Premium

Go Premium: support and real-time rules

Priority support and automatic updates of community-validated Sigma and YARA rules, pushed continuously into your ThreatClaw server. Priced by monitored asset count.

100 monitored assets
€200/mo
€2400/yr · €2.00/asset/mo
billed annually
Go Premium
More than 1000 assets?
For larger fleets, we build custom pricing tailored to your scope.
Request custom pricing

Community vs Premium

The product, the code and the coverage are identical and free for everyone. Premium adds one thing: your rules kept up to date in real time inside your server, plus human support.

Community
Free · self-hosted
  • Every product feature: multi-layer detection, ML engine, 38+ investigation playbooks, on-incident DFIR, HITL response (block an IP, isolate an endpoint, disable an account), 11 compliance reports, 15+ connectors, self-hosted under AGPL v3, no asset cap
  • Rule updates : New rule base once a month
  • Support : Community and GitHub
Deploy for free
Premium
Support + real-time rules
  • Everything in Community, plus:
  • Rule updates : Rules kept current continuously, pushed into your server automatically. When a new attack technique emerges, the detection is written, tested and delivered without waiting for next month. Your coverage tracks the threat day by day.
  • Support : Priority email support. An expert answers first for setup and tuning to your environment.
Go Premium
Detection bases kept up to date in real time
7,000+
Sigma
behavioral rules
19,500+
YARA
file/malware rules
3,589,000+
IOC
C2 & malicious IPs
858
MITRE ATT&CK
mapped techniques
367,000+
EPSS
CVE scores (prioritization)
1,600+
CISA KEV
actively exploited CVEs
In Community: base provided and refreshed once a month.
In Premium: kept current continuously and pushed into your server automatically.

Frequently asked questions

Is it really free?
Yes. ThreatClaw is open source under AGPL v3, every feature is available with no asset cap, and the code is indefinitely forkable. You self-deploy, your data stays on your servers. You only pay if you want human support and real-time rule updates.
What does Premium include?
Two things. (1) Priority support by CyberConsulting.fr: setup help, tuning to your context, response within business days. (2) Automatic updates of community-validated Sigma and YARA rules, pushed continuously into your server, so you never detect with stale rules. Priced per monitored asset, degressive by volume, billed annually.
What's the difference between Premium and the rule feed?
Premium pushes the rules straight into your ThreatClaw server (which runs them for you). The rule feed is a separate product: Sigma + YARA files for your own SIEM or stack, for those not running the ThreatClaw agent. Take one, the other, or both.
What is a monitored asset?
An actual internal device (server, workstation, firewall, switch, NAS, IoT) active and monitored by ThreatClaw in the last 30 days. External IPs (attackers, scanners), CVEs, AD users, ephemeral Docker containers and inactive devices never count. The live count is visible in your dashboard.
Does my data stay on my servers?
100%. Self-hosted, the LLM runs locally via Ollama. No telemetry leaves. No cloud call required. If you enable a cloud AI provider (optional, off by default), the anonymizer masks 17 identifier categories before sending.
How does it compare to a SIEM?
A SIEM collects and correlates. ThreatClaw decides. It consumes Wazuh (and others) data and applies 38+ deterministic investigation playbooks to produce an actionable verdict plus 1 to 3 ready-to-fire HITL actions. Keep Wazuh for collection, add ThreatClaw for reasoning and response, for free.
Made in FrancePublic beta · Auditable code · Your data stays on your servers