# ThreatDown

> EDR and MDR combining AI-powered detection, ransomware rollback and 24/7 managed response.

ThreatDown is an endpoint detection and response platform from ThreatDown offering EDR and managed detection and response in four tiers, from core antivirus protection through full 24/7 analyst coverage including identity threat detection. Listing updated 6 September 2026. Checked by MSP Software 6 September 2026.

- Page: https://mspsoftware.net/software/threatdown
- Vendor: ThreatDown, https://mspsoftware.net/vendors/threatdown, website https://www.threatdown.com/
- Categories: EDR and XDR (primary), MDR and SOC
- Free version: no.
- Deployment: cloud. Platforms: Windows, macOS, Linux, iOS and Android.
- Support: email, help desk and knowledge base. Training: documentation, videos and webinars.

## From the vendor

ThreatDown is an endpoint detection and response platform from ThreatDown for Windows, macOS, Linux, iOS and Android devices, combining multiple protective layers into a single lightweight agent managed through either the Nebula console for enterprises or OneView for MSPs. The platform delivers AI-powered threat detection built on two decades of machine learning, behavioural monitoring, automated remediation and ransomware rollback that recovers encrypted files up to seven days after an attack. It integrates vulnerability assessment, patch management and email security into one unified agent, rather than requiring separate point solutions. The underlying architecture uses a "one agent, one console, one operator" design philosophy to reduce complexity for both internal IT teams and MSP operations. The four pricing tiers progress from Core AV (prevention-focused) through Advanced EDR (detection and recovery) to Elite MDR (24/7 analyst-led threat hunting and response) and Ultimate MDR Plus (with integrated identity threat detection). Each tier runs the same single agent across all supported platforms with full visibility through one unified console for simplified administration. Pricing is calculated per endpoint and adjusts by contract length, with a 20 percent discount for three-year contracts; exact pricing is not published and requires a quote (checked September 2026). The platform is purpose-built for managed service providers through OneView, which provides multi-tenant management and addresses MSP-specific requirements for scale and efficiency. ThreatDown maintains operations from a cloud-based infrastructure for always-on availability. Trial availability, integration depth with specific RMM and PSA platforms, supported deployment models and exact MSP pricing all require contacting sales for a customised quote based on endpoint count and contract term.

## Our take

ThreatDown stands out for combining EDR, MDR and ITDR capabilities in one agent, which suits MSPs wanting unified endpoint visibility rather than stacking multiple point solutions. The four-tier model lets small shops start with preventative protection and scale to full 24/7 managed response, though exact per-endpoint pricing is not published and requires a quote. If you need published pricing and a clear per-seat model, consider SentinelOne or CrowdStrike Falcon. Before committing, confirm integration depth with your existing RMM and PSA tools, trial availability, and whether the MSP console (OneView) includes the specific features your clients need.

## Pricing

ThreatDown does not publish a list price.

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| Behavioural detection | yes | AI-powered behavioural monitoring built into platform |
| Automated remediation | yes | Automated response and remediation with one-click recovery options |
| Rollback to pre-attack state | yes | Ransomware rollback to recover encrypted files up to seven days post-attack |
| Threat hunting console | yes | Managed threat hunting and deep investigation included in Elite MDR and Ultimate tiers |
| Managed MDR add-on | yes | Full MDR service with 24/7 analyst coverage available; Elite and Ultimate tiers provide managed response |
| macOS support | yes | macOS is a supported platform across all tiers |
| Linux support | yes | Linux is a supported platform across all tiers |
| 24-hour human-staffed SOC | yes | 24/7 human-staffed analyst team available in Elite MDR and Ultimate tiers; mean time to detect quoted as five minutes |
| Managed threat response and isolation | yes | Managed threat response and device isolation included in MDR tiers |
| Own endpoint telemetry agent | yes | Own endpoint agent collects behavioural telemetry across all tiers |
| Identity threat detection | yes | Identity threat detection and response (ITDR) included in Ultimate MDR Plus |
| Multi-tenant console | yes | OneView console is purpose-built for multi-tenant MSP management |
| Dedicated incident response | yes | Included as part of managed response in Elite MDR and Ultimate tiers |

## Alternatives

- N-able Managed EDR: 24/7 SOC monitoring and response for N-able's EDR agent, sold by quote, not published pricing. https://mspsoftware.net/software/n-able-managed-edr
- Bitdefender GravityZone: Unified EDR, XDR and MDR in one cloud console with consumption-based MSP pricing. https://mspsoftware.net/software/bitdefender-gravityzone
- FortiEDR: Endpoint detection and response integrated with the Fortinet Security Fabric, quote-only pricing. https://mspsoftware.net/software/fortiedr
- Huntress: Managed detection and response for MSPs, priced per endpoint from $7.99 a month direct. https://mspsoftware.net/software/huntress. Compare: https://mspsoftware.net/compare/huntress-vs-threatdown

## FAQ

### How much does ThreatDown cost?

ThreatDown does not publish a list price. No MSP price reports have been approved yet.

### Does ThreatDown offer a free trial?

There is no free version.

### Is ThreatDown cloud or on-premises?

ThreatDown is cloud-hosted; there is no on-premises version.

### Who is ThreatDown for?

MSPs report using ThreatDown at sizes of 6-15, 16-50, 51-200 and 200+ technicians.

### What are the four ThreatDown pricing tiers and what does each include?

ThreatDown offers four tiers: Core AV focuses on prevention with AI-powered protection and ransomware rollback for basic endpoint security; Advanced EDR adds endpoint detection and deep investigation capabilities for threat identification; Elite MDR (the most popular tier) introduces 24/7 human-led threat monitoring and response with a five-minute mean time to detect; Ultimate MDR Plus combines all features and adds identity threat detection and response. All tiers run as a single lightweight agent supporting Windows, macOS, Linux, iOS and Android devices.

### Is ThreatDown suitable for MSPs?

ThreatDown is built for MSPs through its OneView console, which provides multi-tenant management and is marketed specifically to managed service providers. The tiered approach allows MSPs to offer customers a choice from prevention-only through full managed response. The platform is designed for MSP efficiency with unified console administration and per-endpoint billing. However, exact MSP-specific features, trial availability and integration depth with existing RMM and PSA tools require contacting sales to confirm suitability before committing to a trial.

### Does ThreatDown offer a free trial?

ThreatDown's website does not specify a free trial period or terms. The company invites prospects to request a personalized demo to see the platform in action, including real-time detection and one-click remediation, but a formal trial or no-cost evaluation requires contacting ThreatDown directly through their request-demo page or sales email.

### What is ThreatDown's ransomware rollback capability?

ThreatDown's ransomware rollback feature, available from the Advanced EDR tier upward, can restore encrypted or modified files up to seven days after a ransomware attack. This allows organisations to recover systems without waiting for decryption keys or paying ransom, and is a differentiator from signature-based antivirus solutions.

### How is ThreatDown priced and what does per-endpoint cost?

ThreatDown pricing is tiered per endpoint and does not appear to be publicly published; instead, customers receive a quote based on the tier selected, number of devices, and contract length. The website references approximately ten dollars per device per month for the Elite MDR tier and offers a twenty percent discount for three-year contracts. Exact pricing requires contacting sales.