Pricing
Investigate threats with CTI Unlimited, or block them with an industry blocklist. Both run on the same live honeypot network, both start free, and you can cancel whenever you like.
Blocklists update continuously from live honeypot data and are included with your subscription.
Investigate threats in real time, or block them at your edge. One billing toggle below applies to every price on this page.
Firewall feeds you can drop straight in, built from the same live data. Block malicious IPs at the edge before they ever reach you.
Browse the first pages of every product for free. Subscribe when you need the full picture.
Pick the industry that matches your stack, or take everything with All. Layer on threat category add ons anytime. Every list downloads in any firewall format.
Bolt any of these onto your industry blocklist from your dashboard. Adding is charged pro rata now; removing keeps working until the end of the month.
Three common setups assembled from the pieces above. Mix and match however you like; prices follow the billing toggle.
Investigates incidents in the dashboard, exports reports and gets alerts. No firewall feed needed.
Blocks checkout scanners, card fraud bots and DDoS sources at the firewall.
Protects clients across industries with maximum coverage from one feed.
Tap the pieces you need; the total updates live and follows the billing toggle.
| Free | CTI Unlimited | Blocklists | |
|---|---|---|---|
| Price per month | €0 | €69 | from €149 |
| Dashboard browsing | First 5 pages | Unlimited | First 5 pages |
| Exports, downloads & reports | ✕ | ✓ | ✕ |
| Search, threat map & email alerts | ✕ | ✓ | ✕ |
| Malware samples (Botnet & C2) | ✕ | ✓ | ✕ |
| Firewall feed | Small free sample | ✕ | Full industry feed |
| Threat category add ons | ✕ | ✕ | ✓ |
| Firewall formats (txt, CSV, JSON, .rsc, EDL) | ✓ | ✕ | ✓ |
| Updates from live honeypot data | Continuous | Continuous | Continuous |
CTI Unlimited and Blocklists are independent. Subscribe to either one, or run both side by side.
Yes. Cancel from your billing page in a couple of clicks. Your access keeps working until the end of the period you already paid for, and your configuration is remembered if you come back.
Adding an industry or a threat category is charged pro rata, so you only pay for the remainder of the current period. Removing one keeps it working until the end of the month you paid for.
Both. Every price on this page is shown per month; the toggle at the top switches between yearly billing (about 20 percent cheaper) and month to month billing you can stop anytime.
No. They are separate products on the same data. Firewall teams often run blocklists alone; analyst teams often run CTI alone. You can combine them whenever you like.
Feeds download in plain text, CSV, JSON, MikroTik .rsc and EDL formats, ready for Palo Alto, FortiGate, Cisco, MikroTik and Check Point. Optional /24 CIDR aggregation is included.
Card checkout through Stripe, or PayPal. The free tier needs no card at all, and there is no setup fee on any plan.
Start on the free tier, no card required. Actionable threat intelligence, priced so every team can use it.