Premium feature reference
This page is a reference, not a narrative. Each entry states what the feature does, where it applies, whether it is automatic or requires configuration, and where to find the detailed guide.
For quota values (seats, API call limits, alert volumes), see Quotas and plan limits.
Protectionโ
| Feature | Primary outcome | Scope | State after upgrading | Configuration | Guide |
|---|
| Community Blocklist (Premium) | Block the top 50k most aggressive IPs instead of 3k | Organization | Automatic | None | Community Blocklist |
| Premium tier blocklists | Access to curated specialty lists (botnets, TOR, scanners, proxies) | Organization | Available; not subscribed | Subscribe to each list | Blocklist tiers |
| Unlimited blocklist subscriptions | Subscribe to as many blocklists as needed | Organization | Automatic (limit removed) | None | Blocklists |
| Threat Forecast Blocklist | Organization-specific blocklist derived from your own shared signals | Organization | Automatic (generated) | None; requires engines sharing signals | Threat Forecast |
Centralized security operationsโ
| Feature | Primary outcome | Scope | State after upgrading | Configuration | Guide |
|---|
| Remediation Sync | Propagate decisions to all Security Engines and integrations automatically | Organization | Available; off by default | Must be enabled | Remediation Sync |
| Console decision management | Add, delete, and manage decisions directly from the Console | Organization | Automatic | None | Decision management |
| Centralized allowlists | One allowlist applied across all Security Engines and integrations; supports IP expiration | Organization | Available | Must create entries | Allowlists |
| Blocklist creation and sharing | Create and distribute custom blocklists to other organizations or partners | Organization | Available | Requires Service API credentials | Custom blocklists |
Monitoring and investigationโ
| Feature | Primary outcome | Scope | State after upgrading | Configuration | Guide |
|---|
| Am I Under Attack | Real-time alerts when attack surges are detected on your infrastructure | Organization | Automatic | Notification channels optional | Am I Under Attack |
| Background Noise filtering | Remove mass-scanner and crawler traffic from the alert view | Organization | Available; off by default | Must be enabled; select level (Low / Medium / High) | Background Noise |
| Increased alert quota | Higher monthly alert ingestion limit | Organization | Automatic | None | Alert quotas |
| Extended alert retention | Retain alerts for 365 days instead of 60 | Organization | Automatic | None | Alert quotas |
| Console IP investigations | Investigate IP reputation, behavior, and MITRE ATT&CK context directly in the Console | Per user / organization | Automatic (quota increased) | None | โ |
| Push notification integrations | Receive alerts in Slack, PagerDuty, or webhooks when engines go offline or become outdated | Organization | Available | Must connect integrations | Notification integrations |
Automation and integrationsโ
| Feature | Primary outcome | Scope | State after upgrading | Configuration | Guide |
|---|
| Service API (SAPI) | Programmatic management of blocklists, decisions, and enrollments | Organization | Available | Must create API credentials | Service API |
| CTI API | Query CrowdSec IP reputation data from SIEM, SOAR, or custom tools | Per API key | Automatic (quota increased) | Existing credentials carry higher quota automatically | CTI API |
| Auto Enroll | New Security Engines join the organization automatically on deployment | Organization | Available; off by default | Must be enabled | โ |
| Webhooks (via push notifications) | Send engine health and attack-surge events to external endpoints | Organization | Available | Must configure endpoints | Notification integrations |
Organization and team managementโ
| Feature | Primary outcome | Scope | State after upgrading | Configuration | Guide |
|---|
| Organization seats | Multiple members with role-based access (Viewer, Editor, Admin) | Organization | Automatic (quota increased to 5 included) | Must invite members | Organizations |
| Multiple organizations | Create unlimited separate organizations for clients, environments, or business units | Account | Available | Must create organizations | Organizations |
| Tenant isolation | Each organization's data, engines, and decisions are fully isolated | Per organization | Automatic | None | โ |
Support and serviceโ
| Feature | Premium base | Advance |
|---|
| Support channel | Console chat | Console chat |
| First contact SLA | 3 business days | 1 business day |
| Workaround / solution SLA | 5 business days | 3 business days |
| Coverage hours | 8 AMโ5 PM CET, business days | 8 AMโ5 PM CET + out-of-hours for critical |
| Scope | Console platform | Console + Security Engines + Integrations + all CrowdSec products |
Full support SLA and scope โ