The only difference between plans is alert volume and agent count. Every plan includes the full Ayzal AI platform with no feature gating.
| Category | Features |
|---|---|
| π€ Multi-Agent AI | SOC Agent (auth monitoring, file integrity), Metrics Monitor (CPU/memory/disk/network), Process Monitor (new process detection), DIAG System Diagnostics, Email Monitor, Device Monitor |
| π Login Monitoring | SSH login detection (Linux), RDP/Console login detection (Windows), LoginWindow detection (Mac), Physical login tracking with username & IP, Business hours awareness, Whitelist & baseline integration |
| π§ Email Security Monitoring | Brute-force detection, Impossible travel alerts, No-MFA login alerts, Inbox forwarding rules (BEC), Admin/delegate account creation, Mass email/spam relay detection, SPF/DKIM/DMARC validation, Malicious link/attachment detection, Whaling/impersonation detection |
| π Device Management | USB/Thunderbolt device monitoring, Device policy enforcement (block_all, monitor_only, allow_whitelist), USB storage blocking, Device event tracking with vendor/product ID, Policy auto-refresh on agents |
| π§ AI & Chat | AI Chat with conversation history, AI Analysis, AI Decision Engine, Conversational AI |
| π‘οΈ Threat Intelligence | MITRE ATT&CK mapping (25+ techniques), CVE integration, ThreatIntel model enrichment, Known-bad IP/domain database |
| π Integrations | CrowdStrike Falcon, Splunk, Wazuh, Generic Webhook, ServiceNow, Jira, Slack, Syslog, Exchange Online, and more |
| β‘ Auto-Remediation | 9 automated response triggers, IP blocking (single/range/CIDR), Process kill, File quarantine, Block on ALL servers or source only |
| π Network Whitelist | CIDR range whitelisting, Auto-detected network baselines, Trusted login networks, Whitelist auto-refresh on agents (60s) |
| π Client Portal | Real-time alert feed, API key management, billing/subscription, analytics, usage tracking, settings, Physical Logins widget, Device Events widget, Command Log with pagination |
| Attack Pattern | MITRE ID | Description |
|---|---|---|
| Brute Force | T1110 | Repeated login attempts to compromise accounts |
| Credential Dumping | T1003 | Extracting credentials from OS memory |
| C2 Communication | T1071 | Command & control traffic to attackers |
| Defense Evasion | T1562 | Disabling security tools and logs |
| Persistence | T1547 | Registry modifications and startup folder abuse |
| Data Exfiltration | T1048 | Unauthorized data transfer |
| Lateral Movement | T1021 | Moving across compromised hosts |
| Execution | T1059 | Command and script interpreter abuse |
| Initial Access | T1078 | Valid account compromise |
| Discovery | T1082, T1083 | System and file enumeration |
| Email Threats | T1566 | Phishing, BEC, spam relay, spoofing, whaling |
| Physical Login | T1078 | Unauthorized console/RDP access, off-hours login |
| Device Threats | T1200 | USB hardware attacks, unauthorized peripheral access |
| Feature | Starter | Professional | Business | Enterprise |
|---|---|---|---|---|
| Alerts/Month | 2,000 | 10,000 | 50,000 | Custom (100k+) |
| Concurrent Agents | 2 | 5 | 10 | Custom |
| All AI Features | β | β | β | β |
| All Integrations | β | β | β | β |
| Email Monitoring | β | β | β | β |
| Device Management | β | β | β | β |
| Login Monitoring | β | β | β | β |
| Auto-Remediation | β | β | β | β |
| MITRE Mapping | β | β | β | β |
| Dedicated Support | β | β | β | β |
| Custom Pricing | β | β | β | β |
| Plan | Alerts/Month | Agents | Price/Month | Best For |
|---|---|---|---|---|
| Starter | 2,000 | 2 | $149 | Small teams, startups |
| Professional | 10,000 | 5 | $399 | Mid-market SOC teams |
| Business | 50,000 | 10 | $1,199 | Large enterprises |
| Enterprise | Custom | Custom | Custom | Fortune 500, government |
| Differentiator | Benefit |
|---|---|
| Transparent Pricing | All features in every planβno enterprise gating |
| Modern AI Stack | AI Analysis + FedRAG for superior threat intelligence |
| Vendor-Agnostic | Works with CrowdStrike, Splunk, Wazuh, ServiceNow, Jira, Slack and more β no lock-in |
| Full MITRE Coverage | 25+ techniques mapped to standardized response playbooks |
| Privacy-First | Zero data sharing, hardware-enforced privacy |
| Proven Scale | 150,000+ alerts processed with 42 event types |
Ready to experience AI-powered SOC automation?
π Get 10 Days Trial Now - No Credit Card Required