| Best fit |
Lean teams adding external IOCs |
SOCs feeding SIEM and automation |
Security leaders needing deeper reporting |
Industrial, OT, and critical-infrastructure teams |
| Trial option |
Available |
Available |
Reviewed onboarding |
Reviewed OT onboarding |
| Data tier |
yellow_1 |
yellow_2 |
yellow_3 |
yellow_4 |
| Feed formats |
JSON, STIX-style, IOC JSON |
JSON, STIX-style, IOC JSON, payload JSON/STIX, CEF |
JSON, STIX-style, IOC JSON, payload JSON/STIX/CEF, delivery planning |
Yellow 3 formats plus OT/CI JSON, STIX, CEF, IOC, payload, analytics, and sector advisories |
| Indicator cap |
100 per request |
500 per request |
1,000 per request |
Custom reviewed volume |
| Customer reports |
Public report access |
Authenticated customer reports |
Executive-ready reporting support |
Sector-specific OT and critical-infrastructure briefings |
| Included signal |
Risk, confidence, ASN, country, protocol-derived client family, TTL, behavior labels, and email threat campaign summaries |
Starter plus payload hashes, command-pattern labels, extracted payload URLs/domains, related source IPs, SIEM context, SOC behavior summaries, phishing/malware delivery clusters, and usage analytics |
SOC Pro plus full ordered behavior timelines with observed commands, attacker fingerprints, campaign rollups, executive reporting, and custom integration planning |
Enterprise plus SCADA/OT device evidence, CI sector, asset, protocol, vendor-family, safety relevance, control-impact intent, and recommended defensive controls |
| Standard exclusions |
Raw payloads, raw headers, tokens |
Raw payloads, raw headers, tokens |
SCADA, OT, and critical-infrastructure device intelligence reserved for Yellow 4; red evidence remains restricted |
Red evidence remains restricted; no raw payload bodies, usable credentials, relays, or attacker-controlled outbound actions |