Every feature, every tier

Community is free forever with no account. Pro adds prevention. Team adds fleet-wide visibility. See exactly what each plan includes.

Feature CommunityFree Pro$96/yr Team$168/seat/yr
Scanning & Detection
On-demand file scanningYARA-x engine, CLI + GUI + right-click in file managers
Real-time fanotify interceptionWatches file opens across the filesystem, scans before access
Execution gateBlocks unknown binaries at execve — verdict before the process runs —
Quarantine vaultIsolates detected threats with original path + metadata preserved
Rootkit scannerHidden processes, kernel module anomalies, /proc tampering
Hash-based IOC matchingSHA-256 lookups against curated known-malware feeds during scans and real-time interception —
Payload execution blockingPrevent mmap+exec of exploit shellcode and anomalous memory-mapped executables — Soon Soon
In-memory exploit detectionDetect stack pivots, ROP chains, and JIT spray patterns in running processes — — Soon
Supply-Chain Protection
Dependency lock file scanningnpm, PyPI, Cargo, Go, Ruby, Composer — typosquat + known-malicious
Install-script analysisFlags postinstall hooks that pipe remote scripts to a shell
Pickle / model file analysisDetects code execution in .pt, .ckpt, .pkl model files
Prompt-injection detectionScans CLAUDE.md, .cursorrules, copilot-instructions for injection
MCP server for coding assistantsFour read-only tools so Claude / Cursor can check repos before trusting
Vulnerability Management
Package vulnerability scannerdpkg/rpm → OSV.dev with real CVSS severity, CVE IDs, fix versions
Auto-remediationOne-click fix via apt-get/dnf for packages with known fix versions
CSV exportFull vulnerability list exportable for compliance reporting
Kernel hardening auditVerify KASLR, SMEP, SMAP, KPTI, lockdown mode, module signing, ptrace scope, and more
Vulnerable kernel detectionMatch running kernel version against known exploitable CVEs and public exploits
Integrity & Device Control
File integrity monitoringSHA-256 hashing, configurable watch dirs, package-manager-aware baselines —
USB device controlVID/PID/serial policy, BadUSB composite detection, sysfs enforce —
Persistence scannerAudit crontabs, systemd units, shell rc files, udev rules, LD_PRELOAD, kernel modules —
Honeypot tripwiresCanary files (fake SSH keys, credentials) that alert on any access — ✓ ✓
Endpoint Detection & Response
Process telemetryeBPF tracepoints for exec/exit, ProcessGUID correlation, process trees — —
Network telemetryTCP connect/accept, UDP sendmsg via eBPF kprobes — 5-tuple + direction — —
DNS telemetryPort-53 traffic correlated to processes — query + response — —
Storyline correlationCausal view: parent→child GUID index, aggregate process + net + DNS for full trees — —
IOC matching on network eventsCross-reference outbound connections and DNS queries against known-bad IP/domain threat intel feeds — —
Privilege escalation detectioneBPF credential tracing — alert on uid 0 gained outside su/sudo/pkexec — — Soon
Kernel integrity monitoringVerify syscall table, kprobe hooking, IDT, and module signing at runtime — — Soon
Post-exploit rootkit detectionCross-reference kernel data structures against userspace to catch active rootkits — — Soon
Definitions & Intelligence
Built-in YARA rulesCompiled into the binary — works offline, zero configuration
Signed definition packsEd25519-signed incremental updates — full malicious-package feed + threat rules —
Community YARA rule feedsCurated rules from YARA-Forge, Elastic, signature-base Soon Soon Soon
Fleet Management
Central consoleAgent enrollment, fleet-wide status, license management — —
Policy pushPush settings, USB policy, and exclusions to enrolled agents — —
Air-gapped definition mirrorsSelf-host definitions for offline or classified environments — —
Compliance reportsPCI-DSS, NIST 800-53, HIPAA-ready audit exports across the fleet — —
Slack and webhook notificationsPush threat detections, compliance drift, and agent-offline events to Slack, Discord, Teams, PagerDuty, or any webhook endpoint — — Soon
Threat intelligence dashboardFleet-wide IOC hits, CVE exposure, detection trends, drill-down — — Soon
Incident Response & Compliance
Event logTimestamped alert stream for scans, detections, remediations, USB events
Forensics exportOne-command IR bundle: events, quarantine, EDR timeline, FIM, system state — ✓ ✓
Container-aware scanningScan Docker/Podman images and running containers for vulns + malware — — Soon
CIS Benchmark complianceAutomated checks against CIS Benchmarks for Ubuntu, Debian, RHEL — — Soon
SIEM / SOAR exportStream events to Splunk, Elastic, Sentinel via syslog/CEF or webhook — — Soon
Surfaces
CLIFull control from the terminal — every feature, scriptable, pipe-friendly
Desktop appTauri 2 native app with system tray, all tabs, theme switcher
Self-updateSigned release manifests — hound update pulls the latest .deb