ThreatPipes Logo

Select the Perfect Plan

All plans include unlimited enrichment sources, unlimited exports, and unlimited users.

  • Research

  • Up to
  • 5 scans
  • /mo
  • Equivilant to 20 man hours
  • Unlimited enrichment sources
  • Unlimited exports
  • Unlimited users
  • UI only
  • 30 day data retention
  • Maximum of 500 enrichments / scan
  • Community support
  • $0
  • / month
  • Research +

  • Up to
  • 50 scans
  • /mo
  • Equivilant to 200 man hours
  • Unlimited enrichment sources
  • Unlimited exports
  • Unlimited users
  • UI only
  • 30 day data retention
  • Maximum of 1,000 enrichments / scan
  • Email support
  • $50
  • / month
  • Analyst

  • Up to
  • 500 scans
  • /mo
  • Equivilant to 2,000 man hours
  • Unlimited enrichment sources
  • Unlimited exports
  • Unlimited users
  • UI and API
  • 60 day data retention
  • Maximum of 2,000 enrichments / scan
  • Email support
  • $200
  • / month
  • SOC

  • Up to
  • 5,000 scans
  • /mo
  • Equivilant to 20,000 man hours
  • Unlimited enrichment sources
  • Unlimited exports
  • Unlimited users
  • UI and API
  • 90 day data retention
  • Maximum of 10,000 enrichments / scan
  • Dedicated support
  • $800
  • / month

FAQ

What is ThreatPipes?
ThreatPipes is a tool that automatically enriches IP addresses, domain names, e-mail addresses, file hashes and other threat indicators using 100's of intelligence data sources.
How does ThreatPipes work?
You enter the threat indicators you want to investigate and decide how you want to analyse them. ThreatPipes will collect data to build up a full understanding of the indicators and any related entities.
What enrichments do you support?
Some of existing enrichments include DNS, Whois, Web pages, passive DNS, spam blacklists, file meta data, threat intelligence feeds, SHODAN, and HaveIBeenPwned lookups. We regularly add new enrichment modules. Check our module library for the current list of enrichments. If you don't see what you're looking for, let us know.
What can I do with ThreatPipes?
The data returned from ThreatPipes will provide you with the context about a threat that can be leveraged during an investigation. To maintain existing your workflows, enriched threat indicators can be exported to any of your existing tools.
What is a scan?
Scans enrich an indicator of compromise. Each indicator of compromise you enter is enriched against 100's of sources during a scan. When a scan discovers a new piece of data, that data will also be enriched as part of the same scan.
I need more than 5,000 scans per month. Do you offer larger plans?
Yes. Contact us to discuss our larger plans.
What is community support?
You can get help from ThreatPipes staff and users on the ThreatPipes Slack community. All users will receive an invitation to join the community after registration.
Still have a question?
Contact our sales team for any further questions.