

Build the tailored cybersecurity package that safeguards your brand, domains, executives, and attack surface, ready to scale when you are. You're just three steps to done, with a ZeroFox pro to guide you.





The fastest path to protection. Pre-built packages that cover the brand, domain, and executive risks that hit most often.
Plug in the extras—executive protection, takedowns at scale, deeper intel—no heavy lift. Choose what you need today and add more as your program matures.
Comprehensive monitoring and rapid takedowns to protect your organization from brand abuse, fraudulent domains, and impersonations before they impact your customers or revenue.
Your brand encompasses any and all external representation of your organization. Protect your digital presence, owned assets, accounts, logos, and trademarks against account hacking, impersonations, malicious content and reputation damage.
Your owned websites often serve as the first form of engagement a customer, prospect, candidate or employee uses to connect with your organization. Bad actors know this and create fraudulent, spoofed, and impersonating domains and URLs that trick your customers into providing information and damage to your brand. Protect your owned domains/sub-domains through continuous identification and remediation of impersonating domains and web pages used for trademark infringement, phishing, and more.
A protected domain is defined as any company domain affiliated with web, email, and unique consumer facing content. and/or employee infrastructure that should require advanced analysis and protection against fraud and cyber-based attacks.
Premium Executive Protection is an enterprise protection service that organizations, executives or high-profile individuals can leverage to minimize digital and real-world risks.
The ZeroFox External Attack Surface Management (EASM) solution defines and maps your organization's internet-exposed attack surface, identifying known and unknown assets. Utilize passive discovery to build an accurate inventory of your digital assets including domains, IP addresses, CIDR blocks, open ports, risky services, security certificates, shadow IT, code repositories, and more. Ongoing discoveries monitor for new exposures and changes to existing assets.
EASM combines advanced identification techniques with contextual vulnerability intelligence and prioritization capabilities to improve mean-time to detection (MTTD) and mean-time to response (MTTR) and reduce risk across your digital attack surface.
Automate remediation of offensive or inappropriate content for corporate or organizational Social Media accounts across Facebook, Instagram, LinkedIn, YouTube and Twitter (X).
Corporate Social Accounts are those owned social accounts and pages for which you have administrative control. Authenticated accounts within the Platform receive inline content moderation for offensive or inappropriate content postings on supported social networks.
Credit Card Protection helps prevent credit card fraud by discovering leaked or stolen credit card numbers and PINs for a single Credit Card Bank Identification Number (BIN). BINs are the initial 4 to 6 numbers that appear at the start of the long number on a payment card and identify the institution that issues the card.
Mobile App Protection discovers fraudulent, rogue, or malicious mobile applications impersonating a brand or organization across mobile app stores available on Android or IOS. A Mobile App is an application designed to run on a mobile device, whether that is a smartphone or tablet.
ZeroFox enables you to monitor and alert on expired SSL certificates, open ports, inferred vulnerabilities, and infected hosts within your vendor community. Discover risky or threatening content across the surface web and dark web channels that mention third party brands or related terms of your suppliers, contractors or other key partners.
Unlock a decisive edge with real-time insights from our global, proprietary, and correlated intelligence datagraph.
The ZeroFox Network & Vulnerability Intelligence Feed Bundle equips security teams to prevent intrusions, block exploits, and mitigate phishing with high-confidence threat data. It provides botnet breach data, malware, ransomware, IoCs, C2 domains, and vulnerabilities to enhance detection. This data integrates into block lists for firewalls, proxies, endpoint protection, and email gateways, or enriches alerts in SIEM, SOAR and other tools.
The ZeroFox Identity and Fraud Intelligence Feed Bundle helps security and fraud teams prevent credential theft, stop financial fraud, mitigate phishing, and protect PII. It delivers real-time intelligence on compromised credentials, breach-related credit cards, SSNs, and national IDs from botnets, data breaches, and dark web sources—often before threat actors act. The feed integrates with ID protection, fraud management tools, account databases, and SSO platforms, supporting KYC and PCI DSS compliance.
The ZeroFox Deep and Dark Web Feed Bundle provides unmatched visibility into threat actor activity across Telegram, Discord, encrypted apps, marketplaces, and invite-only forums. It delivers MITRE ATT&CK profiles, brand mentions, breach evidence, and ransomware coordination. Detecting early breach signs, credential sales, and attack planning, it helps stop impersonations, data leaks, and ransomware. Integrates with Threat News Feeds, TIPs, SIEM/SOAR, and ITSM for proactive threat mitigation.
(Integration of licensed threat intelligence feeds into security tools such as TIPs, SIEMs, SOARs, IAMs)
Connect ZeroFox Threat Intelligence Feeds with your other security tools and applications to enrich internal telemetry with unique external threat intelligence. Requires purchase of one or more Threat Intelligence Feed bundles which provide access to the individual endpoints.
Customers are entitled to support for integration enablement and ongoing Threat Intelligence API support and maintenance.
(integration of platform alerts feed to other security tools such as Splunk, SIEMs, SOARs)
Connect alerts from the ZeroFox platform with your other internal tools and applications to streamline your security programs. Leverage available market-leading partner applications to better streamline your response to external threats through alert orchestration and incident remediation. Also request takedowns through the API from your application. Customers are entitled to support for integration enablement and ongoing Platform API support and maintenance.
Safeguard your leaders from impersonation, doxxing, and escalating physical threats with a full-spectrum solution.
Add on to Executive Protection with support for up to 10 executives across either Executive Protection or Premium Executive Protection. Adds a one-time Deep and Dark Web sweep/assessment and subsequent customer briefing as well as bundled topical investigative assessments. Coverage includes PII monitoring and removal and cyber threat protection (OSINT + DDW) for executive mentions, personal assets, family security threat notifications, and high-severity threat escalations via platform alerts.
Add on to Executive Protection with support for up to 10 executives across either Executive Protection or Premium Executive Protection. Supplements manual collection of threats directed toward executives with monitoring for physical security and reputation-based threats via pooled analyst resources and managed DarkOps engagement. Includes a one-time Deep and Dark Web sweep/assessment and subsequent customer briefing as well as bundled topical investigative assessments. Coverage includes PII monitoring and removal and cyber threat protection (OSINT + DDW) for exec mentions, personal assets and family security threat notifications, and high-severity threat escalations via platform alerts, SMS, and phone.
Add on to Executive Protection with support for up to 20 executives across either Executive Protection or Premium Executive Protection. Supplements manual collection of threats directed toward executives with monitoring for physical security and reputation-based threats via named HT OnWatch Expert (up to 20 hrs per week) and Managed DarkOps engagement. Includes a one-time Deep and Dark Web sweep/assessment and subsequent customer briefing as well as bundled topical investigative assessments. Coverage includes PII monitoring and removal and cyber threat protection (OSINT + DDW) for exec mentions, personal assets and family security threat notifications, high-severity threat escalations via platform alerts, SMS, or phone, curated analyst deliveries and global intelligence on the executive security landscape.
Stop threat actors from compromising external assets for profit or exploiting them as entry points into your environment with industry-leading takedowns and remediation.
ZeroFox saves you from the manual, costly and arduous process of finding and taking down malicious profiles and dangerous content, working on your behalf to process and report directly to the source provider for successful takedown removal.
ZeroFox goes above and beyond by working with disruption partners that block or flag malicious adversary infrastructure. By working closely in partnership with the collective intelligence of our Global Disruption Network (GDN), ZeroFox can disrupt complex threat actor campaigns and prevent future attacks from threatening your people, brands and critical business assets.
ZeroFox provides assessments and filings* for Uniform Domain Name Resolution Policy (UDRP) disputes with an ICANN approved provider (ZeroFox uses the World Intellectual Property Organization or WIPO). All UDRP filings are governed by WIPO terms, processes and fees. To read more about those details, see here. ZeroFox will only file a dispute after a UDRP assessment has been made.
*The Complaint may relate to more than one domain name, so long as the person or entity that is the registrant of the domain names specified in the Complaint is the same. If multiple identified domain names are listed under different Registrants, then separate filings must be made to accommodate each. (ex: 5 domains have 5 separate registrants, then this must be 5 separate UDRP filings). This is a WIPO rule.
Identify and monitor relevant threats to your organization with rapid, actionable, and best-in-class intelligence.
Your brand encompasses any and all external representation of your organization. Protect your digital presence, owned assets, accounts, logos, and trademarks against account hacking, impersonations, malicious content and reputation damage.
ZeroFox OnWatch Expert service provides a full-time (up to 40 hrs per week), dedicated, named analyst who performs as a key member of your security operations team. Rely on an experienced security intelligence analyst who provides expert threat analysis, routine threat reporting, and regular executive briefings. Our analysts access the world's most historically accurate, correlated data graph of threat indicators and attack data, including unique data from embedded dark web operatives.
Strengthen your security posture, fill skill and coverage gaps, address seasonality and geographic variances, and quickly supplement your team without the burden of hiring and retaining additional staff.
A Dark Ops specialist will populate intelligence in the form of Key Incidents from closed, exclusive deep and dark web forums (DDW) and marketplaces, unavailable by traditional collection methods into the ZeroFox Platform.
A Dark Ops specialist will populate intelligence in the form of Key Incidents from closed, exclusive deep and dark web forums (DDW) and marketplaces, unavailable by traditional collection methods into the ZeroFox Platform.
A Dark Ops specialist will populate intelligence in the form of Key Incidents from closed, exclusive deep and dark web forums (DDW) and marketplaces, unavailable by traditional collection methods into the ZeroFox Platform.
A named TI Analyst (Up to 40hrs/week), will perform as an extension of your security operations team. Analyst resources are trained to serve as experienced intelligence professionals who deliver various artifacts and services that address intelligence requirements. Analysts can be expected to produce recurring intelligence output, executive summaries, metrics reports, security briefings and mutually agreed-upon custom deliverables.
Dark Ops specialists populate intelligence in the form of Key Incidents from closed, exclusive deep and dark web forums (DDW) and marketplaces, unavailable by traditional collection methods into the ZeroFox Platform.
While the customer can elect for the OnWatch Expert analyst to come on-site to their facilities, the Dark Ops specialist working on their account will always need to be 100% remote.
ZeroFox's OnDemand Investigation and Incident Support provides highly-skilled intelligence analysts who deliver deep-dive reports, technical cybersecurity analysis, threat assessments, research projects, and as-requested analytic projects tailored to your organization.
Provides in-depth analysis on adversaries, campaigns, targets, and brand exposure assessments and reporting according to your intelligence requirements and RFIs.
Provides unlimited access to ZeroFox’s unique threat intelligence graph, comprised of over 12 billion interconnected records. Search across threat actors, indicators, malware, dark web activity, breaking news, and curated intelligence reports. Accelerate investigations and uncover actionable insights by mapping critical relationships in real time, empowering smarter, faster decision-making.
Includes finished intelligence and datasets containing IoCs for Command & Control, Botnet Logs, Covert Communication Channels, Compromised Credentials, and more.
ZeroFox PSI Essential is an enterprise intelligence service that provides near real-time alerting for up to 5 configured locations, as well as global geovisualization of physical security incidents, geopolitical intelligence, and access to the PSI Mobile App (1 mobile license per analyst seat).
ZeroFox PSI Premium is an enterprise intelligence service that provides near real-time alerting for up to 20 configured locations, geovisualization, geopolitical intelligence of global physical security threats, and access to the PSI Mobile Application (1 mobile license per analyst seat).
ZeroFox PSI Elite is an enterprise intelligence service that provides near real-time alerting for up to 5,000 configured locations, geovisualization, geopolitical intelligence of global physical security threats, and access to the PSI Mobile Application (1 mobile license per analyst seat).
ZeroFox Professional Services, Certifications & Add-Ons
ZeroFox's Technical Account Managers (TAM) are dedicated, platform technical specialists who can provide continuous, proactive configuration management, platform monitoring and tuning, technical escalations and disruption escalations for customers that need assistance beyond standard ZeroFox OnWatch Alert service.
Premier Support offers a high-touch, comprehensive support experience designed to maximize the performance and reliability of your platform. This level of support is ideal for organizations seeking personalized guidance, faster resolution times, and proactive management to ensure long-term success.
Straightforward packaging, a unified platform, clear outcomes. Your ZeroFox representative will help you explore the right cybersecurity option for your organization.
ZeroFox currently accepts USD, EUR, GBP, CAD, and SGD for all transactions.