Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Malwarebytes Premium vs ThreatDown: Home Tool or a Real Console?

12 min read Updated October 4, 2026 Antivirus Comparisons

Fix it now

There are three rungs here, not two, and most articles skip the middle one. Malwarebytes’ own agreement lets a business of no more than 10 devices use the paid home software under its Teams terms; Malwarebytes for Teams is a group subscription of up to 20 devices; ThreatDown is the managed platform above that.

  1. Read the agreement before assuming you are non-compliant. Malwarebytes grants the home licence solely for personal, non-commercial purposes and says the software may not be used on a business device – then carries a small business exception for a business of no more than 10 devices that complies with the Teams usage terms.
  2. Buy Malwarebytes for Teams if you are a handful of people. Malwarebytes publishes it as a group subscription of up to 20 devices covering its Windows, Mac, Android and iOS security products.
  3. Move to ThreatDown when you need central control, policy and reporting rather than a group of subscriptions. Its published bundles are Core Next-Gen AV, Advanced EDR, Elite MDR and Ultimate MDR Plus.
  4. Buy ThreatDown regardless if you have a Windows Server. Malwarebytes lists only Windows 11 and Windows 10 as supported for its desktop product; server cover is a ThreatDown add-on.
  5. Skip Malwarebytes Free as your protection. Malwarebytes describes Free as a cleanup tool for attacks that have already damaged a device, and Premium as what stops them happening.
  6. Do not run it permanently alongside another real-time engine. Pick a primary product and keep the free scanner for a manual second look at one machine.

The bundle names changed with the ThreatDown rebrand. If a quote says ThreatDown Core, Advanced, Elite or Ultimate without the capability suffix, ask the supplier to map it to the current Core Next-Gen AV, Advanced EDR, Elite MDR and Ultimate MDR Plus naming before you compare anything.

If the device count and the server question place you on a rung, stop here. Below is what each rung actually gives you, and how to move between them without leaving a machine unprotected.

Why it happens

The usual version of this article says the consumer licence forbids business use full stop, and that the only legitimate move is to the business platform. That is not what Malwarebytes publishes. Its end user licence agreement does grant the home licence solely for personal, non-commercial purposes, and does say the software may not be used on any device that is used in a business or for business purposes – and it then sets out a small business exception permitting a business with no more than 10 devices to use the paid home software for business purposes, provided it complies with the Malwarebytes for Teams usage terms rather than the home terms. If you are five people with five laptops, the honest answer may be that you are already inside the terms and the reason to move is operational rather than contractual.

Above that sits Malwarebytes for Teams, which is the rung most comparisons omit entirely. Malwarebytes publishes it as a group subscription of up to 20 devices covering its Windows, Mac, Android and iOS security products. It is a straightforward answer for a business that has outgrown individual subscriptions but has nothing a console would usefully manage.

ThreatDown is the platform above both, and what you are buying there is management rather than a different scanner. The current bundle names say what each rung adds: Core Next-Gen AV, Advanced EDR, Elite MDR and Ultimate MDR Plus, with ITDR, Premium Support, DNS Filtering, Email Security, Server Protection and Mobile Security published as add-ons rather than bundle contents. The old names – Core, Advanced, Elite, Ultimate – are still what most third-party comparisons use, which is a reason to work from ThreatDown’s own current matrix and nothing else.

You are under ten devices and worried about the licence

You have this one if A handful of laptops, all doing work, all running paid Malwarebytes bought individually.

  1. Read the small business exception in Malwarebytes’ agreement. A business of no more than 10 devices may use the paid home software for business purposes under the Teams usage terms.
  2. If that applies, the argument for moving is administrative – one renewal date, one invoice – rather than a compliance emergency.
  3. Malwarebytes for Teams is the tidy version of the same thing: one group subscription of up to 20 devices across Windows, Mac, Android and iOS.

You now have a server, or a machine that is not Windows 11 or 10

You have this one if There is a box holding shared files and the desktop product either will not install or is simply not on the supported list.

  1. Malwarebytes lists Windows 11 and Windows 10 as the supported Windows operating systems for its desktop security product; no server edition is listed.
  2. Server cover is published as a ThreatDown add-on, alongside Mobile Security, DNS Filtering and Email Security.
  3. Quote workstation seats and server seats separately, so you can see what each part costs rather than a single number.

Nobody can tell you which machines are actually protected

You have this one if You cannot produce a list of endpoints with their protection state without walking to desks.

  1. This is the console argument, and it is the real reason to move to ThreatDown rather than the licence wording.
  2. Start at Core Next-Gen AV if central management of protection is the requirement, and go higher only when you can name the specific thing you want.
  3. Buying a higher bundle for a feature nobody has been assigned to use is the most common way to overspend here.

The one thing not to buy on is the scanner. Malwarebytes describes the free product as a cleanup tool for cyberattacks that have already damaged a device and Premium as what stops those attacks happening in the first place, and the paid protection component is present on every rung above that. What changes as you climb is who can see it, who can enforce it and who is watching the alerts.

Full reference

The three rungs, side by side

Dimension Malwarebytes paid home licence Malwarebytes for Teams ThreatDown
Published business use Personal and non-commercial, with a small business exception for a business of no more than 10 devices under the Teams terms Business use Business use
Device coverage Per subscription, per person Group subscription of up to 20 devices Sized to the estate
Platforms Windows, Mac, Android, iOS Windows, Mac, Android, iOS Windows and Mac endpoints, with Mobile Security as an add-on
Central console with policy No No Yes, and it is the reason to buy it
Windows Server Not listed as supported Not listed as supported Server Protection as an add-on
Detection and response No No From Advanced EDR upward
Managed service No No Elite MDR and Ultimate MDR Plus
Reporting you can export No No Yes

What the ThreatDown bundles are called now

ThreatDown publishes four bundles: Core Next-Gen AV, Advanced EDR, Elite MDR and Ultimate MDR Plus. The names carry the ladder – protection, then detection and response, then a managed service, then the managed service with identity threat detection and response and premium support included rather than added. Alongside them ThreatDown publishes a set of add-ons that are not in any bundle by default: ITDR, Premium Support, DNS Filtering, Email Security, Server Protection and Mobile Security.

We are not reproducing the module matrix row by row, because ThreatDown revises it and a stale table here is worse than no table. Read the current one on ThreatDown’s own pricing page and check the specific modules you are buying for, not the bundle name.

Two rules for the ladder

  • Do not buy detection and response unless somebody will read it, or unless you are buying it in the managed form. An unread console is an expensive log file, and the licence is the smaller half of the cost when you self-manage.
  • Do buy patch and vulnerability management earlier than instinct suggests. Out-of-date third-party software is a far more common way in than novel malware, and it is one of the few additions that reduces ongoing work rather than adding to it.

Moving up without leaving a gap

  1. Count the machines you are actually responsible for, and list any Windows Servers separately – they are a different licence line everywhere.
  2. Decide who owns the console. If the answer is nobody, fix that before buying, because an unopened console changes nothing.
  3. Remove the existing product from a pilot machine using the vendor’s own removal tool, then deploy the managed agent to it and leave it a week.
  4. Set exclusions for your line-of-business software in the policy before the wider rollout.
  5. Roll out in waves, keeping the existing subscriptions live until their machines have moved.
  6. When every machine reports in, compare the console list against your asset list. The machines that never appear are the entire point of the exercise.

Do not leave both products installed on one machine as a belt-and-braces measure. Two real-time engines inspecting the same files cause performance problems and mutual false positives, and diagnosing them costs more time than either product saves.

Which rung, by situation

  • One personal computer, no work use: the paid home licence, or the free scanner alongside Microsoft Defender if you are careful about what you run.
  • A sole trader on one laptop: this is business use, and Malwarebytes’ small business exception is the clause to read before deciding whether anything needs to change.
  • Under twenty devices, nobody administering anything: Malwarebytes for Teams, as a group subscription rather than a scatter of individual ones.
  • Three to fifty machines with somebody nominally in charge of IT: ThreatDown Core Next-Gen AV. The console is the entire reason to move.
  • Any Windows Server in the building: ThreatDown with Server Protection, because the desktop product is not supported there.
  • You want detection and response but nobody to watch it: Elite MDR, or stay at Core and spend the difference on backups.

What the free scanner is still for

Malwarebytes Free remains genuinely useful and it is worth being precise about what for. Malwarebytes describes it as a cleanup tool for cyberattacks that have already damaged a device, as against Premium which stops those attacks in the first place and provides real-time detection and blocking. That makes Free a good second opinion on a single suspect machine, run manually, once. It makes it a poor choice as an estate’s protection, and a poor choice as a permanent second real-time engine anywhere.

When a licence is the actual fix

If the console is what you actually need, ThreatDown Core Next-Gen AV is the rung that provides it, and the console rather than the scanner is what you are paying for. Arco can supply it, size workstation and server cover separately – Server Protection is an add-on rather than a bundle inclusion – and tell you whether Core covers your requirement or whether patch and vulnerability management earns its place in your case. If you are under ten devices, we will point you at the small business exception in Malwarebytes’ own agreement first, and at Malwarebytes for Teams second, before quoting a platform you do not yet need. If you only want to clean one infected home computer, the free scanner does that and we will say so.

Questions people ask about this

Is the home licence really forbidden at work?

Not automatically, and this is where most comparisons are wrong. Malwarebytes grants the home licence solely for personal, non-commercial purposes and says it may not be used on a business device – and then publishes a small business exception permitting a business of no more than 10 devices to use the paid home software for business purposes under its Teams usage terms. Read the clause for the product you hold.

What is Malwarebytes for Teams, and why have I not seen it in comparisons?

It is the rung between the home licence and the ThreatDown platform, and it gets skipped because it is easier to write a two-way comparison. Malwarebytes publishes it as a group subscription of up to 20 devices covering its Windows, Mac, Android and iOS security products. For a business that has outgrown individual subscriptions but has nothing a console would manage, it is often the right answer.

Is ThreatDown just Malwarebytes with a console?

At the Core Next-Gen AV level that is a fair description and not a criticism, because the console is the difference that matters once you have more than a few machines. The higher bundles add capability the home product has no equivalent for: detection and response at Advanced EDR, a managed service at Elite MDR, and identity threat detection and response plus premium support at Ultimate MDR Plus.

Will our existing subscriptions transfer?

No. The business line is separate licensing, so you buy seats and migrate machines. Time remaining on individual subscriptions is normally lost, which makes renewal dates the sensible moment to switch. Overlap the two rather than letting one lapse before the other starts.

Can we keep Malwarebytes as a second opinion alongside our main antivirus?

On one machine, occasionally, with the free on-demand scanner, that is a reasonable habit – Malwarebytes describes Free as a cleanup tool for damage already done. As a permanent second real-time engine across an estate it is not: two engines inspecting the same files cause performance problems and mutual false positives. Pick one primary product and configure it properly.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Free vs Paid Antivirus: What the Free Tier Quietly Leaves Out Review Bitdefender vs Norton in 2026: Which One Actually Slows Your PC Down Less? Review Antivirus for Schools and Charities: Licensing on a Restricted Budget Review Best Antivirus With Parental Controls, and Where Teenagers Get Round Them
โ† Back to Knowledge Base