Skip to main content

Premium feature reference

This page is a reference, not a narrative. Each entry states what the feature does, where it applies, whether it is automatic or requires configuration, and where to find the detailed guide.

For quota values (seats, API call limits, alert volumes), see Quotas and plan limits.


Protectionโ€‹

FeaturePrimary outcomeScopeState after upgradingConfigurationGuide
Community Blocklist (Premium)Block the top 50k most aggressive IPs instead of 3kOrganizationAutomaticNoneCommunity Blocklist
Premium tier blocklistsAccess to curated specialty lists (botnets, TOR, scanners, proxies)OrganizationAvailable; not subscribedSubscribe to each listBlocklist tiers
Unlimited blocklist subscriptionsSubscribe to as many blocklists as neededOrganizationAutomatic (limit removed)NoneBlocklists
Threat Forecast BlocklistOrganization-specific blocklist derived from your own shared signalsOrganizationAutomatic (generated)None; requires engines sharing signalsThreat Forecast

Centralized security operationsโ€‹

FeaturePrimary outcomeScopeState after upgradingConfigurationGuide
Remediation SyncPropagate decisions to all Security Engines and integrations automaticallyOrganizationAvailable; off by defaultMust be enabledRemediation Sync
Console decision managementAdd, delete, and manage decisions directly from the ConsoleOrganizationAutomaticNoneDecision management
Centralized allowlistsOne allowlist applied across all Security Engines and integrations; supports IP expirationOrganizationAvailableMust create entriesAllowlists
Blocklist creation and sharingCreate and distribute custom blocklists to other organizations or partnersOrganizationAvailableRequires Service API credentialsCustom blocklists

Monitoring and investigationโ€‹

FeaturePrimary outcomeScopeState after upgradingConfigurationGuide
Am I Under AttackReal-time alerts when attack surges are detected on your infrastructureOrganizationAutomaticNotification channels optionalAm I Under Attack
Background Noise filteringRemove mass-scanner and crawler traffic from the alert viewOrganizationAvailable; off by defaultMust be enabled; select level (Low / Medium / High)Background Noise
Increased alert quotaHigher monthly alert ingestion limitOrganizationAutomaticNoneAlert quotas
Extended alert retentionRetain alerts for 365 days instead of 60OrganizationAutomaticNoneAlert quotas
Console IP investigationsInvestigate IP reputation, behavior, and MITRE ATT&CK context directly in the ConsolePer user / organizationAutomatic (quota increased)Noneโ€”
Push notification integrationsReceive alerts in Slack, PagerDuty, or webhooks when engines go offline or become outdatedOrganizationAvailableMust connect integrationsNotification integrations

Automation and integrationsโ€‹

FeaturePrimary outcomeScopeState after upgradingConfigurationGuide
Service API (SAPI)Programmatic management of blocklists, decisions, and enrollmentsOrganizationAvailableMust create API credentialsService API
CTI APIQuery CrowdSec IP reputation data from SIEM, SOAR, or custom toolsPer API keyAutomatic (quota increased)Existing credentials carry higher quota automaticallyCTI API
Auto EnrollNew Security Engines join the organization automatically on deploymentOrganizationAvailable; off by defaultMust be enabledโ€”
Webhooks (via push notifications)Send engine health and attack-surge events to external endpointsOrganizationAvailableMust configure endpointsNotification integrations

Organization and team managementโ€‹

FeaturePrimary outcomeScopeState after upgradingConfigurationGuide
Organization seatsMultiple members with role-based access (Viewer, Editor, Admin)OrganizationAutomatic (quota increased to 5 included)Must invite membersOrganizations
Multiple organizationsCreate unlimited separate organizations for clients, environments, or business unitsAccountAvailableMust create organizationsOrganizations
Tenant isolationEach organization's data, engines, and decisions are fully isolatedPer organizationAutomaticNoneโ€”

Support and serviceโ€‹

FeaturePremium baseAdvance
Support channelConsole chatConsole chat
First contact SLA3 business days1 business day
Workaround / solution SLA5 business days3 business days
Coverage hours8 AMโ€“5 PM CET, business days8 AMโ€“5 PM CET + out-of-hours for critical
ScopeConsole platformConsole + Security Engines + Integrations + all CrowdSec products

Full support SLA and scope โ†’

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.