<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in ThreatDown Powered by Malwarebytes Core Server Corporate?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Endpoint Protection</strong> – Multi-layer prevention against signature-based, fileless and zero-day attacks.<br /> <strong>Incident Response</strong> – Linking Engine removes malware executables and all related changes.<br /> <strong>Vulnerability Assessment</strong> – Scheduled or on-demand scans for operating system and application flaws.<br /> <strong>Application Block</strong> – Prevents unauthorised programs from running on Windows servers.<br /> <strong>Nebula Cloud Console</strong> – One browser console for servers, workstations and policies.<br /> <strong>Important</strong> – Core has no EDR, ransomware rollback or patch management.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?</strong><br />Compares the current Windows Server versions and shows which ones still receive support, useful before you decide which servers to protect.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of ThreatDown Powered by Malwarebytes Core Server Corporate?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ThreatDown Core Server is the server-licensed variant of the ThreatDown Core bundle, the business line that Malwarebytes rebranded from Malwarebytes for Business in November 2023. Every protected server runs one lightweight agent and is managed centrally from the cloud-based Nebula console, together with any workstation licences in the same account.<br /> <br /> <strong>Mixed Server Estates</strong> – Covers Windows Server and common Linux distributions in parallel.<br /> <strong>Fast Rollout</strong> – Single agent installs without an on-premises management server.<br /> <strong>Fewer Reinfections</strong> – Remediation removes associated files and changes to prevent re-infection.<br /> <strong>Visible Vulnerabilities</strong> – Scan results show which servers need attention first.<br /> <strong>Role-Based Policies</strong> – Separate policies per server role avoid performance conflicts.<br /> <strong>Security Advisor</strong> –Scores the current configuration and lists concrete improvement steps.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows reaches its limits and what an additional layer adds in practice.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is ThreatDown Powered by Malwarebytes Core Server Corporate suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive question is not how many servers you run, but whether anyone has to reconstruct an incident afterwards. Core detects and blocks, and it records what it did, but it does not store the endpoint telemetry that an investigation or an audit answer usually needs.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Detection and response data on servers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Optional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Recommended</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Required</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Core Server Corporate meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every company that runs a server. Since 1 April 2025, affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. ThreatDown Core Server supports the first half of that duty: the agent detects and blocks malware on Windows and Linux servers, and the Nebula console keeps a dated record of detections and remediation actions that can be exported for the report. What it does not provide is the investigation depth a 24-hour report normally needs, because Core has no EDR telemetry, no suspicious activity monitoring and no root cause analysis, so reconstructing how an attacker entered and which systems were touched remains manual work. It also does not cover backup, encryption or identity protection, which are separate building blocks in most critical-infrastructure security concepts. This text describes product capabilities and is not legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Core Server Corporate meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation NIS 2 compliant, because the directive addresses governance, processes and evidence rather than tools. NIS 2 requires categories of measures: risk analysis and security policies, incident handling, business continuity including backup, supply chain security, vulnerability handling and disclosure, and basic cyber hygiene such as access control. ThreatDown Core Server contributes directly to two of them, namely malware prevention on servers as part of basic cyber hygiene, and vulnerability handling, because scheduled scans produce a documented list of missing operating system and application updates. It contributes partly to incident handling through detection alerts and console records of the remediation carried out. It does not cover business continuity and backup, supply chain security, access control or multi-factor authentication, and it stops halfway through vulnerability handling, since Core reports missing patches but does not install them.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ThreatDown Powered by Malwarebytes Core Server Corporate help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and it is worth knowing in advance which lines you can tick and which you cannot. It answers the questions about anti-malware on all servers, centrally managed protection with enforced policies rather than local settings, real-time protection on Windows and Linux servers, a defined remediation process, and a recurring vulnerability scan whose results can be exported as evidence. It does not answer the questions about continuous endpoint monitoring or an EDR capability, a documented patch process with installation deadlines, encryption of data at rest, multi-factor authentication, tested backup and restore, or 24x7 monitoring, because none of these functions is part of the Core bundle. If several of those lines block a contract, moving up within the same product family is usually the cheaper route than adding a second vendor: the Advanced bundle adds patch management, EDR and ransomware rollback under one agent, whereas a second security agent on the same server tends to create policy conflicts and performance problems.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ThreatDown Core and ThreatDown Advanced?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single most decisive difference is what happens after a detection. Core prevents, removes and reports, while Advanced adds endpoint detection and response with seven-day ransomware rollback, so encrypted or modified files can be restored and the attack path can be examined. The second difference is remediation of vulnerabilities: the manufacturer states explicitly that Core provides vulnerability scanning but not patching, so Core tells you which updates are missing and Advanced installs them. Managed detection and response is not part of either bundle and only starts at the Elite level.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Core</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Advanced</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint Protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Vulnerability scanning</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Patch management</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint Detection and Response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Ransomware Rollback</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed Detection and Response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Test: Best antivirus programs for Windows</strong><br />Shows how current protection solutions perform in independent tests and which criteria actually matter when comparing them.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The agent does not install on Windows Server Core installations, and non-persistent VDI is not supported, while persistent VDI is. Management is cloud-only, because the Nebula console has no on-premises or air-gapped option, so an isolated server network cannot be administered with it. Most Nebula accounts are provisioned in the manufacturer's standard data centre; a European data centre exists but applies only to a limited set of EU accounts provisioned after 3 August 2026, so buyers with a data-location requirement should confirm the placement of their account before rollout. Older Windows Server versions such as 2012 R2 and 2008 R2 are covered by a legacy installer that still receives protection updates but no new features. Core also has no mail-server-specific scanning for Exchange, no encryption management and no mobile coverage, because mobile devices are a separate ThreatDown product.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why a tested backup remains the recovery path when a security product prevents an attack but cannot roll it back.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about ThreatDown Powered by Malwarebytes Core Server Corporate</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it run alongside Microsoft Defender on a server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No, it replaces it. The manufacturer states that ThreatDown disables Windows Defender when it is installed, so you should plan the changeover as a replacement of the active protection layer rather than as an addition to it.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Are Windows and Linux servers protected by the same agent and console?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The same endpoint agent covers Windows Server 2016 to 2025 and the supported Linux server distributions, including Red Hat Enterprise Linux, Ubuntu LTS, Debian, SUSE Linux Enterprise Server 15, Rocky Linux and Alma Linux, on both x86_64 and ARM64. All of them appear in the same Nebula console with the same policy structure.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens on servers with special roles such as Exchange or SQL Server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The manufacturer documents that certain protection layers should not be enabled for specific server roles, including domain controllers, DNS, Exchange, SQL Server and terminal services, because they can cause performance or network problems. In practice this means you create a separate policy per server role instead of applying the workstation policy to servers.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-endpoint,sec-console" data-audience="b2b" data-count="3"> </div>