Skip to main content

๐Ÿ… CrowdSec Premium

What Premium helps you achieveโ€‹

info

CrowdSec Premium extends the protection provided by the open-source Security Engine with additional proactive blocking capabilities, centralized management and enhanced tooling.

Improve proactive protectionโ€‹

Premium expands the Community Blocklist from 3k to 50k IPs, generates an organization-specific Threat Forecast from your own shared signals, and gives you access to premium tier blocklists. Every Premium user benefits from this automatically.

Core Featuresโ€‹

Feature reference โ†’
Threat Forecast โ†’
โ†—๏ธ Premium Blocklists โ†’

Centralize managementโ€‹

Manage decisions, allowlists, and blocklist subscriptions from one place and propagate them to every Security Engine and integration automatically.

Core Featuresโ€‹

Remediation Sync โ†’
Allowlist management โ†’
Decisions management โ†’

Investigate, monitor, and automateโ€‹

Retain up to one year of alerts, investigate IP reputation directly in the Console, and receive real-time notifications when attack patterns change. Use the Service API and Auto Enroll to manage deployments programmatically.

Core Featuresโ€‹

Alerts and retention โ†’
Push Notifications โ†’
Service API โ†’


When Premium is relevantโ€‹

Premium is relevant if you want stronger proactive protection, manage several Security Engines or integrations, or actively investigate and monitor what happens on your infrastructure.

You want stronger proactive protection. Whether you run a personal server or a production fleet, the expanded Community Blocklist, Threat Forecast, and additional premium blocklists help you block more malicious IPs before they reach your infrastructure.

You manage several Security Engines or integrations. Propagating decisions, allowlists, and blocklist subscriptions manually across multiple engines does not scale. Remediation Sync, centralized allowlists, and Console decision management let you control everything from one place. Auto Enroll removes the manual step when deploying new engines.

You actively investigate and monitor your infrastructure. If you need to understand attack patterns over time, investigate specific IPs during an incident, receive proactive alerts, and build detailed reports about blocked traffic, Premium increases retention, investigation quotas, and API access to support that workflow.


Community vs Premiumโ€‹

EntitlementFreePremium
Community BlocklistTop 3k IPsTop 40k IPs
Blocklist subscriptions3Unlimited
Alert quota500 / month10k per Security Engine / month (extendable)
Alert retention60 days365 days
Organization seats15 included
Console IP investigations30 / week100 / week
CTI API calls120 / month1,500 / month
Remediation Syncโ€”Yes
Background Noise filteringโ€”Yes
Am I Under Attackโ€”Yes
Threat Forecast Blocklistโ€”Yes
Service APIโ€”Yes
Multiple organizationsโ€”Yes

For full entitlement details and expandable limits, see Quotas and plan limits.


Your Premium journeyโ€‹

Follow these steps in order. Each guide links to the next.

1. Plan your deploymentโ€‹

Decide which organization model fits your environment before you upgrade. Understand what moves when you transfer a Security Engine and what does not.

Plan your Premium deployment โ†’

2. Upgrade and configureโ€‹

Upgrade your organization, then configure the features that require setup. Know which entitlements are automatic and which need action.

Upgrade and configure Premium โ†’

3. Evaluate your trialโ€‹

Establish a baseline before you activate Premium, then run structured tests to measure the concrete improvement in your environment.

Evaluate your Premium trial โ†’

4. Explore all featuresโ€‹

Review every Premium entitlement, its scope, its default state, and links to detailed configuration guides.

Premium feature reference โ†’

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.