ThreatDown is an endpoint detection and response platform from ThreatDown offering EDR and managed detection and response in four tiers, from core antivirus protection through full 24/7 analyst coverage including identity threat detection.
Listing updated . Checked by MSP Software .
ThreatDown is an endpoint detection and response platform from ThreatDown for Windows, macOS, Linux, iOS and Android devices, combining multiple protective layers into a single lightweight agent managed through either the Nebula console for enterprises or OneView for MSPs. The platform delivers AI-powered threat detection built on two decades of machine learning, behavioural monitoring, automated remediation and ransomware rollback that recovers encrypted files up to seven days after an attack. It integrates vulnerability assessment, patch management and email security into one unified agent, rather than requiring separate point solutions. The underlying architecture uses a "one agent, one console, one operator" design philosophy to reduce complexity for both internal IT teams and MSP operations.
The four pricing tiers progress from Core AV (prevention-focused) through Advanced EDR (detection and recovery) to Elite MDR (24/7 analyst-led threat hunting and response) and Ultimate MDR Plus (with integrated identity threat detection). Each tier runs the same single agent across all supported platforms with full visibility through one unified console for simplified administration. Pricing is calculated per endpoint and adjusts by contract length, with a 20 percent discount for three-year contracts; exact pricing is not published and requires a quote (checked September 2026). The platform is purpose-built for managed service providers through OneView, which provides multi-tenant management and addresses MSP-specific requirements for scale and efficiency. ThreatDown maintains operations from a cloud-based infrastructure for always-on availability. Trial availability, integration depth with specific RMM and PSA platforms, supported deployment models and exact MSP pricing all require contacting sales for a customised quote based on endpoint count and contract term.
ThreatDown stands out for combining EDR, MDR and ITDR capabilities in one agent, which suits MSPs wanting unified endpoint visibility rather than stacking multiple point solutions. The four-tier model lets small shops start with preventative protection and scale to full 24/7 managed response, though exact per-endpoint pricing is not published and requires a quote. If you need published pricing and a clear per-seat model, consider SentinelOne or CrowdStrike Falcon. Before committing, confirm integration depth with your existing RMM and PSA tools, trial availability, and whether the MSP console (OneView) includes the specific features your clients need.
| Feature | Supported | Note |
|---|---|---|
| Behavioural detection | yes | AI-powered behavioural monitoring built into platform |
| Automated remediation | yes | Automated response and remediation with one-click recovery options |
| Rollback to pre-attack state | yes | Ransomware rollback to recover encrypted files up to seven days post-attack |
| USB and device control | unknown | No specific mention of USB or device control in available documentation |
| Application allow-listing | unknown | No specific mention of application allow-listing in available documentation |
| Offline protection | unknown | No specific mention of offline protection in available documentation |
| Threat hunting console | yes | Managed threat hunting and deep investigation included in Elite MDR and Ultimate tiers |
| Managed MDR add-on | yes | Full MDR service with 24/7 analyst coverage available; Elite and Ultimate tiers provide managed response |
| SIEM and SOAR integration | unknown | No specific SIEM or SOAR integration documentation found |
| RMM integration | unknown | OneView console supports multi-tenant MSP management but specific RMM integrations not documented |
| macOS support | yes | macOS is a supported platform across all tiers |
| Linux support | yes | Linux is a supported platform across all tiers |
| Feature | Supported | Note |
|---|---|---|
| 24-hour human-staffed SOC | yes | 24/7 human-staffed analyst team available in Elite MDR and Ultimate tiers; mean time to detect quoted as five minutes |
| Managed threat response and isolation | yes | Managed threat response and device isolation included in MDR tiers |
| Own endpoint telemetry agent | yes | Own endpoint agent collects behavioural telemetry across all tiers |
| Identity threat detection | yes | Identity threat detection and response (ITDR) included in Ultimate MDR Plus |
| Network monitoring | unknown | No specific network monitoring capability documented |
| Microsoft 365 monitoring | unknown | No specific Microsoft 365 monitoring documented; email security mentioned but scope unclear |
| Monthly threat reporting | unknown | No specific mention of monthly threat reporting in available documentation |
| PSA integration for ticketing | unknown | No PSA integration documentation found |
| Multi-tenant console | yes | OneView console is purpose-built for multi-tenant MSP management |
| Works with third-party EDR | unknown | Platform described as all-in-one agent; no mention of supporting third-party EDR |
| Dedicated incident response | yes | Included as part of managed response in Elite MDR and Ultimate tiers |
ThreatDown offers four tiers: Core AV focuses on prevention with AI-powered protection and ransomware rollback for basic endpoint security; Advanced EDR adds endpoint detection and deep investigation capabilities for threat identification; Elite MDR (the most popular tier) introduces 24/7 human-led threat monitoring and response with a five-minute mean time to detect; Ultimate MDR Plus combines all features and adds identity threat detection and response. All tiers run as a single lightweight agent supporting Windows, macOS, Linux, iOS and Android devices.
ThreatDown is built for MSPs through its OneView console, which provides multi-tenant management and is marketed specifically to managed service providers. The tiered approach allows MSPs to offer customers a choice from prevention-only through full managed response. The platform is designed for MSP efficiency with unified console administration and per-endpoint billing. However, exact MSP-specific features, trial availability and integration depth with existing RMM and PSA tools require contacting sales to confirm suitability before committing to a trial.
ThreatDown's website does not specify a free trial period or terms. The company invites prospects to request a personalized demo to see the platform in action, including real-time detection and one-click remediation, but a formal trial or no-cost evaluation requires contacting ThreatDown directly through their request-demo page or sales email.
ThreatDown's ransomware rollback feature, available from the Advanced EDR tier upward, can restore encrypted or modified files up to seven days after a ransomware attack. This allows organisations to recover systems without waiting for decryption keys or paying ransom, and is a differentiator from signature-based antivirus solutions.
ThreatDown pricing is tiered per endpoint and does not appear to be publicly published; instead, customers receive a quote based on the tier selected, number of devices, and contract length. The website references approximately ten dollars per device per month for the Elite MDR tier and offers a twenty percent discount for three-year contracts. Exact pricing requires contacting sales.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review