LUCIDTextjet - Print logo

ThreatDown Powered by Malwarebytes Advanced Server Corporate

Short Description

Open HTML

What are the key advantages of ThreatDown Powered by Malwarebytes Advanced Server Corporate?
Central management – All servers managed from one cloud console.
Server EDR – Suspicious activity monitoring and isolation on servers.
Ransomware rollback – Restores files changed up to seven days.
Patch management – Patches Windows and third-party server software automatically.
Broad coverage – Windows Server 2016 to 2025 and Linux.
Important note – No mailbox scanning and no encryption management.

Long Description

Open HTML

What is included in ThreatDown Powered by Malwarebytes Advanced Server Corporate?

Endpoint Protection – Blocks malware, exploits and ransomware behaviour on server roles.
Endpoint Detection and Response – Suspicious activity monitoring, endpoint isolation and Active Response Shell.
7-day Ransomware Rollback – Restores files changed by ransomware within seven days.
Vulnerability and Patch Management – Scans and patches operating system and third-party applications.
Nebula cloud console – Separate server policies, groups, exclusions and CEF syslog export.
Important – Drive encryption and mailbox-level Exchange scanning are not included.

What are the main benefits of ThreatDown Powered by Malwarebytes Advanced Server Corporate?

ThreatDown Advanced Server is the server variant of the Advanced bundle from ThreatDown powered by Malwarebytes, the business line that was sold as Malwarebytes for Business until the rebrand in November 2023. Every protected server is managed from the cloud-based Nebula console, using server policies, groups and exclusions that are kept separate from the workstation configuration.

One agent per server – Protection, EDR and patching run in a single agent.
Role-aware configuration – Documented exclusions for Exchange, SQL, DNS and domain controllers.
Recovery without VSS – Rollback uses protected local copies, not shadow volume snapshots.
Linux server coverage – One console for Windows Server and major Linux distributions.
Evidence for audits – Detection log kept 365 days, exportable to SIEM.
Guided alert triage – Managed Threat Hunting escalates only the critical alerts.

Best antivirus? Why Windows Defender alone is not enough
Explains where the protection built into Windows reaches its limits and what a separate security layer adds on top of it.

Which company size is ThreatDown Powered by Malwarebytes Advanced Server Corporate suitable for?

The bundle is built for organisations that run a manageable number of servers and do not have a dedicated security team watching alerts around the clock. A company with three domain controllers, a file server and an Exchange server gets full coverage from one console. Once someone has to answer alerts at three in the morning, the technology in Advanced is no longer the limiting factor — the staffing is, and that is what the Elite bundle addresses.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector Likely
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Increasing ✓ ✓
Around-the-clock handling of server alerts ✕ Often ✓
This product fits ✓ ✓ Partial

Does ThreatDown Powered by Malwarebytes Advanced Server Corporate meet the requirements of Swiss cybersecurity legislation?

The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so the first question is whether your organisation falls into that group at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the technical facts have to be assembled on the first day, not during the following week. ThreatDown Advanced Server supports that deadline in a concrete way: the Nebula Detection Log retains records for 365 days, the Events log covers the previous 30 days, and EDR suspicious activity data shows which process ran on which server and what it changed, which is exactly the material a first report needs. What the product does not do is decide whether an incident is reportable, produce the report itself, or cover the organisational side of the obligation — there is no case management, no defined escalation path to management, and no evidence that backups exist or have been tested. This description is technical and is not legal advice; whether your organisation is subject to the reporting obligation should be clarified with your own legal advisers.

Does ThreatDown Powered by Malwarebytes Advanced Server Corporate meet the requirements of European cybersecurity legislation?

No software product makes a company compliant with the NIS 2 Directive, because the directive addresses organisations and their management bodies and requires appropriate technical, operational and organisational measures. The measure categories the directive names include risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, cryptography, access control and multi-factor authentication. ThreatDown Advanced Server contributes materially to three of them: incident handling through EDR detection, endpoint isolation and the Active Response Shell, vulnerability handling through the vulnerability assessment and patch management modules, and asset visibility through the endpoint inventory in Nebula. It contributes nothing to business continuity and backup, cryptography, multi-factor authentication, supply chain governance or staff training, and its scope stops at servers and workstations — network appliances, cloud workloads and identity systems are outside it. Because each member state transposes the directive into its own law, the obligations that actually apply to your organisation follow from the legislation of the country in which you operate.

Does ThreatDown Powered by Malwarebytes Advanced Server Corporate help with security questionnaires from large customers?

Yes, for the endpoint and server section of a questionnaire, and not for the rest of it. It answers the items on malware protection for servers with central management, on the presence of an EDR capability with isolation and response actions, on a documented patch process with reporting, on regular vulnerability scanning, on application control, and on log retention with export to a SIEM in CEF format. It also covers role-based console access, since the user audit log records administrator changes for 90 days. It does not answer the items on backup and restore testing, encryption of data at rest, multi-factor authentication, email and phishing defence, network segmentation, secure development, supplier management, or your own certification status such as ISO 27001. Where the gap is around-the-clock monitoring, moving up to the Elite bundle within the same family is usually cheaper and far less disruptive than bolting a second vendor's managed service onto the same estate; encryption and email items are best closed with the separate ThreatDown modules or with tooling you already license from Microsoft, and backup remains an independent product decision.

Data loss is expensive: How backups help you avoid outages
Covers why a backup and restore concept remains a separate requirement that endpoint security and rollback features do not replace.

What is the difference between ThreatDown Core and ThreatDown Advanced?

The decisive difference is EDR. Core prevents and scans, but it cannot detect suspicious behaviour after the fact, cannot isolate a compromised server, and cannot undo an encryption event. In practical terms Core will tell you that a server is missing patches without being able to install them, because Core includes vulnerability scanning but not patch management. Elite adds no technology that Advanced lacks — it adds people, in the form of 24x7x365 Managed Detection and Response, and Ultimate layers DNS Filtering and Premium Support on top of Elite.

CapabilityCoreAdvancedElite
Endpoint Protection ✓ ✓ ✓
Vulnerability Assessment ✓ ✓ ✓
Patch Management ✕ ✓ ✓
EDR with 7-day Ransomware Rollback ✕ ✓ ✓
Managed Threat Hunting ✕ ✓ ✓
Managed Detection and Response, 24x7x365 ✕ ✕ ✓
European data centre for the console Limited Limited Limited

Which limitations should you know before buying?

Where your console data is processed is the point to check first: most Nebula accounts are provisioned in the standard data centre, and the European data centre is available only to a limited set of EU-based accounts provisioned after 3 August 2026, recognisable by a login URL containing euc1. Platform coverage is not uniform either — Windows Server Core installations and non-persistent VDI are not supported at all, SUSE Linux Enterprise Server 15 on x86_64 runs Endpoint Protection but not EDR, and Ransomware Behaviour Protection is unsupported on RDP, Hyper-V and terminal services roles, which is precisely where many organisations expect it. Older Windows Server versions from 2012 R2 back to 2008 can only be deployed with the legacy installer, which keeps receiving protection updates but no new features. On an Exchange server the agent protects the operating system rather than the mail flow, so there is no transport-level or mailbox-level scanning and Microsoft's own antivirus exclusions still have to be applied. The follow-up purchases that come up most often are Drive Encryption, Email Security and DNS Filtering, which are separate modules, and managed monitoring, which requires the Elite bundle.

Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?
Helps you judge whether your older server versions should be upgraded before you standardise a security agent across the estate.

Frequently asked questions about ThreatDown Powered by Malwarebytes Advanced Server Corporate

Can the agent be installed on a Windows Server Core installation?

No. Server Core installations are not supported, so a full installation with the desktop experience is required. Non-persistent VDI is also unsupported, while persistent VDI works normally.

Which Linux servers are covered, and does EDR work on all of them?

Endpoint Protection covers Alma Linux, Amazon Linux 2, CentOS, Debian, Oracle Linux 10, Red Hat Enterprise Linux, Rocky Linux, SUSE Linux Enterprise Server 15 and Ubuntu LTS releases, on x86_64 and on ARM64. EDR is the exception: it is not available on SUSE Linux Enterprise Server 15 on x86_64, and it requires Linux kernel 3.10 or newer plus DKMS on Amazon Linux, CentOS and Red Hat.

How long is data kept in the Nebula console?

The Detection Log keeps records for 365 days, the Events activity log for 30 days, and the user audit log for 90 days. For longer retention, Nebula forwards threat events to a syslog server in CEF format through a promoted Windows endpoint, or exports detection data to Google Chronicle SIEM.

Does the ransomware rollback replace a backup?

No. Rollback restores files that a detected ransomware process changed on that specific device, within a seven-day window, using protected local copies rather than Windows shadow volume snapshots. It does nothing for hardware failure, accidental deletion, a destroyed server or a corrupted database, so a backup concept remains a separate requirement.

 

Meta Description

Server protection with EDR, patch management and 7-day ransomware rollback, managed in the Nebula cloud console for Windows Server and Linux.

Keywords

ThreatDown Advanced Server, Malwarebytes, ThreatDown, Malwarebytes for Business, server security, endpoint detection and response, patch management, ransomware rollback, Nebula

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree