Pricing
Choose the plan that fits your investigation needs.
Community
Core investigation capabilities — free forever.
Free
- 1 user
Included features:
- Guided IR workflows
- Response actions (containment + remediation)
- Local LLM processing (Ollama, LM Studio, llama.cpp, litellm)
- Cloud LLM (Anthropic Claude, Google Gemini, OpenAI GPT)
- External threat intelligence (VirusTotal, AbuseIPDB, Shodan, URLhaus, ThreatFox + more)
- Two-factor authentication (TOTP)
Configurable sources:
- Microsoft Entra ID
- Microsoft Defender for Endpoint
- Active Directory
Log-based evidence sources:
- Log file ingestion (EVTX, .log, .csv, .json)
- PCAP / wireless capture analysis
- Syslog
- DNS logs
- DHCP logs
- Web access logs
Most Popular
Professional
Advanced integrations and analysis for security teams.
POA
- 1 to 3 users
Everything in Community, plus:
- Case narrative
- CrowdStrike Falcon
- Evidence Export
- Global Source Connectors
- Incidents view
- Multiple Investigations
- Single sign-on (OpenID Connect)
- Single sign-on (SAML 2.0)
- System Backup Restore
- Ubiquiti UCG
- Unlimited File Uploads
Enterprise
Full platform with automation, custom reporting, and premium integrations.
POA
- Unlimited users
Everything in Professional, plus:
- Advanced reporting (NDB, Insurance, Legal Hold, etc.)
- AWS CloudTrailComing Soon
- BigID
- Blast radius analysis
- Exfiltration detection
- External tool execution (BloodHound, NetExec, etc.)
- Google WorkspaceComing Soon
- Microsoft 365 (Graph)
- Palo Alto NetworksComing Soon
- Playbook Content Sampling
- Playbooks
- ProofpointComing Soon
- Microsoft Purview
- Reporting (PDF, DOCX, HTML, JSON, Markdown)
- SentinelOneComing Soon
- Sophos Taegis
- SplunkComing Soon
- Varonis
All plans include the CICADA IR VM appliance. Need a custom deployment or volume licensing? Contact sales