Th

ThreatDown

ThreatDown is an endpoint detection and response platform from ThreatDown offering EDR and managed detection and response in four tiers, from core antivirus protection through full 24/7 analyst coverage including identity threat detection.

Listing updated . Checked by MSP Software .

From the vendor

ThreatDown is an endpoint detection and response platform from ThreatDown for Windows, macOS, Linux, iOS and Android devices, combining multiple protective layers into a single lightweight agent managed through either the Nebula console for enterprises or OneView for MSPs. The platform delivers AI-powered threat detection built on two decades of machine learning, behavioural monitoring, automated remediation and ransomware rollback that recovers encrypted files up to seven days after an attack. It integrates vulnerability assessment, patch management and email security into one unified agent, rather than requiring separate point solutions. The underlying architecture uses a "one agent, one console, one operator" design philosophy to reduce complexity for both internal IT teams and MSP operations.

The four pricing tiers progress from Core AV (prevention-focused) through Advanced EDR (detection and recovery) to Elite MDR (24/7 analyst-led threat hunting and response) and Ultimate MDR Plus (with integrated identity threat detection). Each tier runs the same single agent across all supported platforms with full visibility through one unified console for simplified administration. Pricing is calculated per endpoint and adjusts by contract length, with a 20 percent discount for three-year contracts; exact pricing is not published and requires a quote (checked September 2026). The platform is purpose-built for managed service providers through OneView, which provides multi-tenant management and addresses MSP-specific requirements for scale and efficiency. ThreatDown maintains operations from a cloud-based infrastructure for always-on availability. Trial availability, integration depth with specific RMM and PSA platforms, supported deployment models and exact MSP pricing all require contacting sales for a customised quote based on endpoint count and contract term.

Our take

ThreatDown stands out for combining EDR, MDR and ITDR capabilities in one agent, which suits MSPs wanting unified endpoint visibility rather than stacking multiple point solutions. The four-tier model lets small shops start with preventative protection and scale to full 24/7 managed response, though exact per-endpoint pricing is not published and requires a quote. If you need published pricing and a clear per-seat model, consider SentinelOne or CrowdStrike Falcon. Before committing, confirm integration depth with your existing RMM and PSA tools, trial availability, and whether the MSP console (OneView) includes the specific features your clients need.

Read the EDR and XDR buying guide

How this listing is researched

Alternatives in EDR and XDR

All EDR and XDR software
N-able Managed EDR 24/7 SOC monitoring and response for N-able's EDR agent, sold by quote, not published pricing. No reviews yet Bitdefender GravityZone Unified EDR, XDR and MDR in one cloud console with consumption-based MSP pricing. No reviews yet FortiEDR Endpoint detection and response integrated with the Fortinet Security Fabric, quote-only pricing. No reviews yet Huntress Managed detection and response for MSPs, priced per endpoint from $7.99 a month direct. No reviews yet · from US$7.99 All alternatives to ThreatDown

Features

EDR and XDR features
FeatureSupportedNote
Behavioural detectionyesAI-powered behavioural monitoring built into platform
Automated remediationyesAutomated response and remediation with one-click recovery options
Rollback to pre-attack stateyesRansomware rollback to recover encrypted files up to seven days post-attack
USB and device controlunknownNo specific mention of USB or device control in available documentation
Application allow-listingunknownNo specific mention of application allow-listing in available documentation
Offline protectionunknownNo specific mention of offline protection in available documentation
Threat hunting consoleyesManaged threat hunting and deep investigation included in Elite MDR and Ultimate tiers
Managed MDR add-onyesFull MDR service with 24/7 analyst coverage available; Elite and Ultimate tiers provide managed response
SIEM and SOAR integrationunknownNo specific SIEM or SOAR integration documentation found
RMM integrationunknownOneView console supports multi-tenant MSP management but specific RMM integrations not documented
macOS supportyesmacOS is a supported platform across all tiers
Linux supportyesLinux is a supported platform across all tiers
MDR and SOC features
FeatureSupportedNote
24-hour human-staffed SOCyes24/7 human-staffed analyst team available in Elite MDR and Ultimate tiers; mean time to detect quoted as five minutes
Managed threat response and isolationyesManaged threat response and device isolation included in MDR tiers
Own endpoint telemetry agentyesOwn endpoint agent collects behavioural telemetry across all tiers
Identity threat detectionyesIdentity threat detection and response (ITDR) included in Ultimate MDR Plus
Network monitoringunknownNo specific network monitoring capability documented
Microsoft 365 monitoringunknownNo specific Microsoft 365 monitoring documented; email security mentioned but scope unclear
Monthly threat reportingunknownNo specific mention of monthly threat reporting in available documentation
PSA integration for ticketingunknownNo PSA integration documentation found
Multi-tenant consoleyesOneView console is purpose-built for multi-tenant MSP management
Works with third-party EDRunknownPlatform described as all-in-one agent; no mention of supporting third-party EDR
Dedicated incident responseyesIncluded as part of managed response in Elite MDR and Ultimate tiers

FAQ

How much does ThreatDown cost?
ThreatDown does not publish a list price. No MSP price reports have been approved yet.
Is ThreatDown cloud or on-premises?
ThreatDown is cloud-hosted; there is no on-premises version.
Who is ThreatDown for?
MSPs report using ThreatDown at sizes of 6-15, 16-50, 51-200 and 200+ technicians.
What are the four ThreatDown pricing tiers and what does each include?

ThreatDown offers four tiers: Core AV focuses on prevention with AI-powered protection and ransomware rollback for basic endpoint security; Advanced EDR adds endpoint detection and deep investigation capabilities for threat identification; Elite MDR (the most popular tier) introduces 24/7 human-led threat monitoring and response with a five-minute mean time to detect; Ultimate MDR Plus combines all features and adds identity threat detection and response. All tiers run as a single lightweight agent supporting Windows, macOS, Linux, iOS and Android devices.

Is ThreatDown suitable for MSPs?

ThreatDown is built for MSPs through its OneView console, which provides multi-tenant management and is marketed specifically to managed service providers. The tiered approach allows MSPs to offer customers a choice from prevention-only through full managed response. The platform is designed for MSP efficiency with unified console administration and per-endpoint billing. However, exact MSP-specific features, trial availability and integration depth with existing RMM and PSA tools require contacting sales to confirm suitability before committing to a trial.

Does ThreatDown offer a free trial?

ThreatDown's website does not specify a free trial period or terms. The company invites prospects to request a personalized demo to see the platform in action, including real-time detection and one-click remediation, but a formal trial or no-cost evaluation requires contacting ThreatDown directly through their request-demo page or sales email.

What is ThreatDown's ransomware rollback capability?

ThreatDown's ransomware rollback feature, available from the Advanced EDR tier upward, can restore encrypted or modified files up to seven days after a ransomware attack. This allows organisations to recover systems without waiting for decryption keys or paying ransom, and is a differentiator from signature-based antivirus solutions.

How is ThreatDown priced and what does per-endpoint cost?

ThreatDown pricing is tiered per endpoint and does not appear to be publicly published; instead, customers receive a quote based on the tier selected, number of devices, and contract length. The website references approximately ten dollars per device per month for the Elite MDR tier and offers a twenty percent discount for three-year contracts. Exact pricing requires contacting sales.

ThreatDown reviews

Reviews are moderated. How reviews work.

Be the first MSP to review ThreatDown

Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.

Write the first review

Sign in or create an account

Use your work email to review tools, share pricing and manage your vendor profile.

By continuing, you agree to our terms and acknowledge our privacy policy.