<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in ThreatDown Powered by Malwarebytes Advanced Server Corporate?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Endpoint Protection</strong> – Blocks malware, exploits and ransomware behaviour on server roles.<br /> <strong>Endpoint Detection and Response</strong> – Suspicious activity monitoring, endpoint isolation and Active Response Shell.<br /> <strong>7-day Ransomware Rollback</strong> – Restores files changed by ransomware within seven days.<br /> <strong>Vulnerability and Patch Management</strong> – Scans and patches operating system and third-party applications.<br /> <strong>Nebula cloud console</strong> – Separate server policies, groups, exclusions and CEF syslog export.<br /> <strong>Important</strong> – Drive encryption and mailbox-level Exchange scanning are not included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of ThreatDown Powered by Malwarebytes Advanced Server Corporate?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ThreatDown Advanced Server is the server variant of the Advanced bundle from ThreatDown powered by Malwarebytes, the business line that was sold as Malwarebytes for Business until the rebrand in November 2023. Every protected server is managed from the cloud-based Nebula console, using server policies, groups and exclusions that are kept separate from the workstation configuration.<br /> <br /> <strong>One agent per server</strong> – Protection, EDR and patching run in a single agent.<br /> <strong>Role-aware configuration</strong> – Documented exclusions for Exchange, SQL, DNS and domain controllers.<br /> <strong>Recovery without VSS</strong> – Rollback uses protected local copies, not shadow volume snapshots.<br /> <strong>Linux server coverage</strong> – One console for Windows Server and major Linux distributions.<br /> <strong>Evidence for audits</strong> – Detection log kept 365 days, exportable to SIEM.<br /> <strong>Guided alert triage</strong> – Managed Threat Hunting escalates only the critical alerts.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows reaches its limits and what a separate security layer adds on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is ThreatDown Powered by Malwarebytes Advanced Server Corporate suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The bundle is built for organisations that run a manageable number of servers and do not have a dedicated security team watching alerts around the clock. A company with three domain controllers, a file server and an Exchange server gets full coverage from one console. Once someone has to answer alerts at three in the morning, the technology in Advanced is no longer the limiting factor — the staffing is, and that is what the Elite bundle addresses.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Likely</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Increasing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Around-the-clock handling of server alerts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Advanced Server Corporate meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so the first question is whether your organisation falls into that group at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the technical facts have to be assembled on the first day, not during the following week. ThreatDown Advanced Server supports that deadline in a concrete way: the Nebula Detection Log retains records for 365 days, the Events log covers the previous 30 days, and EDR suspicious activity data shows which process ran on which server and what it changed, which is exactly the material a first report needs. What the product does not do is decide whether an incident is reportable, produce the report itself, or cover the organisational side of the obligation — there is no case management, no defined escalation path to management, and no evidence that backups exist or have been tested. This description is technical and is not legal advice; whether your organisation is subject to the reporting obligation should be clarified with your own legal advisers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Advanced Server Corporate meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes a company compliant with the NIS 2 Directive, because the directive addresses organisations and their management bodies and requires appropriate technical, operational and organisational measures. The measure categories the directive names include risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, cryptography, access control and multi-factor authentication. ThreatDown Advanced Server contributes materially to three of them: incident handling through EDR detection, endpoint isolation and the Active Response Shell, vulnerability handling through the vulnerability assessment and patch management modules, and asset visibility through the endpoint inventory in Nebula. It contributes nothing to business continuity and backup, cryptography, multi-factor authentication, supply chain governance or staff training, and its scope stops at servers and workstations — network appliances, cloud workloads and identity systems are outside it. Because each member state transposes the directive into its own law, the obligations that actually apply to your organisation follow from the legislation of the country in which you operate.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Advanced Server Corporate help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the endpoint and server section of a questionnaire, and not for the rest of it. It answers the items on malware protection for servers with central management, on the presence of an EDR capability with isolation and response actions, on a documented patch process with reporting, on regular vulnerability scanning, on application control, and on log retention with export to a SIEM in CEF format. It also covers role-based console access, since the user audit log records administrator changes for 90 days. It does not answer the items on backup and restore testing, encryption of data at rest, multi-factor authentication, email and phishing defence, network segmentation, secure development, supplier management, or your own certification status such as ISO 27001. Where the gap is around-the-clock monitoring, moving up to the Elite bundle within the same family is usually cheaper and far less disruptive than bolting a second vendor's managed service onto the same estate; encryption and email items are best closed with the separate ThreatDown modules or with tooling you already license from Microsoft, and backup remains an independent product decision.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers why a backup and restore concept remains a separate requirement that endpoint security and rollback features do not replace.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ThreatDown Core and ThreatDown Advanced?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is EDR. Core prevents and scans, but it cannot detect suspicious behaviour after the fact, cannot isolate a compromised server, and cannot undo an encryption event. In practical terms Core will tell you that a server is missing patches without being able to install them, because Core includes vulnerability scanning but not patch management. Elite adds no technology that Advanced lacks — it adds people, in the form of 24x7x365 Managed Detection and Response, and Ultimate layers DNS Filtering and Premium Support on top of Elite.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Core</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Advanced</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Elite</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint Protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Vulnerability Assessment</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patch Management</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">EDR with 7-day Ransomware Rollback</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed Threat Hunting</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed Detection and Response, 24x7x365</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">European data centre for the console</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Where your console data is processed is the point to check first: most Nebula accounts are provisioned in the standard data centre, and the European data centre is available only to a limited set of EU-based accounts provisioned after 3 August 2026, recognisable by a login URL containing euc1. Platform coverage is not uniform either — Windows Server Core installations and non-persistent VDI are not supported at all, SUSE Linux Enterprise Server 15 on x86_64 runs Endpoint Protection but not EDR, and Ransomware Behaviour Protection is unsupported on RDP, Hyper-V and terminal services roles, which is precisely where many organisations expect it. Older Windows Server versions from 2012 R2 back to 2008 can only be deployed with the legacy installer, which keeps receiving protection updates but no new features. On an Exchange server the agent protects the operating system rather than the mail flow, so there is no transport-level or mailbox-level scanning and Microsoft's own antivirus exclusions still have to be applied. The follow-up purchases that come up most often are Drive Encryption, Email Security and DNS Filtering, which are separate modules, and managed monitoring, which requires the Elite bundle.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?</strong><br />Helps you judge whether your older server versions should be upgraded before you standardise a security agent across the estate.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about ThreatDown Powered by Malwarebytes Advanced Server Corporate</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the agent be installed on a Windows Server Core installation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Server Core installations are not supported, so a full installation with the desktop experience is required. Non-persistent VDI is also unsupported, while persistent VDI works normally.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which Linux servers are covered, and does EDR work on all of them?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Endpoint Protection covers Alma Linux, Amazon Linux 2, CentOS, Debian, Oracle Linux 10, Red Hat Enterprise Linux, Rocky Linux, SUSE Linux Enterprise Server 15 and Ubuntu LTS releases, on x86_64 and on ARM64. EDR is the exception: it is not available on SUSE Linux Enterprise Server 15 on x86_64, and it requires Linux kernel 3.10 or newer plus DKMS on Amazon Linux, CentOS and Red Hat.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How long is data kept in the Nebula console?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Detection Log keeps records for 365 days, the Events activity log for 30 days, and the user audit log for 90 days. For longer retention, Nebula forwards threat events to a syslog server in CEF format through a promoted Windows endpoint, or exports detection data to Google Chronicle SIEM.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the ransomware rollback replace a backup?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. Rollback restores files that a detected ransomware process changed on that specific device, within a seven-day window, using protected local copies rather than Windows shadow volume snapshots. It does nothing for hardware failure, accidental deletion, a destroyed server or a corrupted database, so a backup concept remains a separate requirement.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-edr,sec-endpoint" data-audience="b2b" data-count="3"> </div>