ThreatDown
Table of Contents
The Syncro-ThreatDownintegration offers best-in-class endpoint security solutions designed to protect organizations like yours.
Note: Universal Billing is currently available with Threatdown.
About Threatdown
You need security that's powerful yet simple. ThreatDown gives you a single, multi-tenant dashboard to manage all your clients' security, from endpoint protection to advanced threat hunting.
With Threatdown, you can:
- Boost Efficiency: Manage everything from one place, saving time and resources.
- Increase Revenue: Easily add high-value services like EDR and MDR to your offerings.
- Deliver Expert Security: Provide 24/7 expert-led threat detection and response without the cost of building your own security operations center.
The Syncro-ThreatDown integration makes it easy to deliver comprehensive security, increase profitability, and give your clients the peace of mind they deserve.
Pricing
Pricing is per endpoint with no contracts and no minimums.
Note: Syncro displays specific pricing in the ThreatDown tile, located in the App Center for your Syncro account.
Support
All technical support is handled by ThreatDown directly.
Support requests can be created, viewed, and responded to using the “Support Cases” tab when logged into the ThreatDown OneView portal.
Provision New Accounts or Migrate Existing Accounts
Note: You must be a paying Syncro subscriber (i.e., not on a Trial) to provision or migrate an account.
To provision a new ThreatDown account, follow these steps:
- Navigate to Admin > Integrations - App Center.
- Type “Threatdown” in the search bar, or click the Security link.
- Click the ThreatDown tile.
- To create a new account, click Provision New Account. The page will refresh momentarily and you'll receive an activation email.
- To migrate your existing ThreatDown instance over to Syncro instead (to take advantage of our aggressive pricing):
- Send email to threatdown@syncrosecure.com.
- When that process is complete, you'll be able to click Link Migrated Account and provide the ThreatDown Client ID and ThreatDown Client Secret:
Obtain Your ThreatDown Client ID and Client Secret
To obtain the Client ID and Secret you need to link a migrated account, follow these steps:
- Log into your ThreatDown account.
- Navigate to the “Integrate” section. (This is typically found in the main menu or under a settings/gear icon.)
- Look for the APIs section for a link to “OAuth2 Clients.” (You should find an option to generate client credentials or create a new client.)
- Follow the prompts to name the new client application (e.g., "Syncro").
- Assign the necessary access permissions (e.g., read, write, execute) for the new token. You should only grant the permissions that your integration requires. Syncro recommends all three:
- Once created, the console will display the Client ID and Client Secret. These are your API credentials.
IMPORTANT: Copy and store these credentials in a secure, encrypted location. The Client Secret is typically shown only once and cannot be retrieved again.
Deploy, Monitor, & Update ThreatDown Policies
Native ThreatDown policy deployment and monitoring is currently in EA (Early Access). Click here to participate.
Deploy ThreatDown Via a Policy
You can assign and update ThreatDown protection for your assets directly from a Policy, without copying installer URLs or running scripts on individual devices.
To deploy ThreatDown to an Organization's assets:
- Open an existing Policy or create a new one. (See Work with Policies for details.)
- In the left panel of Syncro's Policy Builder, select the Antivirus category.
- Select ThreatDown from the Antivirus dropdown menu.
- Click Save Policy. Syncro fetches the installer URL and begins deployment to assets assigned to the policy.
Monitor Status & Sync Health
Once ThreatDown is deployed, you can monitor status and policy sync health from the Asset Details Page:

If Syncro cannot fetch the installer URL for a policy, a sync error appears here too:

Making Policy Updates
Syncro deploys the ThreatDown agent to an asset. Once the agent is installed, security configuration is managed entirely from the ThreatDown Nebula console. Any change made there applies automatically to any asset that already has the agent installed; no action in Syncro is required.
If you want to change which Assets have ThreatDown installed, perform that action in Syncro. If you want to change the ThreatDown licensing or security settings of an asset, perform that action in the ThreatDown portal.