Skip to content

Commit ab06d3f

Browse files
rr404jdv
andauthored
Added list of premium features (#961)
* added list of premium features * addition of a section to test premium value --------- Co-authored-by: jdv <julien@crowdsec.net>
1 parent 78f3565 commit ab06d3f

File tree

1 file changed

+150
-0
lines changed

1 file changed

+150
-0
lines changed

crowdsec-docs/unversioned/console/premium_upgrade.mdx

Lines changed: 150 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,3 +46,153 @@ To split your Security Engines into different organizations, use either:
4646
- Or via `cscli`, re-enroll your Security Engines in the desired organization with the `--overwrite` flag to force moving them to the new organization.
4747

4848
After the transfer, the alerts will reappear in the new organization after a few minutes.
49+
50+
---
51+
52+
53+
## Test Premium Value in Your Environment
54+
55+
Before exploring all Premium features, here are practical ways to measure and experience the value yourself.
56+
The following can be used as a guide during your trial period to assess the benefits of upgrading to Premium.
57+
58+
### 🎯 Measure Improved Protection
59+
60+
**Activate:**
61+
- Community Blocklists (premium) will automatically be sent to your enrolled engines.
62+
- The [Threat Forecast Blocklist](/u/console/threat_forecast) Will be generated automatically used in your organization based on your shared signals.
63+
- Premium Tier Blocklists can be subscribed and subscription numbers per org are unlimited.
64+
- You can activate [Remediation Sync](/u/console/remediation_sync) to propagate decisions across all your enrolled Security Engines.
65+
- Respond faster to a spike of alerts thanks to "Am I Under Attack"
66+
67+
**Measure the impact:**
68+
- **Remediation Metrics:** Track your proactive vs reactive blocking ratio
69+
- **Server Resources:** Monitor CPU, memory, and bandwidth reduction
70+
- **SIEM Logs:** Measure log volume decrease and background noise reduction
71+
72+
**Expected results:** 2x more proactive blocking, 75-92% less malicious traffic reaching your servers, cleaner logs and reduced alert fatigue.
73+
74+
---
75+
76+
### 👥 Enable Team Collaboration
77+
78+
**Activate:**
79+
- Invite collaborators thanks to Multi-Seat Access
80+
- Extended Alert Retention (365 days) allow improved traceability
81+
- Use the improved in-console CTI quotas to enrich your investigations
82+
- Get notified within your tools thanks to [Push Notification Integrations](/u/console/notification_integrations/overview)
83+
84+
**How your team benefits:**
85+
- Analyze long-term attack trends and recurring threats
86+
- Conduct CTI investigations directly in the Console
87+
- Multiple team members work simultaneously without access conflicts
88+
89+
**Expected results:** Faster incident investigations, better threat attribution, reduced tool sprawl.
90+
91+
---
92+
93+
### 🏢 Scale for MSPs & Enterprises
94+
95+
**Activate:**
96+
- Administrate & share access to your clients thanks to Multi-Organization
97+
- Create & Share Blocklists across organizations via our [Service API (SAPI)](/u/console/service_api/getting_started)
98+
99+
100+
**Manage at scale:**
101+
- Segment customer environments (one org per client)
102+
- Share custom threat intelligence across organizations
103+
- Automate blocklist management via API
104+
105+
**Expected results:** Clear tenant isolation, streamlined multi-customer operations, custom visibility on their defenses.
106+
107+
---
108+
109+
## Premium Features Overview
110+
111+
Premium features enable multiple use cases.
112+
Make the best use of the premium features for your needs in: **Scaling, Multi-tenancy, Inhanced proactive protection, Centralized management, Team collaboration, Integration and automation, Enhanced threat intelligence, and improved support.**
113+
114+
---
115+
116+
### Scaling, Automation & Multi-Tenancy
117+
118+
#### Remediation Sync
119+
Automatically synchronize security decisions across your entire organization. Syncs to all Security Engines and Blocklists Integration endpoints, ensuring consistent protection across your infrastructure.
120+
[Learn more about remediation sync](/u/console/remediation_sync)
121+
122+
#### Console Decision Management
123+
Add, delete, and manage security decisions directly from the Console. Force pull blocklists when subscribing or unsubscribing, giving you complete control over your security posture from a central interface.
124+
[Learn more about decision management](/u/console/decisions/decisions_management)
125+
126+
#### Centralized Allowlists
127+
Manage allowlists from a single location and apply them across all security engines and integrations organization-wide. Supports IP expiration for temporary allowlisting.
128+
[Learn more about allowlists](/u/console/allowlists)
129+
130+
#### Service API (SAPI)
131+
Access APIs for console management.
132+
[Learn more about Service API](/u/console/service_api/getting_started)
133+
134+
#### Blocklist Creation & Sharing
135+
Via our [Service API (SAPI)](/u/console/service_api/getting_started) Distribute custom blocklists across multiple organizations or partners, enabling coordinated security operations across your business ecosystem.
136+
[Learn more about SAPI Blocklist endpoints](/u/console/service_api/blocklists)
137+
138+
#### Auto Enroll
139+
Automatically enroll new security engines into your organization for streamlined deployment and management.
140+
141+
#### Expanded Organization Seats
142+
Provide view/edit/admin access to you customers or collaborate with team members by adding more seats to your organization. (3 included in bas Premium plan)
143+
144+
### Extra protection
145+
146+
#### Threat Forecast Blocklists
147+
Access exclusive, organization-specific blocklists generated from the signals your organization shares with CrowdSec. These blocklists are more precise than community blocklists and provide tailored protection for your infrastructure.
148+
[Learn more about threat forecast blocklists](/u/console/threat_forecast)
149+
150+
#### Expanded Community Blocklist Coverage
151+
Unlock the premium Community Blocklist as a network participant.
152+
Receive up to 50k of the most aggressive attackers targeting similar services as yours *(up from top [3k in Community](/central_api/community_blocklist/#community-blocklist-lite)).*
153+
154+
#### Premium Tier Blocklist Access
155+
Get access to our Premium tier blocklists, providing enhanced protection with curated specialized blocklists tailored for different attack vectors.
156+
157+
#### Unlimited Blocklist Subscriptions
158+
Premium subscribers get unlimited blocklist subscriptions (compared to 3 in Community), allowing you to protect your infrastructure with multiple specialized blocklists simultaneously.
159+
[Learn more about premium tier blocklists features](/u/blocklists/intro#crowdsec-blocklist-tiers)
160+
161+
### Reactivity & Monitoring
162+
163+
#### Am I Under Attack Feature
164+
Receive real-time alerts when your infrastructure experiences attack surges. This feature analyzes current traffic patterns against historical baselines to detect anomalous activity, with support for email notifications and webhook integrations.
165+
[Learn more about attack detection](/u/console/security_engines/am_i_under_attack)
166+
167+
#### Push Notifications Integrations
168+
Receive alerts when security engines go offline or become outdated, ensuring your security infrastructure remains operational.
169+
[Learn more about push notifications](/u/console/notification_integrations/overview)
170+
171+
#### Increased Alert Quotas and Extended Retention
172+
Upgrade from the Community Plan's 500 alerts per month and 2-month retention to custom quotas (up to several million alerts) and up to 1 year of retention. This enables comprehensive monitoring of large-scale infrastructures and long-term security analysis.
173+
[Learn more about premium quotas](/u/console/alerts/quotas#why-upgrade-to-premium-)
174+
175+
#### Background Noise Filtering
176+
Automatically filter out internet background radiation and mass scanning activity to focus on genuine threats. Customize noise cancellation levels (Low, Medium, High) to match your security requirements.
177+
[Learn more about background noise filtering](/u/console/alerts/background_noise)
178+
179+
#### IP reputation investigation quotas
180+
Audit what CrowdSec knows about IP addresses, attacking you and present in blocklists, with increased investigation quotas.
181+
100 attacker details per week (compared to 30 in Community), including IP reputation and MITRE ATT&CK mappings for comprehensive threat intelligence.
182+
183+
#### CTI API Access
184+
Leverage CrowdSec IP reputation data into your vendors.
185+
Get 100 CTI API calls per week (compared to 30 in Community) for integration with SIEM, SOAR, and other security tools.
186+
[Learn more about CTI API](/u/cti_api/api_integration/integration_intro)
187+
188+
---
189+
190+
## How to Upgrade
191+
192+
Ready to enhance your security posture with Premium features?
193+
194+
1. Visit our [pricing page](https://app.crowdsec.net/pricing) to compare plans and pricing
195+
2. Upgrade to Premium with our self service plan or [Contact](https://www.crowdsec.net/contact-crowdsec) our sales team to discuss your specific requirements
196+
3. Once upgraded, enjoy immediate access to all Premium features in your organization and add options as you grow.
197+
198+
For questions about Premium features or to discuss custom enterprise solutions, please [contact our team](https://www.crowdsec.net/pricing).

0 commit comments

Comments
 (0)