ThreatDown bundles are the packaged editions in which Malwarebytes sells ThreatDown business security directly. The online store offers four bundles, Core, Advanced, Elite and Ultimate, each bought for a number of devices and a number of years.[1] Servers and mobile devices are covered by add-ons, and two products have their own metrics: Email Security per email address and ITDR per identity Account.[1][2] The upper bundles include managed services. Those services carry extra conditions under the ThreatDown Managed Services Agreement: they must cover every endpoint, and any growth in endpoints must be paid for.[3] For the vendor overview, see Malwarebytes licensing.
Editions
| Bundle | Tag line on the pricing page | Catalog |
|---|---|---|
| Core | “Core Next-Gen AV”: AI-powered protection that stops threats before they get in[1] | ThreatDown Core |
| Advanced | “Advanced EDR”: advanced detection and recovery with built-in ransomware rollback[1] | ThreatDown Advanced |
| Elite | “Elite MDR”: 24/7 human-led threat monitoring and response[1] | ThreatDown Elite |
| Ultimate | “Ultimate MDR Plus”: comprehensive, fully managed protection across devices and identities[1] | ThreatDown Ultimate |
The pricing page lists features available across the bundles. They include incident response, next-gen antivirus, device control, application block, vulnerability assessment, browser phishing protection, ransomware rollback for up to 7 days, EDR, patch management, host-based firewall management, drive encryption, managed threat hunting, MDR, MDR Plus, ThreatDown AI and ITDR.[1] Each bundle is sold per year, with a stated saving for a three-year term.[1] Server Protection, Mobile Security for Chromebook, Android, iOS and iPadOS, and Premium Support appear as add-ons.[1]
Malwarebytes for Teams is a separate, simpler line for very small businesses. It is sold as Sole proprietor (3 devices), Boutique business (10 devices) and Small office (20 devices) annual plans.[8] It may be used only by businesses with no more than 25 Devices.[9] Catalog: Malwarebytes for Teams.
Metrics
Bundles are counted in Devices. The EULA counts each operating system instance on a partitioned or virtualized machine as a Device.[2] Email Security is licensed per email address, not per Device.[2] ITDR is licensed per Account. Every Account that exists in connected identity providers at any point in the term needs a licence.[2]
Counting / floors
Bundles give one seat count. In the Nebula console, an account that buys individual subscriptions can have different seat counts per product, for example 500 EDR seats and 25 DNS Filtering seats. An account with a bundle has the same number of seats for every subscription in it.[6] With individual subscriptions, a feature enabled in more policies than its seats allow shows as over-use. ThreatDown attributes this to policy and group misconfiguration. It recommends removing endpoints inactive for 30 days or more, scoping policies, and only then buying more licences.[6] Catalog: Nebula seats are allocated per subscription.
Servers. Bundled software may not run on a server operating system unless it is a ThreatDown server product, which in practice means the Server Protection add-on.[2][1] Catalog: Server operating systems need a ThreatDown server product.
Reading consumption. The Nebula Account page lists each subscription’s status, expiry date and seats used out of seats purchased.[7] For ITDR, the console count is not enough on its own. The EULA counts every Account that existed at any point in the term, including disabled ones, so the identity provider’s history matters more than today’s active-user list.[2] Catalog: Nebula shows seats used against seats purchased; ITDR covers every Account that exists at any point in the term.
Upgrades and billing. Website bundle purchases are managed by any Super Admin through a billing portal. The portal covers invoices, payment methods and auto-renewal, and the Account page has a “Request upgrade” button for moving to a higher tier.[7]
Floors. No minimum quantity appears in the EULA. The store’s device selector defaults to 5 devices.[1]
Managed services
The Managed Services Agreement governs ThreatDown MDR and Managed Threat Hunting (MTH). It does not license software, which stays under the Software License Agreement.[3]
All endpoints, with EDR. Managed Services need an active ThreatDown EDR subscription on all of the customer’s endpoints. They are quoted and sold only for deployment on all endpoints.[3] The MDR service description says MDR needs active MDR and EDR subscriptions implemented on 100% of the customer’s endpoints.[4] A partial deployment is therefore outside the commercial model, not just a quality issue. Catalog: MDR is sold only for all endpoints and requires EDR on every endpoint.
Growth and shrinkage. If the customer adds endpoints during the term, it must pay for Managed Services on them for the rest of the term. Removing endpoints does not reduce the cost or give any refund or credit.[3] This is a one-way true-up. Catalog: Added endpoints are paid for the rest of the MDR term; removals give no credit. See subscription and consumption licensing.
Term and renewal. The term follows the Sales Order Form, or one year by default. Unlike software subscriptions, managed services orders do not renew automatically unless the customer opts in. Opted-in renewals keep the same term and price unless ThreatDown gives 60 days’ notice of a price change.[3] Catalog: Managed Services do not auto-renew unless opted in.
MSPs. An MSP accepting the agreement binds its end customers. It is responsible for implementing recommendations and making sure its customers meet the prerequisites.[3] Customers who buy through a reseller or MSP pay that party, not ThreatDown.[3]
MDR Plus SLA credits. MDR Plus includes a notification SLA for Critical Incidents. It does not apply during the first 90 days after activation.[4] Credits are capped at 5% of the monthly service fee. They can be claimed no more than three times a year, and can be used only as a discount on renewing the same MDR Plus service or a successor bundle that includes it.[4]
Support tiers
The Support Service Agreement gives Incident Response, Endpoint Protection, EDR and Education Site License customers Standard support for the term of their subscription.[5] Customers receive the tier named in their purchasing document. The agreement’s response-time table also lists Premium, Technical Account Manager and MSP tiers, plus legacy Gold and Silver tiers that are no longer sold.[5] Catalog: Standard support is included with ThreatDown subscriptions; Premium Support.
Virtualization & partitioning
Bundles follow the Device rule: each virtual or partitioned operating system instance is a Device.[2]
Out of scope
- Regional list prices and promotions.
- Detailed feature-by-bundle matrices, which the pricing page renders dynamically.
- The Managed Threat Hunting service description and MDR operational responsibilities beyond licensing.
- Distributor and partner pricing.