Every feature, every tier
Community is free forever with no account. Pro adds prevention. Team adds fleet-wide visibility. See exactly what each plan includes.
| Feature | CommunityFree | Pro$96/yr | Team$168/seat/yr |
|---|---|---|---|
| Scanning & Detection | |||
| On-demand file scanningYARA-x engine, CLI + GUI + right-click in file managers | |||
| Real-time fanotify interceptionWatches file opens across the filesystem, scans before access | |||
| Execution gateBlocks unknown binaries at execve — verdict before the process runs | — | ||
| Quarantine vaultIsolates detected threats with original path + metadata preserved | |||
| Rootkit scannerHidden processes, kernel module anomalies, /proc tampering | |||
| Hash-based IOC matchingSHA-256 lookups against curated known-malware feeds during scans and real-time interception | — | ||
| Payload execution blockingPrevent mmap+exec of exploit shellcode and anomalous memory-mapped executables | — | Soon | Soon |
| In-memory exploit detectionDetect stack pivots, ROP chains, and JIT spray patterns in running processes | — | — | Soon |
| Supply-Chain Protection | |||
| Dependency lock file scanningnpm, PyPI, Cargo, Go, Ruby, Composer — typosquat + known-malicious | |||
| Install-script analysisFlags postinstall hooks that pipe remote scripts to a shell | |||
| Pickle / model file analysisDetects code execution in .pt, .ckpt, .pkl model files | |||
| Prompt-injection detectionScans CLAUDE.md, .cursorrules, copilot-instructions for injection | |||
| MCP server for coding assistantsFour read-only tools so Claude / Cursor can check repos before trusting | |||
| Vulnerability Management | |||
| Package vulnerability scannerdpkg/rpm → OSV.dev with real CVSS severity, CVE IDs, fix versions | |||
| Auto-remediationOne-click fix via apt-get/dnf for packages with known fix versions | |||
| CSV exportFull vulnerability list exportable for compliance reporting | |||
| Kernel hardening auditVerify KASLR, SMEP, SMAP, KPTI, lockdown mode, module signing, ptrace scope, and more | |||
| Vulnerable kernel detectionMatch running kernel version against known exploitable CVEs and public exploits | |||
| Integrity & Device Control | |||
| File integrity monitoringSHA-256 hashing, configurable watch dirs, package-manager-aware baselines | — | ||
| USB device controlVID/PID/serial policy, BadUSB composite detection, sysfs enforce | — | ||
| Persistence scannerAudit crontabs, systemd units, shell rc files, udev rules, LD_PRELOAD, kernel modules | — | ||
| Honeypot tripwiresCanary files (fake SSH keys, credentials) that alert on any access | — | ✓ | ✓ |
| Endpoint Detection & Response | |||
| Process telemetryeBPF tracepoints for exec/exit, ProcessGUID correlation, process trees | — | — | |
| Network telemetryTCP connect/accept, UDP sendmsg via eBPF kprobes — 5-tuple + direction | — | — | |
| DNS telemetryPort-53 traffic correlated to processes — query + response | — | — | |
| Storyline correlationCausal view: parent→child GUID index, aggregate process + net + DNS for full trees | — | — | |
| IOC matching on network eventsCross-reference outbound connections and DNS queries against known-bad IP/domain threat intel feeds | — | — | |
| Privilege escalation detectioneBPF credential tracing — alert on uid 0 gained outside su/sudo/pkexec | — | — | Soon |
| Kernel integrity monitoringVerify syscall table, kprobe hooking, IDT, and module signing at runtime | — | — | Soon |
| Post-exploit rootkit detectionCross-reference kernel data structures against userspace to catch active rootkits | — | — | Soon |
| Definitions & Intelligence | |||
| Built-in YARA rulesCompiled into the binary — works offline, zero configuration | |||
| Signed definition packsEd25519-signed incremental updates — full malicious-package feed + threat rules | — | ||
| Community YARA rule feedsCurated rules from YARA-Forge, Elastic, signature-base | Soon | Soon | Soon |
| Fleet Management | |||
| Central consoleAgent enrollment, fleet-wide status, license management | — | — | |
| Policy pushPush settings, USB policy, and exclusions to enrolled agents | — | — | |
| Air-gapped definition mirrorsSelf-host definitions for offline or classified environments | — | — | |
| Compliance reportsPCI-DSS, NIST 800-53, HIPAA-ready audit exports across the fleet | — | — | |
| Slack and webhook notificationsPush threat detections, compliance drift, and agent-offline events to Slack, Discord, Teams, PagerDuty, or any webhook endpoint | — | — | Soon |
| Threat intelligence dashboardFleet-wide IOC hits, CVE exposure, detection trends, drill-down | — | — | Soon |
| Incident Response & Compliance | |||
| Event logTimestamped alert stream for scans, detections, remediations, USB events | |||
| Forensics exportOne-command IR bundle: events, quarantine, EDR timeline, FIM, system state | — | ✓ | ✓ |
| Container-aware scanningScan Docker/Podman images and running containers for vulns + malware | — | — | Soon |
| CIS Benchmark complianceAutomated checks against CIS Benchmarks for Ubuntu, Debian, RHEL | — | — | Soon |
| SIEM / SOAR exportStream events to Splunk, Elastic, Sentinel via syslog/CEF or webhook | — | — | Soon |
| Surfaces | |||
| CLIFull control from the terminal — every feature, scriptable, pipe-friendly | |||
| Desktop appTauri 2 native app with system tray, all tabs, theme switcher | |||
| Self-updateSigned release manifests — hound update pulls the latest .deb | |||