Start free.
Upgrade when it earns it.

A personalised threat feed: 16,000+ sources clustered and deduplicated in real time, so one incident arrives as one cluster, not thirty alerts. Free forever, no card. When you need unlimited reads, dark web and alerts, a 7-day Researcher trial is one click away.

Compare plans

No card · 30 seconds · nothing to cancel

Individual
Free
A threat feed personalised to what you track — clustered, deduplicated, and updated in real time. No card, ever.
$0 forever
No card. No trial timer. 30 seconds to set up.
  • Reads per day
  • 3 cluster reads
  • 1 entity page
  • Defensive countermeasures (D3FEND)
  • Tracking
  • 5 tracked interests
  • Personalised My Feed
  • Delivery
  • Public RSS & MISP feeds (10 items)
  • No saved feeds (Researcher: 5)
  • No personalised digest
  • No webhooks or alerts
  • No report generation
  • No workflows
  • No dark web access
  • No API or CLI
Researcher
One analyst's daily work surface. Full read access, personal alerts, custom feeds.
$29.99 / month
Start with a 7-day free trial · Cancel anytime before day 7, no charge.
  • Reads per day
  • Unlimited cluster & entity views
  • Tracking
  • 20 alerting keywords (push: digest, webhooks, alerts)
  • 5 saved feeds (75 entities each) (personal)
  • 5 collections (100 items each)
  • Delivery
  • Personalised threat digest
  • 3 webhooks, 5 alert rules (personal)
  • Full RSS & MISP feed (50 items)
  • Programmatic
  • REST API & tc CLI (60 req/min, read-only scopes)
  • Bulk IOC export
  • Hunting
  • KQL / SPL / Lucene queries
  • ATT&CK Navigator export
  • Intelligence
  • Rising threats in Explore
  • X & Twitter intelligence
  • Dark web
  • Ransomware leak-site tracking
  • Credential market monitoring
  • Underground forum monitoring
For teams
Business
A SOC or CTI team's daily surface. Automation, org sharing, breach matching.
$399 / seat / month
Scales linearly. No seat floor.
Talk to us
  • Everything in Analyst, plus
  • 20 reports / day
  • Unlimited alerting keywords
  • 10 saved feeds (100 entities each)
  • 25 collections (100 items each)
  • 3 webhooks, 25 alert rules
  • 10 workflows (50 runs / day)
  • Org sharing
  • Share saved feeds with the org
  • Share webhooks across the org
  • Share alert rules across the org
  • Share workflows across the org
  • Org-level API keys with custom scopes
  • Unlocked at Business
  • REST API & tc CLI (120 req/min, full scopes)
  • MCP server access
  • AI-assisted feed creation
  • Breach matching (credential lookup)
  • Company / domain monitoring (full org footprint)
  • Exposure management (priced per device)
  • Dedicated support contact
MSSP
One account, every client. Per-customer scoping across the whole platform.
Custom
Per managed customer. No minimum, no cap.
Talk to us
  • Everything in Business, plus
  • Unlimited custom feeds, reports, workflows
  • Higher API rate limits
  • Multi-customer
  • Customer records (name, domain, contact, logo)
  • Per-customer scheduled digests
  • Per-customer exposure management
  • Customer-scoped alert routing
  • Aggregate MSSP dashboard
  • Delivery
  • White-labelled PDF reports per customer
  • AI-prompt-shaped digests per customer
  • Service
  • Dedicated account manager
  • Custom feature development

All plans run on the same live feed. The differences are limits and the surfaces you unlock around it.

Capability Free Researcher Analyst Business MSSP
Intelligence
Cluster views / day3UnlimitedUnlimitedUnlimited
Entity views / dayUnlimitedUnlimitedUnlimited
Smart analysis (summary, impact, technical, response) Read-only on free cluster
Threat scoring (0–100, four sub-scores)
Attack flows (CTID Attack Flow v3)
D3FEND countermeasures
CWE extraction
Public exploit tracking (Sonar)
Sub-article link enrichment
X / Twitter intelligence
Rising threats (Explore)
Dark web
Ransomware leak-site tracking
Credential market monitoring
Underground forum monitoring
Breach matching
Company / domain monitoring Single org Multi-customer
Exposure management — priced separately, per device
Asset inventory Per device Per device, per customer
Asset connectors (Tenable, Defender, CrowdStrike)
Bulk upload (CSV / JSON) and API push
CISA SSVC ranking
Asset tagging (internet-facing, crown-jewel, isolated)
Threat hunting
Industry threat models (17 sectors)
Hunting queries (KQL, SPL, Lucene)
Hunt playbooks
ATT&CK Navigator export
Diamond Model view
IOC watchlist export
Feeds & alerts
Alerting keywords — push to digest, webhooks, alerts 5 20 Unlimited Unlimited
Saved feeds — named views, RSS exports 3 10 Unlimited
Entities per saved feed 5 50 100 100
Org-shared saved feeds
Alert rules 3 25 Unlimited
Org-shared alert rules
Webhooks 1 3 Unlimited
Org-shared webhooks
Personalised threat digest General digest only Per customer
RSS feed 10 items 50 items 50 items 50 items
MISP feed 10 events 50 events 50 events 50 events
Workflows
Workflows 10 Unlimited
Workflow runs / day 50 Unlimited
Steps per workflow 10 20
Stored credentials 10 50
Triggers (cluster, CVE threshold, entity, KEV)
Actions (webhook, Slack, Teams, email, ticket, AI summary)
Dry-run against historical data
Per-workflow audit log
Reporting
Reports / day 10 Unlimited
Notion-style editor
Dynamic content blocks (live data on every render)
Scheduled delivery (daily / weekly / monthly / quarterly)
PDF / HTML / Markdown export
Public shareable URL
White-labelled reporting Org branding Per customer
Theming (dark / light, colours, fonts, logo)
MSSP
Multi-customer scoping
Customer records (name, domain, contact, logo, notes)
Customer portal (read-only client view)
Aggregate MSSP dashboard
Customer-scoped alert routing
Custom feature development
AI assistant
Ask AI per cluster / day 3 10 99
Cluster AI global search / day 10 100 Unlimited
Report editor AI inserts / day 30 200 Unlimited
Inline source citations
Collections & tags
Collections 1 5 25 Unlimited
Items per collection 10 100 100 500
Tags Unlimited Unlimited Unlimited
Team sharing with roles
IOC exports
TXT / CSV / JSON
STIX 2.1 bundles (TLP-marked)
Bulk IOC export (confidence / type / time filters)
Integrations
REST API 60 req/min 120 req/min Higher limits
tc CLI
API scopes Read-only (5 scopes) Full (all scopes) Full (all scopes)
Org-level API keys (custom scopes)
MCP server access
AI-assisted feed creation
Agent tool surface
SIEM ingestion (Splunk, Sentinel, Elastic, OpenSearch)
SOAR / ticketing (webhook routing)
included — not on this tier "Unlimited" means no enforced cap inside fair-use limits.

Can I try Researcher first?

Yes. The Free plan needs no card and lets you get a feel for how clustering reads. When you're ready, start a 7-day Researcher trial: you add a card but aren't charged until day 7, and you can cancel any time before then at no cost.

Why are Business and MSSP custom?

Both are scoped to your team or your book of clients. Custom feed counts, API limits, and white-labelling are easier to land in one short call than from a default price page. No procurement gauntlet — we keep it under an hour.

How is MSSP priced?

Per managed customer. No minimum, no cap. You can grow your book without rebuilding the contract every quarter.

What gets you onto the API?

Researcher and up. Researcher gets a read-only key (threats, IOCs, entities, vulnerabilities, feeds) at 60 req/min and the tc CLI. Business widens the scope set to include dark web and inventory, plus 120 req/min, MCP server access, and org-level API keys with custom scopes.

What about dark web?

Researcher gets full dark web access — leak sites, credential markets, and underground forum monitoring. Company / domain monitoring (your own domain) starts at Analyst; breach matching (credential lookup) is a Business feature. Free doesn't include any dark web surfaces.

How is exposure management priced?

Exposure management is scoped separately on a per-device basis on top of Business and MSSP, so the bill matches what you're actually monitoring rather than your seat count.

Do you offer annual billing?

Researcher is monthly. Business and MSSP are annual contracts by default, with quarterly options if that fits your finance calendar better.

Free for education, non-profits, and foundations?

Yes. Researcher is free for accredited educational institutions, registered non-profits, and cybersecurity foundations (CERTs, ISACs, threat-sharing communities, infosec charities). Request access via our contact form from your institutional address.

We grew up reading the same open writeups as everyone else. If you're a university, a registered non-profit, or a cybersecurity foundation (CERTs, ISACs, threat-sharing communities, infosec charities) — ThreatCluster Researcher is free.

Reach out via our contact form from your institutional address with a one-line description of what you're working on. We turn it around in a couple of days.

Request free access →

Pick a plan. Start reading the feed.

Free is one click. Researcher is one more. Business and MSSP are a short scoping call so we can match the contract to your team.

Talk to us