๐ CrowdSec Premium
What Premium helps you achieveโ
CrowdSec Premium extends the protection provided by the open-source Security Engine with additional proactive blocking capabilities, centralized management and enhanced tooling.
Improve proactive protectionโ
Premium expands the Community Blocklist from 3k to 50k IPs, generates an organization-specific Threat Forecast from your own shared signals, and gives you access to premium tier blocklists. Every Premium user benefits from this automatically.
Core Featuresโ
Feature reference โ
Threat Forecast โ
โ๏ธ Premium Blocklists โ
Centralize managementโ
Manage decisions, allowlists, and blocklist subscriptions from one place and propagate them to every Security Engine and integration automatically.
Core Featuresโ
Remediation Sync โ
Allowlist management โ
Decisions management โ
Investigate, monitor, and automateโ
Retain up to one year of alerts, investigate IP reputation directly in the Console, and receive real-time notifications when attack patterns change. Use the Service API and Auto Enroll to manage deployments programmatically.
Core Featuresโ
Alerts and retention โ
Push Notifications โ
Service API โ
When Premium is relevantโ
Premium is relevant if you want stronger proactive protection, manage several Security Engines or integrations, or actively investigate and monitor what happens on your infrastructure.
You want stronger proactive protection. Whether you run a personal server or a production fleet, the expanded Community Blocklist, Threat Forecast, and additional premium blocklists help you block more malicious IPs before they reach your infrastructure.
You manage several Security Engines or integrations. Propagating decisions, allowlists, and blocklist subscriptions manually across multiple engines does not scale. Remediation Sync, centralized allowlists, and Console decision management let you control everything from one place. Auto Enroll removes the manual step when deploying new engines.
You actively investigate and monitor your infrastructure. If you need to understand attack patterns over time, investigate specific IPs during an incident, receive proactive alerts, and build detailed reports about blocked traffic, Premium increases retention, investigation quotas, and API access to support that workflow.
Community vs Premiumโ
| Entitlement | Free | Premium |
|---|---|---|
| Community Blocklist | Top 3k IPs | Top 40k IPs |
| Blocklist subscriptions | 3 | Unlimited |
| Alert quota | 500 / month | 10k per Security Engine / month (extendable) |
| Alert retention | 60 days | 365 days |
| Organization seats | 1 | 5 included |
| Console IP investigations | 30 / week | 100 / week |
| CTI API calls | 120 / month | 1,500 / month |
| Remediation Sync | โ | Yes |
| Background Noise filtering | โ | Yes |
| Am I Under Attack | โ | Yes |
| Threat Forecast Blocklist | โ | Yes |
| Service API | โ | Yes |
| Multiple organizations | โ | Yes |
For full entitlement details and expandable limits, see Quotas and plan limits.
Your Premium journeyโ
Follow these steps in order. Each guide links to the next.
1. Plan your deploymentโ
Decide which organization model fits your environment before you upgrade. Understand what moves when you transfer a Security Engine and what does not.
2. Upgrade and configureโ
Upgrade your organization, then configure the features that require setup. Know which entitlements are automatic and which need action.
3. Evaluate your trialโ
Establish a baseline before you activate Premium, then run structured tests to measure the concrete improvement in your environment.
4. Explore all featuresโ
Review every Premium entitlement, its scope, its default state, and links to detailed configuration guides.