syslog. In the same detail, here is what it will not answer: backup and restore testing, encryption at rest on servers, multi-factor authentication for administrative accounts, email filtering, web and DNS filtering, network segmentation, secure development practices, physical security, staff awareness training, subprocessor lists, and your own certification status. Where the gap is DNS filtering, moving up to the Ultimate bundle of the same family is usually cheaper and simpler than introducing a second vendor, since it is one agent and one console either way; Email Security and Premium Support are add-ons within the same family. Encryption is the one gap you cannot close inside this line for servers — ThreatDown Drive Encryption is a separate module aimed at Windows workstations — so budget for a separate answer there.
The single decisive difference is who reads the alerts. Advanced gives your own staff the full technical stack and expects them to triage what it produces; Elite adds Managed Detection and Response, so ThreatDown analysts investigate, respond and remediate on your behalf around the clock; Ultimate adds DNS filtering on top of Elite. Everything below the MDR line — protection, EDR, rollback, vulnerability assessment and patching, managed threat hunting — is identical across all three, so the question is staffing rather than features. Elite is a complete bundle in its own right: it is not an add-on to another ThreatDown product and it is not a renewal-only item, so it does not require an existing licence of a different product to work.
| Component | Advanced | Elite | Ultimate |
|---|---|---|---|
| Endpoint Protection | ✓ | ✓ | ✓ |
| EDR with Ransomware Rollback | ✓ | ✓ | ✓ |
| Vulnerability and Patch Management | ✓ | ✓ | ✓ |
| Managed Threat Hunting | ✓ | ✓ | ✓ |
| Managed Detection and Response | ✕ | ✓ | ✓ |
| DNS Filtering | Add-on | Add-on | ✓ |
| Email Security | Add-on | Add-on | Add-on |
The management platform is cloud-only: neither Nebula nor the multi-tenant OneView console can be hosted on-premises or in an air-gapped network, which rules the product out wherever that is a hard requirement. Data location is the second point Swiss and European buyers should settle before signing, because a European data centre does exist but, according to ThreatDown's own network documentation, it applies only to a limited set of EU-based accounts provisioned after 3 August 2026, while most accounts continue to run in the standard data centre — you can tell which one you have from the Nebula login URL, where European accounts contain euc1. On platform coverage, Windows Server 2016 through 2025 are supported but Server Core installations are not, and non-persistent VDI is not supported either, both of which catch people out on consolidated estates. Ransomware Rollback is a Windows-only feature, so Linux file servers receive detection, isolation and remediation but no rollback, and on x86_64 hardware SUSE Linux Enterprise Server 15 is supported for protection but not for EDR. Rollback is also not a backup: the cache holds between one and seven days of file changes with three days as the default, the server backup path must sit on a local drive because network drives are not supported, and files above the configured size limit are skipped entirely.
No. Suspicious activity monitoring has a separate policy switch for server operating systems, and both the general switch and the server switch must be enabled before detection or Ransomware Rollback works on a server. ThreatDown's own guidance is to place servers in their own group with their own policy rather than reusing the workstation policy, which also keeps role-specific exclusions for Exchange, SQL, DNS and domain controllers manageable.
Only if you authorise it. In the Managed Services configuration you choose between ThreatDown-managed remediation and notification-only, and you separately authorise analysts to isolate endpoints on your behalf. One practical detail worth knowing in advance: removing isolation reboots the endpoint, which is a different conversation on a production server than on a laptop.
No. Mobile Security for Business, covering Android, iOS, iPadOS and ChromeOS, is a separate ThreatDown product, as is Drive Encryption. Drive Encryption is also aimed at Windows workstations rather than servers, so server-side encryption at rest needs a separate answer.
No, and treating it as one is a costly mistake. It is a local cache of recent file changes, configurable between one and seven days with three as the default, covering Windows only and depending on the agent still running. It will not help after a full system loss, a hardware failure, or a deletion older than the configured window.