<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in ThreatDown Core Corporate?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Endpoint Protection</strong> – Multi-layer prevention against signature-based, fileless and zero-day attacks.<br /><strong>Vulnerability Assessment</strong> – Scheduled or on-demand scans for operating system and application vulnerabilities.<br /><strong>Application Block</strong> – Blocks unauthorised programs so acceptable-use policies are actually enforced.<br /><strong>Incident Response</strong> – Linking Engine removes malware executables and every associated change.<br /><strong>Nebula Cloud Console</strong> – One browser console and one agent for all endpoints.<br /><strong>Important</strong> – EDR, Ransomware Rollback and Patch Management need the Advanced bundle.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of ThreatDown Core Corporate?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ThreatDown Core Corporate is the entry bundle of the ThreatDown range, the business line that Malwarebytes rebranded from Malwarebytes for Business in November 2023. Every protected device runs a single agent and is managed centrally from the cloud-based Nebula console, or from OneView if the environment is run by a managed service provider.<br /><br /><strong>One Agent</strong> – Covers Windows workstations, macOS devices and Linux servers.<br /><strong>Faster Cleanup</strong> – Automatic remediation removes leftovers that cause repeat infections.<br /><strong>Fewer Helpdesk Tickets</strong> – Application blocking keeps unwanted software off company devices.<br /><strong>Clear Patch Priorities</strong> – Scan results show which machines need attention first.<br /><strong>Central Policy Control</strong> – One policy replaces manual configuration on every single endpoint.<br /><strong>Security Advisor Score</strong> – Console score shows where your configuration is still weak.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows stops and what a centrally managed endpoint product adds on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is ThreatDown Core Corporate suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Core Corporate fits organisations that need managed, uniform malware prevention across a fleet of workstations and can accept that investigating an incident afterwards is limited. Once a company has to reconstruct how an attack unfolded, or has to prove it can restore encrypted files, Core reaches its boundary and the Advanced bundle becomes the realistic choice.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Detection history for incident analysis</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Required</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Core Corporate meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most buyers of an entry endpoint bundle are affected only indirectly through customers or contracts. Those who are affected must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the discovery itself has to happen quickly and has to be documented. Core Corporate supports that first step: the Nebula console raises alerts for blocked and quarantined threats, records the remediation the Linking Engine performed, and produces exportable reports that show what was found on which device and when. What Core does not support is the part of the report that describes how the attack entered and spread, because the endpoint detection and response module, the suspicious activity monitoring and the extended detection history are only part of the Advanced bundle and above. Core also has no automated patching, so a vulnerability it reports still has to be closed by another tool or by hand. This description is a product overview and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Core Corporate meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive addresses organisational risk management rather than a specific tool. NIS 2 requires measure categories such as risk analysis and security policies, incident handling, business continuity including backup and crisis management, supply chain security, security in acquisition and maintenance including vulnerability handling, basic cyber hygiene, access control and the use of cryptography. Core Corporate contributes to three of those: cyber hygiene through multi-layer malware prevention on every managed device, vulnerability handling through scheduled scans that identify outdated operating system and application components, and the technical side of incident handling through automatic remediation and a central alert record. It contributes nothing to business continuity and backup, nothing to access control or cryptography, and nothing to supply chain security, and its contribution to vulnerability handling stops at reporting because the bundle cannot install patches. Buyers who need the vulnerability cycle closed inside the same product, rather than documented and handed to a separate process, should look at the Advanced bundle, which adds Patch Management.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Best antivirus programs for Windows 2025</strong><br />Compares the protection products currently available for Windows and shows which criteria actually separate them in practice.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Core Corporate help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, but only for the prevention and asset-hygiene block of a typical questionnaire. Core Corporate lets you answer that anti-malware protection is deployed on all managed endpoints, that it is centrally administered rather than left to users, that unauthorised applications can be blocked by policy, that vulnerability scans run on a defined schedule, and that malware removal is automated and logged. On the vendor side, Malwarebytes holds an ISO 27001 certification and a SOC 2 attestation covering security, availability and confidentiality, and makes those reports available under a signed non-disclosure agreement, which answers the third-party assurance questions many questionnaires now include. The questions Core cannot answer are equally specific: there is no 24x7 monitoring, no detection telemetry retained for forensic reconstruction, no endpoint isolation, no patch deployment with a measurable remediation time, no endpoint encryption, no multi-factor authentication, no email filtering and no backup or restore capability. If a questionnaire fails you on those points, moving up within the same family is usually cheaper and simpler than adding a second vendor: Advanced closes the detection, rollback and patching gaps in the same console and with the same agent, and Elite adds the managed 24x7 monitoring. Encryption, multi-factor authentication and backup are outside the ThreatDown range entirely and will always need a separate product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ThreatDown Core and ThreatDown Advanced?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that Advanced adds Endpoint Detection and Response, and with it the seven-day Ransomware Rollback that restores files encrypted during an attack. Core prevents and cleans up, but once something gets through it cannot show you the attack path or turn the clock back. The second difference matters just as much in daily work: Core reports vulnerabilities and Advanced patches them, which is the point at which vulnerability management stops being a list somebody has to work through manually. Advanced also adds Managed Threat Hunting, where alerts are correlated against threat intelligence and only the critical ones are escalated with response guidance. Both bundles use the same single agent and the same console, so upgrading later does not mean redeploying anything.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ThreatDown Core</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ThreatDown Advanced</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint Protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Vulnerability Assessment</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Application Block</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Incident Response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint Detection and Response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Ransomware Rollback</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patch Management</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed Threat Hunting</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most relevant point for Swiss and European buyers concerns where the console data lives. ThreatDown operates a European data centre for Nebula, but according to the manufacturer this applies to EU-based customers with accounts provisioned after 3 August 2026 and covers only a limited set of accounts, while most tenants run in the standard data centre. Swiss buyers are not automatically in scope, so if the processing location matters for your contracts, confirm before rollout which data centre your tenant is assigned to; the console login address indicates it. The console itself is cloud-based, which rules the product out for organisations that require an on-premises or air-gapped management platform. Coverage is the second thing that causes follow-up purchases: the workstation licence does not cover servers, which are licensed through ThreatDown for Server, and mobile devices need the separate Mobile Security product, even though all of them are managed in the same console. Windows Server Core installations and non-persistent VDI are not supported by the agent, and DNS Filtering, Email Security and Premium Support remain paid add-ons in every bundle.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Shows why a working backup remains necessary even with endpoint protection in place, since Core has no ransomware rollback.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about ThreatDown Core Corporate</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Core Corporate protect servers as well as workstations?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The ThreatDown agent runs on Windows Server 2016 through 2025 and on a wide range of Linux server distributions including Red Hat Enterprise Linux, Ubuntu LTS, Debian, SUSE Linux Enterprise Server, Alma Linux and Rocky Linux. Servers are, however, licensed through the separate ThreatDown for Server product, so a workstation bundle alone will not cover them. Both appear in the same console once licensed.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Nebula and OneView consoles?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Nebula is the single-tenant console used by companies managing their own environment. OneView is the multi-tenant console for managed service providers who need to switch between several customer environments from one login. The agent on the endpoint is identical in both cases.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which client operating systems does the ThreatDown agent support?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">On the workstation side the agent supports Windows 11, including ARM devices, and Windows 10 from version 1607 onwards, as well as macOS from Big Sur 11 up to Tahoe 26 on both Intel and Apple Silicon hardware. Older Windows versions can still be protected through a legacy installer that continues to receive protection updates but no new features.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>