Pricing
Two products. One sensor network.
Investigate threats with CTI Unlimited, or block them with an industry blocklist. Both run on the same live honeypot network, both start free, and you can cancel whenever you like.
Blocklists update continuously from live honeypot data and are included with your subscription.
Two ways to outsmart attackers
Investigate threats in real time, or block them at your edge. One billing toggle below applies to every price on this page.
- Heartbeat: open proxies, Tor exits & DDoS sources
- Scanner recon across TCP & UDP
- Botnet & C2 tracking with malware samples
- OpenData feeds (DNS, NTP, SSDP)
Firewall feeds you can drop straight in, built from the same live data. Block malicious IPs at the edge before they ever reach you.
- Ready for Palo Alto, FortiGate, Cisco, MikroTik & Check Point
- Plain, CSV, JSON, .rsc & EDL formats
- Optional /24 CIDR aggregation
- Refreshed continuously from live data
Start free, go Unlimited
Browse the first pages of every product for free. Subscribe when you need the full picture.
- First 5 pages of every product
- Browse Heartbeat
- Browse Scanner recon
- Browse Botnet & C2
- Browse OpenData
- No exports or downloads
- Unlimited pages & pagination
- Exports, downloads & reports
- Full Heartbeat (proxies, Tor, DDoS)
- Full Scanner recon (TCP/UDP)
- Full Botnet & C2 + malware samples
- Full OpenData feeds
- Search, threat map & email alerts
- Full Platform Access
- Email Notifications
- Data Exports (JSON, PNG)
- Botnet Tracking & Analysis
- TCP/UDP Scanner Monitoring
- Heartbeat Analysis
- Open Data Access
- All Platform Features
Industry blocklists
Start with a sample, protect one industry, combine up to three, or cover every industry. Every plan produces one continuously updated feed in every firewall format.
Need a different industry mix, managed deployment, or contract pricing? Custom is available as a secondary, sales-assisted option.
Talk to salesCompare what you get
| Free | CTI Unlimited | Blocklists | |
|---|---|---|---|
| Price per month | €0 | €69 | from €89 |
| Dashboard browsing | First 5 pages | Unlimited | First 5 pages |
| Exports, downloads & reports | ✕ | ✓ | ✕ |
| Search, threat map & email alerts | ✕ | ✓ | ✕ |
| Malware samples (Botnet & C2) | ✕ | ✓ | ✕ |
| Firewall feed | Small free sample | ✕ | Full industry feed |
| Threat categories | Sample only | ✕ | Included in paid tiers |
| Firewall formats (txt, CSV, JSON, .rsc, EDL) | ✓ | ✕ | ✓ |
| Updates from live honeypot data | Continuous | Continuous | Continuous |
CTI Unlimited and Blocklists are independent. Subscribe to either one, or run both side by side.
Billing, answered
Can I cancel anytime?
Yes. Cancel from your billing page in a couple of clicks. Your access keeps working until the end of the period you already paid for, and your configuration is remembered if you come back.
What happens when I change tiers mid month?
Billing shows the exact charge or credit before you confirm. Industry-only changes within the same tier do not add another subscription item.
Monthly or yearly billing?
Both. Every price on this page is shown per month; the toggle at the top switches between yearly billing (about 20 percent cheaper) and month to month billing you can stop anytime.
Do I need CTI Unlimited to buy a blocklist?
No. They are separate products on the same data. Firewall teams often run blocklists alone; analyst teams often run CTI alone. You can combine them whenever you like.
Which firewalls are supported?
Paid feeds support all eleven advertised encoders: TXT, plain, CSV, JSON, MikroTik, Check Point, Wazuh, F5, Zeek, CIDR and RPZ. Optional /24 CIDR aggregation is included.
How do I pay?
Paid plans use secure card checkout through Stripe. The Free tier needs no card, and there is no setup fee.
Start blocking threats today
Start on the free tier, no card required. Actionable threat intelligence, priced so every team can use it.