LUCIDTextjet - Print logo

ThreatDown Powered by Malwarebytes Ultimate Server Corporate

Short Description

Open HTML

What are the key advantages of ThreatDown Powered by Malwarebytes Ultimate Server Corporate?
Central management – Cloud console for every protected server.
Managed response – ThreatDown analysts monitor and remediate around the clock.
Server EDR – Detection and response for Windows and Linux servers.
Ransomware rollback – Estores changed files up to seven days.
Patch management – Automates Windows Server and application patching.
Important note – Email security and DNS filtering are add-ons.

Long Description

Open HTML

What is included in ThreatDown Ultimate Server?

Nebula cloud console – Single-tenant console for policies, alerts and server reporting.
Server endpoint protection – Covers Windows Server 2016 to 2025 and major Linux distributions
EDR and rollback – Suspicious activity monitoring plus seven-day ransomware file recovery.
Managed Detection and Response – ThreatDown analysts investigate and remediate alerts around the clock.
Vulnerability and patching – Scans and patches Windows operating systems and third-party applications.
Important – Email security and DNS filtering are sold as separate add-ons.

What are the main benefits of ThreatDown Ultimate Server?

ThreatDown Ultimate Server is the server-licensed version of the top ThreatDown bundle, managed from the cloud-based Nebula console rather than from software installed on each machine. ThreatDown is the business line Malwarebytes introduced in late 2023, replacing the products previously sold as Malwarebytes Endpoint Protection for Servers and Malwarebytes Endpoint Detection and Response for Servers.

One agent – One installer covers protection, EDR and patching.
Night coverage – Analysts act on server alerts outside office hours.
Faster ransomware recovery – Rollback restores encrypted files without restoring a backup.
Patch evidence – Console reports show which server patches were applied.
Syslog export – Endpoint events can be forwarded to a SIEM.
Mixed platform coverage – Windows, macOS and Linux run on one console.

Best antivirus? Why Windows Defender alone is not enough
Explains where the built-in Windows protection stops and what a managed security product adds on top of it.

Which company size is ThreatDown Ultimate Server suitable for?

The deciding factor is not headcount but whether anyone is watching your servers at three in the morning. Companies with a few file, database and application servers and no night shift gain the most, because the managed service replaces staffing that would otherwise have to be hired.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector By sector
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Occasional ✓ ✓
Own staff monitoring servers at night ✕ Limited ✓
This product fits ✓ ✓ Partly

Does ThreatDown Ultimate Server meet the requirements of Swiss cybersecurity legislation?

The Swiss reporting obligation does not apply to every company: under the revised Information Security Act, designated operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Meeting that deadline depends on knowing quickly what happened on which machine, and this is where the product contributes: EDR records suspicious process activity on each server, the Nebula console retains the alert history, and the MDR analysts investigate the incident instead of leaving night-time triage to your own staff. Endpoint events can also be forwarded by syslog to a SIEM when a report has to be assembled from several systems. What the product does not do is file the report for you, and it sees nothing outside the protected endpoints, so network equipment, cloud services and identity systems remain uncovered, as does the internal decision process that determines who declares an incident reportable. This text is general information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.

Does ThreatDown Ultimate Server meet the requirements of European cybersecurity legislation?

No software product makes an organisation NIS 2 compliant, because the directive addresses management accountability, risk management processes and reporting duties rather than product features. NIS 2 requires measures in categories including risk analysis and information system security, incident handling, business continuity and backup management, supply chain security, vulnerability handling and disclosure, and basic cyber hygiene. This product supports incident handling through EDR telemetry and round-the-clock managed investigation, vulnerability handling through scheduled vulnerability scans and automated patch deployment, and cyber hygiene through application blocking and device control on server endpoints. It contributes nothing to business continuity and backup management, because the seven-day ransomware rollback restores files from a protected local cache on Windows machines and is not a backup system. Network segmentation, cryptography policy, supplier assessment and staff training are equally outside its scope and remain separate projects with separate budgets.

Does ThreatDown Ultimate Server help with security questionnaires from large customers?

Yes, for the endpoint and server sections, and not at all for the rest. It answers questions on malware protection for servers, on endpoint detection and response, on 24/7 security monitoring by a named provider, on vulnerability scanning intervals, on patch deployment for operating systems and third-party applications, on removable media control, and on whether protection status is centrally reported and exportable. It does not answer questions on email and phishing protection, on encryption of server volumes, on multi-factor authentication, on backup and restore testing, on network segmentation, or on secure software development. The two gaps that most often stop a questionnaire are email security and encryption, and the cheaper route is usually to add the vendor's own Email Security add-on to the same console rather than introducing a second management platform. Where the questionnaire asks about data location, note that most Nebula accounts are provisioned in the standard data centre, so check which one applies to yours before answering.

What is the difference between ThreatDown Elite Server and ThreatDown Ultimate Server?

The decisive difference is the depth of the managed service, not the protection engine, which is identical in both. Elite includes 24/7 Managed Detection and Response, while Ultimate is the MDR Plus tier, adding malware removal by the analyst team, root cause analysis, threat intelligence and dark web exposure monitoring, and a published service level agreement. Ultimate also includes identity threat detection and Premium Support, both of which are chargeable add-ons at the lower tiers. Note that ThreatDown restructured these bundles during 2026: DNS filtering was previously part of Ultimate and is now listed as an add-on for every tier, so verify the current scope on the datasheet before you compare offers.

CapabilityCoreAdvancedEliteUltimate
Endpoint protection and remediation ✓ ✓ ✓ ✓
Endpoint Detection and Response ✕ ✓ ✓ ✓
Patch management Scan only ✓ ✓ ✓
24/7 Managed Detection and Response ✕ ✕ ✓ ✓
MDR Plus with published SLA ✕ ✕ ✕ ✓
Premium Support included Add-on Add-on Add-on ✓
Email security Add-on Add-on Add-on Add-on

Which limitations should you know before buying?

The endpoint agent does not install on Windows Server Core installations or on non-persistent VDI machines, which rules out a share of hardened and virtualised server estates before anything else is discussed. Coverage on Linux is narrower than on Windows: operating system patching is available for Windows only, ransomware rollback works on Windows endpoints only, and SUSE Linux Enterprise Server 15 on x86_64 runs without the EDR component, so a mixed estate will not have the same feature set everywhere. Management is cloud-only, and the manufacturer states that it currently offers no on-premises alternative, which excludes air-gapped environments and organisations whose policy forbids a hosted console. On data location, a European data centre exists but is limited to EU-based accounts provisioned after 3 August 2026, so most accounts, including those created earlier, run in the standard data centre; ask which one your account will use before you sign. Finally, email security and DNS filtering are chargeable add-ons rather than bundle content, and mail servers therefore receive file-level protection but no mailbox-level phishing defence.

Windows Server 2025 vs. 2022 vs. 2019: is the upgrade worth it?
Compares the supported Windows Server versions and helps you judge whether an upgrade is due before you roll out new agents.

Frequently asked questions about ThreatDown Ultimate Server

Does the licence also cover workstations?

No. Server coverage is licensed separately from workstation coverage, and this package covers server endpoints. Note that every Linux machine registered in the console is counted as a server, regardless of its role.

Which Linux distributions are supported?

The agent supports Alma Linux, Amazon Linux 2, CentOS, Debian, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, SUSE Linux Enterprise Server 15 and Ubuntu LTS releases on x86_64, with a narrower list on ARM64. EDR availability differs per distribution and version, so check your exact release rather than the distribution family.

Does ransomware rollback replace a backup?

No. Rollback restores files that a non-trusted process modified within the last seven days, on Windows endpoints, from a protected local cache. It does nothing for hardware failure, deletion outside that window, theft, or a server that no longer boots, so a separate backup remains mandatory.

Data loss is expensive: how backups help you avoid outages
Sets out why a backup strategy remains necessary alongside security software and what an outage actually costs.

 

Meta Description

Server licences for the ThreatDown Ultimate bundle: EDR, patch management and 24/7 managed response in one cloud console. No Server Core.

Keywords

ThreatDown Ultimate Server, ThreatDown, Malwarebytes, Malwarebytes Endpoint Protection for Servers, server protection, endpoint detection and response, managed detection and response, patch management, ransomware rollback

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree