TrapLayer Intel

Subscribe to intelligence from a live deception network.

Better Actionable Intel from attacker interaction with AI, cloud, DevOps, database, email, SSH, and industrial-control lures: block-ready indicators, payload context, behavior intelligence, email threat campaign signals, SIEM payloads, and analyst-grade reporting.

Packages

Premium feeds for teams that need Better Actionable Intel.

Public dashboards show safe aggregate activity. Paid customers receive operational indicators, context, delivery formats, and reporting designed to drive block, challenge, hunt, monitor, and escalation workflows.

Starter

Threat Intel Starter

$499/mo

For lean security teams that want credible external telemetry without deploying and maintaining decoys.

  • Yellow 1 commercial data tier
  • JSON and STIX-style enriched indicators
  • Source IP IOC feed with risk, confidence, ASN, country, reason, and TTL
  • High-level behavior labels across SSH, SMTP, SCADA, cloud, DevOps, database, and AI-agent sensors
  • Email threat campaign summaries without raw message bodies
  • 100 indicators per request
  • Customer dashboard and API keys
Premium

Enterprise Intel

From $4,500/mo

For organizations that want broader coverage, deeper reports, and custom delivery planning around their security stack.

  • Everything in SOC Pro
  • Yellow 3 enterprise data tier with reviewed workflows
  • Attacker fingerprints, campaign rollups, MITRE/CVE context, and richer behavior-chain recommendations
  • Executive-targeted email campaign timelines and management-ready reporting
  • 1,000 indicators per request
  • Executive and analyst-ready reporting support
  • Custom delivery planning for Splunk, Sentinel, Elastic, S3, or webhook workflows
  • Future customer-stack lure network planning
Industrial intelligence

Critical Infrastructure Intel

From $7,500/mo

For water, telecom, energy, oil/gas, transportation, and manufacturing teams that need OT-aware deception intelligence and advisory support.

  • Everything in Enterprise Intel
  • Yellow 4 industrial and critical-infrastructure data tier
  • SCADA, OT, and critical-infrastructure device intelligence excluded from Yellow 3
  • OT sector, asset type, protocol, vendor-family, site-role, safety-relevance, and control-impact context
  • MITRE ATT&CK for ICS mapping where evidence supports it
  • Sector-specific advisories for water/wastewater, telecom, electric utility, oil/gas, transportation, and manufacturing activity
  • Recommended controls for exposed HMI, vendor remote access, cellular gateways, default credentials, VPN logs, and controller logic review
  • Multi-node facade deployment planning for office, field, database, and OT network slices

TrapLayer is not positioned as a low-cost blocklist. Pricing reflects live deception infrastructure, classifier context, IOC quality controls, and customer-ready reporting.

Plan Comparison

What each customer package includes

Public feeds are green data. Paid packages step up through yellow_1, yellow_2, yellow_3, and yellow_4 data tiers. Yellow 4 adds industrial/OT and critical-infrastructure intelligence; raw headers, payload bodies, session IDs, token values, and red evidence remain excluded from automated commercial feeds.

Capability Starter SOC Pro Enterprise Intel Critical Infrastructure Intel
Best fit Lean teams adding external IOCs SOCs feeding SIEM and automation Security leaders needing deeper reporting Industrial, OT, and critical-infrastructure teams
Trial option Available Available Reviewed onboarding Reviewed OT onboarding
Data tier yellow_1 yellow_2 yellow_3 yellow_4
Feed formats JSON, STIX-style, IOC JSON JSON, STIX-style, IOC JSON, payload JSON/STIX, CEF JSON, STIX-style, IOC JSON, payload JSON/STIX/CEF, delivery planning Yellow 3 formats plus OT/CI JSON, STIX, CEF, IOC, payload, analytics, and sector advisories
Indicator cap 100 per request 500 per request 1,000 per request Custom reviewed volume
Customer reports Public report access Authenticated customer reports Executive-ready reporting support Sector-specific OT and critical-infrastructure briefings
Included signal Risk, confidence, ASN, country, protocol-derived client family, TTL, behavior labels, and email threat campaign summaries Starter plus payload hashes, command-pattern labels, extracted payload URLs/domains, related source IPs, SIEM context, SOC behavior summaries, phishing/malware delivery clusters, and usage analytics SOC Pro plus full ordered behavior timelines with observed commands, attacker fingerprints, campaign rollups, executive reporting, and custom integration planning Enterprise plus SCADA/OT device evidence, CI sector, asset, protocol, vendor-family, safety relevance, control-impact intent, and recommended defensive controls
Standard exclusions Raw payloads, raw headers, tokens Raw payloads, raw headers, tokens SCADA, OT, and critical-infrastructure device intelligence reserved for Yellow 4; red evidence remains restricted Red evidence remains restricted; no raw payload bodies, usable credentials, relays, or attacker-controlled outbound actions

Intelligence summary

Summary