Skip to content

Serverless threat protection · formerly WebShieldThreat Studio.Serverless, pay as you go.

Threat Studio puts our threat protection in front of any app or API, with nothing to install and no gateway to run. A WAF with the OWASP Core Rule Set, IP reputation and bot control, every decision in one console, and a bill that follows the traffic you protect.

POST /login?user=admin'--

from 203.0.113.42 · hosting network

suspicious
  • IP reputation+40
  • Hosting network (ASN)+15
  • WAF · OWASP CRS+45
  • Bots & AI crawlers—
  • CrowdSec—
  • Honeypots—

100

threat score

logtarpitchallengedenyban Banned on every node

Nothing to run

A serverless service in front of any app or API, wherever it runs. No gateway to install, operate or scale.

WAF · OWASP Core Rule Set

SQL injections, cross-site scripting and the OWASP Top 10, stopped by a JVM-native WAF running the OWASP Core Rule Set.

IP reputation

Threat-intel feeds, CrowdSec and hosting networks score every caller before it reaches your app.

Bots & AI crawlers

Verify the crawlers that claim to be somebody, decide what AI crawlers may read, challenge the rest.

One threat score

Every detector adds up into one score, and the response is graded, from log to challenge to ban.

Pay as you go

Plans follow your protected requests and security events. Start for free, every feature in every plan.

Threat Studio in action

One suite. One console.

Activity, geography, logs, the decision fabric and the WAF: a tour of Threat Studio, the security console for Otoroshi.

Decision fabric

Every threat.
One score.

IP reputation, hosting networks, the WAF, bots and AI crawlers, honeypots: every detector adds its weight to one threat score for the request. The response is graded, from logging it to slowing it down, challenging it, denying it or banning the caller. Threat Studio shows what each protection lays down, how many decisions were enforced or only observed, and which detector decided.

  • IP reputation & CrowdSec
  • WAF · OWASP CRS
  • Bots & AI crawlers
  • Graded response, up to a ban
threat-studio · Overview
Threat Studio overview of a workspace: routes governed, protections armed, security decisions of the week, enforced versus observed, and which detector decided

Threat Studio · Protection

Observe first.
Then arm, one switch at a time.

The protection of your apps is a chain of sections: threat gate, bot guard, IP reputation, fail2ban, WAF, threat response. Each one can run in monitor or dry-run mode, recording what it would have done, before you arm it. Nothing blocks legitimate traffic by surprise.

  • Monitor & dry run
  • Arm section by section
  • Fail2ban
  • Graded threat response
threat-studio · Protection
Threat Studio Protection page: threat gate, bot guard, IP reputation, fail2ban, WAF and threat response sections

Threat Studio · WAF tuning

Fewer false positives.
Without lowering your guard.

When a rule fires on legitimate traffic, the tuning assistant shows where, and proposes the narrowest change that stops it: skip one argument on one path rather than switching a rule off everywhere. Each proposal says what it stops and what it no longer catches.

  • The narrowest exclusion
  • What it stops, what it misses
  • Learning mode
  • Rules and rule groups
threat-studio · WAF
Threat Studio WAF tuning: proposals to narrow rule 942100 on a path, with what each proposal stops and no longer catches

Threat Studio · Activity

See where attacks come from.
And what stopped them.

Every decision is recorded: by action, by detector, by route, by source and by country, enforced or only observed. Follow your traffic over time, open a decision to see the signals behind it, and the incidents that group them.

  • Geography of the decisions
  • Enforced versus observed
  • Detectors & sources
  • Bans & incidents
threat-studio · Activity
Threat Studio Activity page: the geography of the security decisions on a globe

Run it your way

Serverless, or on your own Otoroshi.

Pricing

Pay for the traffic you protect

Usage-based plans, by protected requests and security events per month. Every feature of Threat Studio is included in every plan.

Free

0 €/mo

Try Threat Studio, serverless, on a first app or API.

Try for free
  • 1,000 requests / month
  • 100 events / month
  • 1 environment

Tiger

16.49 €/mo

Essential protection for startups and small teams, for their first apps and APIs in production.

Subscribe
  • 50K requests / month
  • 5,000 events / month
  • 3 environments

Panda

99.99 €/mo

Growing businesses protecting more traffic, with bot control and tuned rules.

Subscribe
  • 200K requests / month
  • 15K events / month
  • 10 environments

Bear

399.99 €/mo

High-traffic apps and APIs, with tailored policies for every environment.

Subscribe
  • 2M requests / month
  • 150K events / month
  • 50 environments

Enterprise

Beyond 2 million requests a month, or with specific needs. A tailored plan with dedicated support for your critical applications.

  • Unlimited requests
  • Unlimited environments
  • Tailored policies
  • Dedicated support
Contact sales

Prices excl. VAT, per month.

FAQ

Frequently asked questions

Still have a question? Talk to our team.

What is Threat Studio?

Threat Studio is our threat protection as a serverless service, pay as you go. It puts the protection of our Threat Protection suite (WAF, IP reputation, bot control, one threat score) in front of any app or API, without any gateway to run, and you follow every decision in its console.

What happened to WebShield?

WebShield is now Threat Studio. It is the same serverless, pay-as-you-go protection, now named after the console where you configure it and follow every decision.

How is Threat Studio priced?

By usage. Each plan includes a volume of protected requests and security events per month, with every feature included. Start with the free plan, move up when your traffic grows, or contact us for a tailored plan.

Does Threat Studio affect the performance of my apps?

No. Threat Studio is designed to filter malicious traffic efficiently, without slowing down your applications.

Can I try a protection before blocking anything?

Yes. Protections can run in monitor or dry-run mode first: you see what would have been blocked, then arm them one at a time. The tuning assistant proposes the narrowest change when a rule fires on legitimate traffic.

Can I enable or disable specific WAF rules?

Yes. You can enable, disable or tune individual rules and rule groups to meet the needs of each environment.

I run my own Otoroshi. Is there an equivalent?

Yes, the open-source Threat Protection suite brings the same protection and Threat Studio to any Otoroshi cluster, and Threat Studio Enterprise opens the studio to your whole organization.

Ready to build?Start in minutes.

Spin up a managed Otoroshi cluster or a serverless project for free, or ask us for a live demo of the whole platform.