Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, correlation rules that detect allowed inbound traffic from malicious infrastructure, and SOAR playbooks that bring GreyNoise threat context into automated response workflows. Install the GreyNoise Foundry App to get started.

How CrowdStrike + GreyNoise Helps the SOC 

Every organization is under pressure as AI shortens time-to-exploitation and the volume of new exploits climbs. This is worst for organizations with large perimeter footprints, where edge devices lack the telemetry for real-time observability and alerting.

GreyNoise continuously observes internet-wide scanning and exploitation through a global sensor network, classifying the associated IPs, tagging the exploitation behavior seen, and recording the post-exploitation artifacts and command-and-control infrastructure used. That intelligence provides valuable context on the alerts generated in Falcon Next-Gen SIEM and enriches the workflows in Charlotte Agentic SOAR.

Falcon Next-Gen SIEM unifies detection and response with real-time dashboards, correlation rules, and centralized case management. Charlotte Agentic SOAR then combines structured workflows with agentic reasoning to drive machine-speed response.

Together, GreyNoise’s real-time intelligence adds valuable context inside the Falcon platform: dashboards for real-time edge observability, correlation rules to detect attacks on edge devices, and SOAR playbooks to automate triage and response.

What’s in the Integration

The integration delivers three categories of content.

  1. A Falcon Next-Gen SIEM dashboard visualizes successful inbound connections from GreyNoise-classified malicious IPs.
  2. Falcon Next-Gen SIEM correlation rules detect successful inbound connections from malicious IPs and allowed outbound traffic to C2 infrastructure. 
  3. Charlotte Agentic SOAR playbooks cover active exploitation response, compromised device response, and alert severity recategorization based on GreyNoise threat context.

Falcon Next-Gen SIEM Dashboard: Successful Inbound from Malicious IPs

Correlate inbound allow events from firewall and WAF telemetry in Falcon Next-Gen SIEM against GreyNoise, and surface sessions where known-malicious infrastructure was permitted through the perimeter. Built on Falcon Next-Gen SIEM’s live dashboard capabilities, it gives analysts a view of:

  • Successful inbound sessions from GreyNoise-classified malicious IPs, prioritized by source IP volume
  • The GreyNoise tags and classifications behind each source and what that IP has been observed doing across the internet

Falcon Next-Gen SIEM Correlation Rules: Detecting Successful Connections with Malicious Infrastructure

Falcon Next-Gen SIEM’s correlation rules surface detections that feed directly into its unified detection and response workflow.

Rule 1: Allowed Inbound from Malicious IPs

Triggered by firewall or WAF allow events, this rule flags inbound connections originating from IPs flagged as malicious or suspicious by GreyNoise. This is typically the infrastructure that GreyNoise has observed conducting mass scanning, exploitation, or credential abuse across the internet. This helps you detect perimeter gaps in real time rather than discovering them in incident response after the fact. Each detection is both a session to investigate and a policy gap to close.

Rule 2: Allowed Outbound to Malicious IPs

Internal hosts should not be connecting outbound to malicious infrastructure. When they do, it’s a high-fidelity indicator of compromise: C2 beaconing, data exfiltration, or botnet participation. This rule matches outbound connection events against GreyNoise-classified malicious destinations and surfaces the internal hosts involved.

Outbound volumes are typically too high to investigate anomalies manually; anchoring detection on destinations GreyNoise has observed behaving maliciously makes the problem tractable. That targeted enrichment cuts guesswork during triage and feeds the SOAR playbooks discussed next.

Charlotte Agentic SOAR Playbooks: Automated Response Enabled by Real-time Threat Context 

These playbooks bring GreyNoise context into Charlotte Agentic SOAR, so automated workflows act on real-time observation of attacker activity.

Playbook 1: CVE Exploitation Workflow

Organizations typically don’t see global exploitation spikes against their technology stack until it’s too late. GreyNoise observes surges in scanning and exploitation for specific CVEs as they happen. Oftentimes, this is activity that precedes vendor disclosures and KEV publications.

This playbook ingests GreyNoise CVE exploitation events into Charlotte Agentic SOAR and automates the response: case creation, vulnerability management ticketing, and blocklist updates for the IPs doing the exploiting. This can provide you an early warning when exploitation activity spikes against a CVE relevant to your tech stack.

Playbook 2: Compromised Device Workflow

Most edge devices are embedded systems that can’t run EDR agents. When these devices are compromised, they often scan the internet or call back to attacker-controlled infrastructure without triggering any alerts. 

This playbook runs when GreyNoise observes your own IP ranges conducting unsolicited scanning, or when internal hosts connect to known callback infrastructure. Charlotte Agentic SOAR ingests the alert, enriches with additional context, and creates a case and containment ticket, with persistent issues tracked in a single case timeline through Falcon Next-Gen SIEM’s centralized case management.

Playbook 3: Alert Severity Recategorization Based on GreyNoise IP Context

Analysts spend significant time manually looking up IPs to understand whether an alert really matters. This playbook automatically enriches alerts in Charlotte Agentic SOAR with GreyNoise classification and tags, and helps to determine the threat level. It then applies decision rules to recategorize case severity automatically.

An alert involving an IP GreyNoise has observed conducting active exploitation can be escalated. Enrichment is written to the case, so the rationale is visible to analysts and available to downstream workflows.

Get Started

The GreyNoise Foundry App is available now in the CrowdStrike Marketplace. Install it here to deploy the Falcon Next-Gen SIEM dashboard, correlation rules, and Charlotte Agentic SOAR playbooks in your CrowdStrike environment.

This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
Read the full report
GreyNoise Labs logo
Link to GreyNoise Twitter account
Link to GreyNoise Twitter account