< Back to all blog posts

New GreyNoise Pricing - What We Changed and Why

Dan Maier

At GreyNoise, we value transparency. A lot. That’s why it really killed us when we took our pricing down off our website a month or so ago.

Well now, we’ve rolled our public pricing back out, with new product packaging that aligns to how security teams use us, and a pricing approach that encourages SOCs to maximize the value they get out of our data.

The changes you’ll see on our new pricing page are driven by the learning we’ve been doing. Our original premise was that SOC teams would use our data to automatically enrich alerts and indicators in their SIEM, SOAR and TIP tools, to help de-prioritize harmless events and filter out false positives.

But what we found when we dug into usage patterns surprised us - a ton of our customers were using GreyNoise to pivot and get context during investigations. So we spent the past month or so re-defining our products to match how our customers clearly want to use our data. Here’s an overview of our NEW product offerings and pricing:

GreyNoise Community - $0

GreyNoise Community is intended to be used by individual analysts trying to understand internet threats and vulnerabilities. It doesn’t cost any money to use this version of GreyNoise, and it will be free forever. GreyNoise Community includes:

  • Data - access to GreyNoise data via web UI and Community API
  • IP lookups - 50 per day
  • Advanced queries in the web UI - unlimited
  • Alerts - 3 active alerts
  • Bulk IP address analysis - 3 per day
  • Community API - 50 lookups per day
  • 3rd party tool integrations - all that support the Community API
  • GreyNoise Community Slack
  • Community events - preferred access to things like our Open Forum and “How I Use GreyNoise” webinars

Today we are approaching 20,000 users in the GreyNoise user community who are getting tremendous value out of our data, and sharing insights with the rest of the community. Come join us - create your own free Community account here.

GreyNoise Investigate - $25,000/year

GreyNoise Investigate is intended to be used by threat hunters and senior analysts who need to speed up investigations and research emerging threats and vulnerabilities, but don’t need to enrich alerts at high volumes. Based on customer feedback, we packaged up a set of features in Investigate to help analysts

  • quickly analyze and get context on suspicious IP addresses that have triggered security alerts or response protocols
  • identify and filter out IPs that represent noisy scanners, false positives, and non-targeted threats
  • identify IPs actively exploiting vulnerabilities and CVEs in the wild

And we priced it at an affordable flat rate, so SOC teams can use it as much as they need to. GreyNoise Investigate includes:

  • Data - access to GreyNoise data via web UI and Full Context APIs
  • IP lookups - unlimited lookups in the web-based Visualizer
  • Advanced queries - unlimited via web and API; export up to 50K results
  • Alerts - unlimited
  • Bulk IP address analysis - unlimited
  • IP Lookup APIs - 100 lookups per day
  • 3rd party tool integrations - unlimited
  • GreyNoise Community Slack
  • Community events - preferred access to things like our Open Forum and “How I Use GreyNoise” webinars
  • Enterprise customer support

GreyNoise Automate - $35K to $275K/year (up to 100K employees)

GreyNoise Automate is for security teams who need to unlock analyst capacity by automatically reducing noisy alerts. We designed it to help SOCs and security engineering teams:

  • Automatically enrich IP addresses in your SIEM, SOAR or TIP with turnkey GreyNoise integrations and REST API
  • Automatically reduce the priority of SIEM events generated by noisy scanners, false positives, and non-targeted threats.
  • Quickly triage alerts in your SOAR based on IP context
  • Identify and suppress false positive IP address indicators from your TIP

One of the biggest learnings we had was that our customers were rationing their usage of our data, because of our consumption-based pricing model. So we made the decision to price our Automate offering based on the size of our customer’s organization (measured by number of employees), and allow unlimited API lookups. Now our Automate customers no longer have to ration their daily queries, and they can focus on getting maximum value by implementing multiple use cases. GreyNoise Automate includes:

  • Data - access to GreyNoise data via web UI and Full Context APIs
  • IP lookups - unlimited lookups via web and API
  • Advanced queries - unlimited via web and API (but no results data export)
  • Alerts - unlimited
  • Bulk IP address analysis - unlimited
  • IP Lookup APIs - unlimited
  • 3rd party tool integrations - unlimited
  • GreyNoise Community Slack
  • Community events - preferred access to things like our Open Forum and “How I Use GreyNoise” webinars
  • Enterprise customer support

Other Areas

Note that the pricing described above is focused on enterprise customer use cases. That said, we also work with other customers and partners as well, including:

  • Managed Security Service Providers (MSSPs) and Managed Detection & Response (MDR) companies who use GreyNoise to optimize their security operations and analyst productivity. Contact us.
  • OEM/whitelabel partners who integrate GreyNoise data into their offerings. Contact us.
  • Channel partners who resell GreyNoise as part of a portfolio of offerings to their enterprise customers. Contact us.

We hope this pricing and product packaging resonates with customers and prospects, and we’d love to hear your thoughts and feedback. If you have a strong opinion, please let us know by shooting us an email at hello@greynoise.io.

And here’s a link to our beautiful new pricing page if you want to check it out.

Product Updates
Pricing and Packaging