<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Malwarebytes Endpoint Detection &amp; Response?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Nebula cloud console</strong> – Central policies, groups and reporting for every managed endpoint.<br /> <strong>Suspicious activity monitoring</strong> – Behavioural detection mapped to the MITRE ATT&amp;CK framework.<br /> <strong>Ransomware rollback</strong> – Restores encrypted Windows files up to seven days back.<br /> <strong>Three isolation modes</strong> – Network, process and desktop isolation, manual or automatic.<br /> <strong>Active Response Shell</strong> – Remote command shell for Windows, macOS and Linux.<br /> <strong>Important</strong> – Patch management, drive encryption and DNS filtering are separate modules.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Malwarebytes Endpoint Detection &amp; Response?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Malwarebytes moved its business products to the ThreatDown brand in November 2023, so this product appears as ThreatDown Endpoint Detection &amp; Response in the vendor's current documentation. It installs one agent per device and is administered centrally, in the Nebula console for a single organisation or in the multi-tenant OneView console used by service providers.<br /><br /> <strong>One agent</strong> – Prevention, detection and response ship in a single installer.<br /> <strong>Rollback instead of restore</strong> – Reverses ransomware damage without opening a backup set.<br /> <strong>Faster containment</strong> – Critical alerts can isolate a device automatically.<br /> <strong>Root cause visibility</strong> – Process graphs show how the infection actually started.<br /> <strong>Remote remediation</strong> – Clean and inspect home office devices over the internet.<br /> <strong>Evidence for audits</strong> – Detection records stay available for 365 days.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows stops and why companies add a second, centrally managed layer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Malwarebytes Endpoint Detection &amp; Response suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Company size decides less here than sector and staffing. Swiss reporting duties follow the sector, not the headcount, while the practical question for EDR is whether anyone in the organisation reads and triages the alerts it produces.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Staff available to triage EDR alerts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Malwarebytes Endpoint Detection &amp; Response meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, so most ordinary Swiss companies are affected indirectly, as suppliers, rather than directly. Those who are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the facts have to be assembled the same working day. This product supplies part of that material: the suspicious activity view records when the behaviour was first seen, which processes and files were involved and which MITRE ATT&amp;CK techniques were triggered, and detection records remain retrievable for 365 days. It does not cover the rest of the duty. There is no reporting form, no case management, no notification workflow towards BACS, and no visibility outside the endpoint, so incidents on firewalls, network equipment, cloud services or OT systems will not appear in this console at all. This description is not legal advice, and which obligations apply to your organisation should be confirmed with qualified counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Malwarebytes Endpoint Detection &amp; Response meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and documented processes, not software features. NIS 2 requires a set of risk-management measures that includes incident handling, business continuity and backup management, supply chain security, access control and identity handling, vulnerability treatment, cryptography, and staff awareness training. This product contributes to two of those categories in a concrete way: incident handling, through behavioural detection, endpoint isolation and remote remediation, and vulnerability treatment in a partial sense, since vulnerability assessment and patch deployment are separate modules rather than part of the EDR function. The remaining categories are not addressed. Backup and restore, identity and access control, multi-factor authentication, cryptography beyond the separately licensed Windows drive encryption module, supplier assessment and user training all have to be covered elsewhere, and endpoint telemetry alone will not satisfy an auditor asking how continuity is tested.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Malwarebytes Endpoint Detection &amp; Response help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the endpoint chapter, and only for that chapter. It answers the questions on managed anti-malware coverage across all workstations and servers, behavioural detection beyond signatures, the ability to isolate a compromised device, remote forensic access through the response shell, threat hunting across thirty days of endpoint events, and a detection history kept for 365 days that can be exported as evidence. It does not answer the questions that usually sit next to those. Multi-factor authentication, identity monitoring, backup and tested restore, patch installation with an SLA, disk encryption on anything other than Windows workstations and only with the separate module, email and phishing filtering, mobile device management, penetration testing, and 24/7 monitoring by named analysts are all outside its scope, and so is the question about where console data is processed, which should be put to the vendor in writing before signature. Where the gaps matter commercially, moving up within the same family is usually the cheaper route than adding a second vendor: patch management, drive encryption, DNS filtering, mobile security and the managed detection service are all administered from the same console and the same agent, whereas a second product means a second agent, a second console and a second set of exclusions to maintain.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Endpoint Protection and Endpoint Detection &amp; Response?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is what happens after something gets through: Endpoint Protection blocks and quarantines, while Endpoint Detection &amp; Response additionally records what the process did and lets you reverse it. Both use the identical agent and the identical console, so the upgrade is a licence and policy change rather than a redeployment. Endpoint Protection is the right level where an administrator only wants malware stopped and cleaned. Endpoint Detection &amp; Response is the right level where someone has to answer how an infection started, contain a device within minutes, or recover files that were already encrypted.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Endpoint Protection</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Endpoint Detection &amp; Response</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Next-generation antivirus</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Suspicious activity monitoring</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Ransomware rollback</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows only</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint isolation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Threat hunting over 30 days</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Remote response shell</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patch management and drive encryption</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Separate module</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Separate module</td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />Compares the current Windows antivirus products and shows where pure prevention ends and detection and response begins.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Ransomware rollback is a Windows feature only, and its window is configurable between one and seven days with three days as the delivered default, so a Mac or Linux device gets detection and isolation but no file recovery. Isolation is likewise uneven across platforms: network and process isolation work broadly, while desktop isolation, the mode that locks the user out of the screen, exists on Windows only, and process isolation is not available on macOS 10.13 and 10.14. Flight Recorder search, the function that lets you look back over thirty days of process, file, registry and network events, is switched off by default and has to be enabled in the policy, which is worth checking during the pilot rather than during an incident. Server Core installations and non-persistent VDI are not supported, all Linux devices are counted as servers regardless of their role, and behavioural monitoring on servers is a separate policy switch that adds load to the machine. The console itself is cloud-only, with Nebula for a single organisation and OneView for service providers managing several customers; there is no on-premises variant, so the data processing location is determined by the vendor and not by you.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Sets out why rollback and backup solve different problems and where a recovery plan still needs a real backup.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Malwarebytes Endpoint Detection &amp; Response</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ransomware rollback replace a backup?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Rollback works from a cache held on the endpoint itself, limited by a configurable share of free disk space and by a maximum file size, so files above that size are never copied. If the device is wiped, stolen or its disk fails, the cache goes with it, which is why rollback shortens recovery after an encryption event but does not remove the need for a separate backup.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Are servers covered as well as workstations?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, the same agent runs on Windows Server and on supported Linux distributions, and every Linux device is counted as a server in the console regardless of what it does. Behavioural monitoring on servers is enabled by its own policy toggle, and rollback on a server additionally requires that toggle to be active. Server Core installations are not supported.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can detections be forwarded to a SIEM?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, threat events can be sent in CEF format to a syslog server or SIEM, and there is also a dedicated integration for Google Chronicle. The syslog path requires one Windows endpoint to be promoted as the communication device, and it buffers only the last 24 hours if it cannot reach the console, so a longer outage will leave a gap in the exported data.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-endpoint" data-audience="b2b" data-count="3"> </div>