Product

Product announcements, new feature launches, and roadmap updates — everything you need to stay current on evolving GreyNoise solutions.

Introducing Tactics: See What Adversaries Do After They’re Inside

GreyNoise has spent years observing the earliest stages of an attack. Our Global Observation Grid sees adversaries as they scan the internet, probe exposed systems, and attempt to exploit vulnerabilities at the edge. That visibility has traditionally focused on the left side of the MITRE ATT&CK framework, from Reconnaissance through Initial Access and it’s where we built our primary-source intelligence brand.

But we’ve known that is only half the equation.

Moving Further Right on MITRE ATT&CK

Earlier this year, we launched our C2 Detection Module, expanding our visibility beyond inbound scanning to the attacker-controlled infrastructure used after exploitation. GreyNoise reads the callback destinations embedded in exploit payloads to identify where a compromised device would call home, from malware-hosting servers to suspected C2 infrastructure.

This marked our first move right of Initial Access on MITRE ATT&CK, extending visibility beyond the exploit itself to the infrastructure supporting what happens next. Defenders can match outbound traffic from their edge devices against GreyNoise callback intelligence to identify connections to confirmed malware-serving infrastructure or suspected C2 servers.

See Host Telemetry from GreyNoise Deception Sensors on Your Network 

When we launched Project Swarm, we opened our deception platform to the global security community. Participants could deploy GreyNoise Deception Sensors across their own infrastructure that looked like the firewalls, routers, VPN gateways, and other internet-facing systems that adversaries target.

Project Swarm users gained full visibility into the sessions reaching their sensors, including raw payloads, HTTP headers, TLS metadata, and other behavioral artifacts. 

But a common ask from them was deeper visibility into what happened after an exploit succeeded. What shell commands did the adversary run? What files did they touch? What did they try to do next?

Introducing GreyNoise Tactics

Today, we are launching Tactics, giving anyone deploying a GreyNoise Deception Sensor deeper visibility into what attackers do after initial compromise. 

Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping.

You can find Tactics under Observe → Tactics in the GreyNoise Visualizer. Open a detection to:

  • Follow the attacker’s complete command sequence
  • See the commands, scripts, and binaries the adversary executed
  • Inspect files created or modified, including their SHA256 hashes
  • Review outbound connections to internet destinations
  • Identify attempts to move laterally within your address space

Tactics begin populating when your workspace has a sensor running a vulnerable profile. Once an attacker compromises that profile and performs activity mapped to a MITRE ATT&CK technique, the session will appear as a detection.

Routine and unclassified sessions are filtered out, so the view focuses on meaningful adversary behavior rather than every connection your sensor receives.

See What Happens After the Shell

Because GreyNoise captures the attacker’s interaction with the host, Tactics can identify behavior across the post-compromise stages of MITRE ATT&CK.

That includes:

  • Execution: Commands, scripts, and binaries run after gaining access
  • Persistence: Scheduled jobs, new accounts, and other attempts to maintain access
  • Privilege Escalation: Attempts to gain greater control of the host
  • Defense Evasion: Actions intended to hide activity or interfere with protections
  • Credential Access: Searches for cloud credentials, private keys, service account tokens, and other secrets
  • Discovery: Commands used to inspect the operating system, processes, files, and surrounding environment
  • Lateral Movement: Attempts to reach other systems from the initial foothold, a view that keeps expanding as our deception network grows 
  • Collection: Files and data gathered from a system they think they’ve compromised 
  • Command and Control: Connections used to retrieve payloads or maintain access
  • Exfiltration: Attempts to move credentials, files, or other data off the sensor
  • Impact: Activity intended to disrupt the host, consume resources, or interfere with processes

With Tactics, GreyNoise now shows what adversaries do with access, not just how they find and exploit exposed systems.

Turn Observed Behavior Into Action

Every command, file, hash, path, and network connection captured by a sensor gives defenders a lead they can investigate inside their own environment.

  • SOC analysts and detection engineers can build and tune detections around the commands and techniques adversaries are using now.
  • Threat hunters can search production environments for observed hashes, file paths, binaries, and command patterns.
  • Threat intelligence teams can track which tactics and techniques are appearing across infrastructure relevant to their organization.

Because this intelligence comes directly from observed session activity, defenders can work from what the adversary actually did after gaining access. Mapping that activity to MITRE ATT&CK makes it easier to understand and use across existing security workflows.

What We Found After the Shell

Before launching Tactics, we analyzed weeks of post-compromise activity across our own Deception Sensor network in the Global Observation Grid.

Much of what we observed was commodity cryptomining, with adversaries treating each new foothold as more infrastructure to consume. A smaller set of sessions showed more serious behavior, going after cloud credentials, attempting container escapes, or creating backdoor accounts.

We break down these findings in After the Shell, a new GreyNoise research report published today. It examines what adversaries did after gaining access, which behaviors appeared most often, and what those observations mean for defenders.

Join the Swarm

Tactics is available for all users who have deployed a GreyNoise sensor. If you already have a sensor deployed, open Tactics under Observe in the GreyNoise Visualizer to see what it has captured.

If you’re new to Project Swarm, deploy a Greynoise Deception Sensor to start observing what attackers do after compromise.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

A New Way to Navigate GreyNoise

Over the past year, GreyNoise has moved further right on MITRE ATT&CK, helping defenders detect and investigate activity at the edge, uncover signs of compromise, and analyze the artifacts captured from their own sensors.

Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.

Organized around how you work

The most noticeable change is the navigation.

Instead of dropdown menus across the top of the Visualizer, the new experience uses a persistent sidebar organized around three areas:

  • Intelligence for investigating IPs and CVEs
  • Observation for working with their own Deception Sensors and exploring the sessions, activity, and post-compromise behavior they capture
  • Automation for actioning on GreyNoise intelligence via alerts, feeds, and blocklists

Dashboards sit at the top, giving you a quick way to return to the intelligence you care about most. 

See the new Visualizer in action

Watch a quick walkthrough of the redesigned Visualizer, including the new navigation, search experience, and updated investigation workflows.

Search from anywhere

Search is now available throughout the Visualizer.

Open it from the sidebar, use Command + K, or start from the Visualizer home page. From the same search experience, you can look across IPs, Callback, CVEs, and Tags.

For IP investigations, we’ve also changed how GreyNoise Query Language (GNQL) queries are displayed. Individual search terms can be shown as badges, making it easier to add or remove filters, switch between AND and OR, and refine a search without rewriting the entire query.

Prefer writing GNQL directly? You can switch back to raw query text at any time.

Intelligence, investigation, and action are closer together

Several workflows that previously lived on separate pages now sit directly alongside the intelligence they relate to.

When you’re investigating scanner IPs, for example, the same query can be used to create an alert or blocklist from the Actions menu. Compare is now a view within IP search rather than a separate destination. IP and CVE bulk analysis now live together under Analysis.

The same principle carries across the Visualizer: related actions are available where you’re already working.

Triage and investigate with more context

When an IP shows up in an alert or investigation, the IP details page brings together the different ways GreyNoise may know about it.

Depending on the address, you may see intelligence from up to three GreyNoise datasets:

  • Scanner for activity GreyNoise has directly observed from the IP as it scanned the internet
  • Callback when the IP has appeared as a destination inside an observed exploit payload
  • Business Service when the IP belongs to a known business service

When an IP appears in more than one dataset, you can move between them directly from the IP page. Scanner activity, related CVEs and tags, callback activity, and business service context are available without moving between separate parts of the Visualizer.

For analysts working through alerts or investigating suspicious infrastructure, that puts more of the context needed to understand an IP in one place.

Your sensors and what they observe, in one place

The Observation section brings together the workflows associated with GreyNoise Deception Sensors. 

From here, you can deploy and manage Deception Sensors, assign profiles, inspect the individual sessions they capture, and review post-compromise activity mapped to MITRE ATT&CK tactics and techniques. Sessions are available as a list, graph, or multi-pane view, with the underlying PCAP available from the individual session.

You can also compare what your sensors observe with the broader GreyNoise sensor network. This helps teams understand what is reaching their own edge, what attackers are doing when they get there, and how that activity compares with what GreyNoise is observing across the internet.

Turn what you find into action

The Automation section brings Alerts, Feeds, and Blocklists together.

You can still manage each independently, but automation is also built directly into the investigation workflow. A useful GNQL search can become an alert that watches for new activity or a continuously updated blocklist. Alerts can also be created directly from the IP, Tag, and CVE workflows where applicable, while Feeds can stream GreyNoise events into downstream systems.

This makes it easier to move from investigating activity in GreyNoise to monitoring it or taking action in your existing tools. 

Try the new Visualizer today

The new Visualizer is available today. If you’re logged in to the Classic Visualizer, click Try the New Visualizer in the upper-right corner. To switch back, click Classic from the new Visualizer header.

Your preference is saved to your GreyNoise account, so it follows you across devices.

For a complete walkthrough of the new navigation, search experience, feature locations, and what moved from the Classic Visualizer, see the New Visualizer Documentation.

Introducing Tactics: See What Adversaries Do After They’re Inside

GreyNoise has spent years observing the earliest stages of an attack. Our Global Observation Grid sees adversaries as they scan the internet, probe exposed systems, and attempt to exploit vulnerabilities at the edge. That visibility has traditionally focused on the left side of the MITRE ATT&CK framework, from Reconnaissance through Initial Access and it’s where we built our primary-source intelligence brand.

But we’ve known that is only half the equation.

Moving Further Right on MITRE ATT&CK

Earlier this year, we launched our C2 Detection Module, expanding our visibility beyond inbound scanning to the attacker-controlled infrastructure used after exploitation. GreyNoise reads the callback destinations embedded in exploit payloads to identify where a compromised device would call home, from malware-hosting servers to suspected C2 infrastructure.

This marked our first move right of Initial Access on MITRE ATT&CK, extending visibility beyond the exploit itself to the infrastructure supporting what happens next. Defenders can match outbound traffic from their edge devices against GreyNoise callback intelligence to identify connections to confirmed malware-serving infrastructure or suspected C2 servers.

See Host Telemetry from GreyNoise Deception Sensors on Your Network 

When we launched Project Swarm, we opened our deception platform to the global security community. Participants could deploy GreyNoise Deception Sensors across their own infrastructure that looked like the firewalls, routers, VPN gateways, and other internet-facing systems that adversaries target.

Project Swarm users gained full visibility into the sessions reaching their sensors, including raw payloads, HTTP headers, TLS metadata, and other behavioral artifacts. 

But a common ask from them was deeper visibility into what happened after an exploit succeeded. What shell commands did the adversary run? What files did they touch? What did they try to do next?

Introducing GreyNoise Tactics

Today, we are launching Tactics, giving anyone deploying a GreyNoise Deception Sensor deeper visibility into what attackers do after initial compromise. 

Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping.

You can find Tactics under Observe → Tactics in the GreyNoise Visualizer. Open a detection to:

  • Follow the attacker’s complete command sequence
  • See the commands, scripts, and binaries the adversary executed
  • Inspect files created or modified, including their SHA256 hashes
  • Review outbound connections to internet destinations
  • Identify attempts to move laterally within your address space

Tactics begin populating when your workspace has a sensor running a vulnerable profile. Once an attacker compromises that profile and performs activity mapped to a MITRE ATT&CK technique, the session will appear as a detection.

Routine and unclassified sessions are filtered out, so the view focuses on meaningful adversary behavior rather than every connection your sensor receives.

See What Happens After the Shell

Because GreyNoise captures the attacker’s interaction with the host, Tactics can identify behavior across the post-compromise stages of MITRE ATT&CK.

That includes:

  • Execution: Commands, scripts, and binaries run after gaining access
  • Persistence: Scheduled jobs, new accounts, and other attempts to maintain access
  • Privilege Escalation: Attempts to gain greater control of the host
  • Defense Evasion: Actions intended to hide activity or interfere with protections
  • Credential Access: Searches for cloud credentials, private keys, service account tokens, and other secrets
  • Discovery: Commands used to inspect the operating system, processes, files, and surrounding environment
  • Lateral Movement: Attempts to reach other systems from the initial foothold, a view that keeps expanding as our deception network grows 
  • Collection: Files and data gathered from a system they think they’ve compromised 
  • Command and Control: Connections used to retrieve payloads or maintain access
  • Exfiltration: Attempts to move credentials, files, or other data off the sensor
  • Impact: Activity intended to disrupt the host, consume resources, or interfere with processes

With Tactics, GreyNoise now shows what adversaries do with access, not just how they find and exploit exposed systems.

Turn Observed Behavior Into Action

Every command, file, hash, path, and network connection captured by a sensor gives defenders a lead they can investigate inside their own environment.

  • SOC analysts and detection engineers can build and tune detections around the commands and techniques adversaries are using now.
  • Threat hunters can search production environments for observed hashes, file paths, binaries, and command patterns.
  • Threat intelligence teams can track which tactics and techniques are appearing across infrastructure relevant to their organization.

Because this intelligence comes directly from observed session activity, defenders can work from what the adversary actually did after gaining access. Mapping that activity to MITRE ATT&CK makes it easier to understand and use across existing security workflows.

What We Found After the Shell

Before launching Tactics, we analyzed weeks of post-compromise activity across our own Deception Sensor network in the Global Observation Grid.

Much of what we observed was commodity cryptomining, with adversaries treating each new foothold as more infrastructure to consume. A smaller set of sessions showed more serious behavior, going after cloud credentials, attempting container escapes, or creating backdoor accounts.

We break down these findings in After the Shell, a new GreyNoise research report published today. It examines what adversaries did after gaining access, which behaviors appeared most often, and what those observations mean for defenders.

Join the Swarm

Tactics is available for all users who have deployed a GreyNoise sensor. If you already have a sensor deployed, open Tactics under Observe in the GreyNoise Visualizer to see what it has captured.

If you’re new to Project Swarm, deploy a Greynoise Deception Sensor to start observing what attackers do after compromise.

Now Available: Intelligence Dashboard in the GreyNoise Platform

Every day, GreyNoise's global sensor network observes scans and attacker traffic from hundreds of thousands of IPs across the internet. GreyNoise analyzes that activity to understand what each IP is doing, why it matters, and which tags and CVEs are connected to it. You can explore it all in the Visualizer.

The Intelligence Dashboard, available now, gives that intelligence a home. You can pin any combination of CVEs, tags, countries, IPs, and GNQL queries into one persistent, always-current view. Open it, and the activity you care about is already there, up to date.

See the Intelligence Dashboard in action

The first time you open the Dashboard tab, GreyNoise builds a Daily Intelligence Dashboard for you, stamped with today’s date and populated from what is currently notable across the sensor network. It is a starting point, not something you have to maintain. Edit it, save your own version, or let it regenerate fresh the next day.

Watch how to build a dashboard from scratch, add and configure panels, and save it for ongoing use.

What you can put on a dashboard

A dashboard is a set of panels. Each panel combines a panel type (how the data is shown) with a focus (what it shows activity for).

There are five panel types:

Panel Type What It Shows
Key Numbers Headline counts for your focus: observed IPs, source countries, top classification, and a top tag.
Activity Map A world map of the countries involved in the focused activity, colored by whether each country is a source of activity, a destination, or both.
Activity Trend A line chart of activity over the selected time range.
Tag Details The full intelligence card for one GreyNoise tag: description, classification, block/monitor recommendation, associated CVEs, references, and an activity graph.
CVE Details The intelligence card for one CVE: description, active-exploitation and CISA KEV status, CVSS score, EPSS score, threat IP count over the last day, and related tags.

And five ways to focus a panel:

Focus Description Available Panels
IP address One IP address Key Numbers, Activity Map
CVE One vulnerability (e.g. CVE-2021-22873) Key Numbers, Activity Map, Activity Trend, CVE Details
Tag One GreyNoise tag Key Numbers, Activity Map, Activity Trend, Tag Details
Country Activity involving one country Key Numbers, Activity Map
GNQL query Any custom GNQL query (e.g. tags:mirai classification:malicious) Key Numbers, Activity Map, Activity Trend

The GNQL focus is the most flexible option. Any query you already run in GreyNoise can become a live dashboard panel, so a standing query like tags:mirai classification:malicious turns into something you watch instead of rerunning every time. Just give the panel a name (a sensible default is suggested), and click *Add Panel*.

Make it your own

Every dashboard is built from panels, and adding one takes just a few clicks: pick a panel type and a focus, give it a name, and it lands on your dashboard already populated. You can drag panels to rearrange them, resize them, or expand any panel to full screen.

For the full step-by-step, including every panel type, focus option, and layout control, see the Intelligence Dashboard documentation.

Navigating a dashboard

Two controls in the header apply to every panel at once:

  • Time range: switch the whole board between the past 24 hours and the past 10 days.
  • Data source: choose which sensor data the panels query. GreyNoise’s global network by default, Community sensors, your own workspace sensors, or a combination. 

The Activity Map is worth a closer look. Countries are color-coded to show whether they are the source of activity, the destination, or both. Click any country on the map or in the sidebar to see the IPs the activity is coming from and the IPs being targeted, along with the organization that owns each one. Every IP links to its detail page, while “View all IPs” in the Visualizer opens the full result set as a GNQL query. When building a map panel, you can also filter it by source or destination country. For example, you could create a map that only shows activity targeting the regions where you operate.

Changes are not saved automatically. When you have unsaved edits, a banner appears with a “Save” button. The dashboard manager, accessed through the panel icon in the header, lets you switch between saved dashboards, search by name, create a new dashboard, or delete one. Dashboards are personal to you within your workspace. You can save up to 50 dashboards, with up to 24 panels in each.

Quick tip: which data source should I use?

  • Use GreyNoise to see what is happening across the internet at large.
  • Use My Workspace to focus a dashboard on what your own deployed sensors are seeing.

Community and My Workspace require a deployed Swarm sensor. Once you deploy one, access is granted within about 6 hours. 

Access and availability

The Intelligence Dashboard is available to all signed-in GreyNoise users. GreyNoise customers and Community users with a business email get at least 10 days of data lookback, while Community users with a consumer email get 2 days. Available data sources may also vary by account type.

To build your first dashboard, open the GreyNoise Visualizer and navigate to Query → Dashboard.

Ready to get started?

  • Current customers: Log in to the Visualizer, start from the daily view, and save your first dashboard.
  • Not a customer yet? Contact Sales to learn more.

Now Available: The Threat Brief Library in the GreyNoise Platform

Every week, GreyNoise publishes a threat intelligence brief called At The Edge. This covers what attackers are doing on the internet, including which products are drawing exploitation traffic, which vulnerabilities are being exploited, and what changed from the previous week. Each brief is built on primary-source data from our global sensor network and analyzed by our research team into named findings, IOCs, and recommended actions.

The Threat Brief Library is now available in the GreyNoise Visualizer. You can browse, search, filter, and download every brief available to your account as a PDF. Community users can access every At The Edge Clear edition, while customers get the full library.

What's in the library

The library includes three report types:

  • At The Edge: GreyNoise’s weekly intelligence brief covering exploitation activity observed across the edge during the previous week. Each edition includes analysis, IOCs, and recommended actions by role.
  • Executive Situation Reports: Event-driven briefs focused on a single campaign or vulnerability under active exploitation. Each report includes key judgments, vulnerability and campaign context, attacker infrastructure, observed tradecraft, implications, recommended actions, and the supporting activity data.
  • At The Edge Clear: The public edition of the weekly At The Edge brief, covering the week’s headline activity and key findings.

Inside a full At The Edge brief

Each brief is built on primary-source data from the GreyNoise Global Observation Grid, our global network of sensors that emulate the edge infrastructure attackers target. The sensors record all the exploitation attempts and our research team correlates them into named campaigns, confirms the CVEs involved, attributes the hosting infrastructure behind them, and writes the detection and remediation guidance.

A full At The Edge brief includes:

  • Bottom Line Up Front: the week's most significant activity and what to do about it
  • Recommended actions by role for for security leadership, SOC, vulnerability management, network security, threat hunting, and IAM teams
  • Named findings: the products, CVEs, CISA KEV status, campaigns, traffic volumes, and host classifications driving activity
  • Infrastructure attribution: the ASNs, hosting fleets, and network ranges behind the activity
  • Target assessments, IOCs, and detection guidance based on request patterns and client fingerprints that persist as source addresses rotate
  • Persistent activity updates on threats that remain active from previous weeks

Want to see what a week looks like? Read the latest At The Edge Clear edition.

Where to find it

Log in to the GreyNoise Visualizer, click your name on the top right, and open the Threat Brief Library. You can search by title or description, filter by category, and download any brief you have access to as a PDF. The newest briefs appear first. Briefs are also available through the API and an RSS feed, so you can pull them directly into your own tools or subscribe to new briefs as they publish.

The library is available to all GreyNoise users. Community users can read every At The Edge Clear edition, while GreyNoise customers get the full library, including weekly At The Edge briefs and Executive Situation Reports. Read the Threat Briefs documentation to learn more.

Contact us to get access to the full library.

Project Swarm: Join the Collective. Defend the Edge

Here at GreyNoise, we’ve spent years building one of the most advanced deception networks on the internet. Our Global Observation Grid has over 5,000 sensors across 80 countries processing more than 500 million sessions per day, allowing us to see the internet's attack traffic before it reaches your doorstep. We've used that visibility to alert the world to mass scanning surges, vuln exploitation waves, and early reconnaissance patterns that signal what's coming next.

But there's a class of adversaries we can't catch alone.

The Perimeter Was Never “Dead”

The most advanced threat actors, state-sponsored adversaries like the Typhoon groups, have figured something out: the network edge is still a blind spot. Firewalls, VPN gateways, routers, load balancers — these devices can't run EDR agents. They often don't even support basic telemetry like logging. And they sit at the most critical exposure point: the network edge.

These adversaries have made edge devices their preferred point of initial access. They exploit vulnerabilities in firewalls and VPN gateways, hijack built-in tools on perimeter devices to maintain persistence, and send quiet, targeted probes designed to blend into the background. The Typhoon actors have demonstrated the most sophisticated version of this approach, building massive residential botnet proxies by compromising edge devices with little-to-no monitoring. APT41 has exploited zero-days in Fortinet VPNs, Cisco routers, and Citrix appliances. And well-funded ransomware crews are increasingly following the same path. The edge is where advanced adversaries go first, because it's where defenders see least.

Meanwhile, the exposure window keeps widening. The average patch time for edge devices is roughly 32 days, but exploit time is often near zero. For an entire month, your critical internet-facing infrastructure sits exposed to adversaries who are already watching.

The perimeter was never dead — it's the hardest attack surface to defend, and threat actors know it.

Deception Is the Best Answer

When the adversary specializes in staying quiet, you have to change the game. We believe deception is the best way to provide visibility into edge attacks — you can’t detect the threat; but you can make the threat reveal itself.

GreyNoise deploys sensors that emulate the exact assets attackers are looking for. When an adversary probes a sensor, they believe they've found a real target. Instead, they've exposed their tools, their payloads, their behavioral fingerprints, and their intent.

But here's the problem: no single organization can build the deception infrastructure needed to cover the internet's entire attack surface. We need more IP diversity, more device profiles, and faster detection rules than any one company can produce on its own.

That's why we're opening up our platform.

Announcing Project Swarm

Today, we're launching Project Swarm — a research initiative that opens the GreyNoise deception platform to the global security community.

Project Swarm transforms GreyNoise from a proprietary sensor network into a collective intelligence platform. We're inviting security researchers, universities, non-profits, ISPs, and OEM manufacturers to contribute to three pillars that make edge deception work at scale:

  • IP Coverage — Deploy sensors on your infrastructure to expand the geographic and network diversity of the Global Observation Grid.
  • Device Coverage — Bring device profiles for the edge assets you know best — firewalls, routers, VPN gateways — so sensors look like real, high-value targets to attackers.
  • Detection Velocity — Contribute detection rules and tags to identify attacker TTPs faster than GreyNoise can alone.

What You Get

When you deploy a GreyNoise sensor through Project Swarm, you get visibility into all the traffic hitting that sensor, and everything your sensor captures is yours to work with.

Every session is recorded with full fidelity: raw PCAPs, payloads, HTTP headers, TLS metadata, and behavioral artifacts. That means you're not just seeing that something probed you — you're seeing exactly what it did, what it sent, and how it behaved. 

For researchers, this opens up a world of possibilities. Here are some ideas to get you started:

  • Analyze captured payloads to reverse-engineer exploit attempts and study attacker tooling in the wild. 
  • Track how scanning and exploitation campaigns evolve over time by watching the same vulnerability get targeted with different techniques over time. 
  • Study the behavioral patterns that distinguish targeted reconnaissance from opportunistic noise — timing, sequencing, header fingerprints, TLS characteristics. 
  • Correlate early-stage recon activity against eventual CVE disclosures to build predictive models for what's coming next. 
  • Write and contribute detection rules based on what you observe, improving the GreyNoise tag library for the entire community. 
  • Compare your sensor traffic against the GreyNoise global baseline to identify what's specifically targeting your sensor versus what's hitting the broader internet. 

The possibilities are limited only by what IPs, emulators, and devices you can bring to Project Swarm.

Join the Collective

We believe deception is the best and only way to gain real visibility on the edge. You can't install agents on embedded systems. You can't rely on logs that don't exist.. But you can put something in the attacker's path that looks real enough to make them show their hand. When they probe a deceptive asset, they reveal themselves — their tools, their intent, their techniques — without ever knowing they've been caught.

The challenge is scale. To see the full picture, deception infrastructure needs to span more IP space, emulate more device types, and develop detection rules faster than any single organization can manage. That's what Project Swarm is about — turning the security community's collective reach into the world's most advanced deception network.

The era of defending in isolation is over. The adversaries targeting the edge are patient, precise, and well-resourced. But together, we can be everything, everywhere, all at once. Security is a collective team sport.

Introducing C2 Detection: Know When Your Edge Devices Are Calling Home to Attackers

When a firewall gets exploited, nothing happens, at least, nothing you can see. No EDR alert. No endpoint log. The device just quietly reaches out to an attacker-controlled server, downloads a payload, and waits for instructions. 

From the attacker's perspective, access is established. From yours, it's Tuesday.

Edge and perimeter devices, routers, firewalls, VPN concentrators, are the most actively exploited assets on the internet right now. They're also the ones your security stack has the least visibility into. EDR doesn't run on them. Their native telemetry is sparse. And when they're compromised, the only evidence is an outbound connection buried somewhere in your firewall logs. 

Today, we're launching C2 Detection, a new GreyNoise intelligence module that gives you two distinct, high-confidence signals that a device in your environment has been compromised.

Detect Compromise Through Outbound Traffic

C2 Detection is a new GreyNoise intelligence capability that surfaces the attacker-controlled infrastructure, malware-hosting servers, C2 nodes, and associated file hashes that compromised devices phone home to after a successful exploit.

Here's how it works: GreyNoise reads the exploit payloads that attackers send to its global sensor network and extracts the callback destinations embedded in those payloads. It then collects the malware hosted at those destinations and analyzes it to map the next stages of the attack chain — from staging servers to command-and-control infrastructure. This is payload-derived intelligence. GreyNoise doesn't need to wait for an exploit to succeed. It reads the payload directly, observes the post-exploitation chain, and delivers the results as a continuously updated dataset of confirmed callback IPs and associated malware hashes.

In the Visualizer, you'll see this as callback IP intelligence and malware hash data — two new layers that extend GreyNoise beyond inbound scanning into outbound threat detection.

Turn Outbound Traffic Into a Detection Signal

  • Detect active compromise from outbound traffic. Export your egress logs from edge devices and match destination IPs against the GreyNoise callback dataset. If there's a hit, the attack stage tells you how serious it is and what to do next.
  • Enrich your SIEM and SOAR with callback context. Pull callback stage and metadata via the API and use it to branch your playbooks. A Stage 1 match (confirmed file download) opens a case. A Stage 2 match (suspected C2 activity) triggers immediate escalation and containment.
  • Investigate historically. Callback infrastructure persists for weeks or months, far longer than scanning IPs. Use time range filters and the callback_ips query parameter to trace when GreyNoise first observed the infrastructure and which scanner IPs are linked to the same attack network.

Three Stages, One Severity Framework

Every callback IP is classified into one of three stages based on what GreyNoise has confirmed:

Stage What It Means Recommended Action
Unconfirmed IP appeared in a payload, but no file was successfully downloaded. Investigate. Don't escalate yet.
Stage 1: File Downloaded GreyNoise confirmed this IP is actively serving file payloads. Treat contacting devices as potentially compromised. Open a case.
Stage 2: C2 Suspected Behavioral analysis including VirusTotal detections, sandbox network activity, and malware associations indicates active C2 infrastructure. Assume active exploit presence. Escalate immediately.

This stage-based model gives you a built-in severity framework. Instead of a binary "good or bad," you get a signal calibrated to where the attacker is in their kill chain so your response matches the actual risk.

Two Signals. One Answer: You’re Compromised

C2 Detection strengthens a use case GreyNoise customers already know, detecting compromised assets by adding a second, independent signal:

  • Signal A (existing): Your organization's IP appears in GreyNoise as a scanner. That device has been recruited into a botnet and is scanning the internet on the attacker's behalf.
  • Signal B (new): Your outbound traffic matches a confirmed callback IP. That device is calling home to attacker-controlled infrastructure.

C2 Detection expands GreyNoise coverage beyond inbound activity, bringing high-confidence visibility into outbound communication with attacker-controlled infrastructure.

What This Adds to GreyNoise

This is entirely net-new. GreyNoise previously tracked only IPs actively scanning the internet, inbound threat intelligence. C2 Detection is the first GreyNoise capability focused on post-exploitation, outbound-facing threat intelligence. It introduces:

  • A new dataset: Callback IPs
  • A new classification model: Three attack stages
  • New data types: Malware files and hashes (with VirusTotal correlation)
  • A new query parameter: callback_ips

None of these existed in GreyNoise before.

Same Workflow. Stronger Signal. 

If you're already enriching alerts with GreyNoise, the integration model doesn't change. The Callback IP dataset is accessed through the same API and Visualizer you already use. It's a different dataset, a different API call, but the workflow pattern is identical: take an IP, ask GreyNoise about it, act on the answer.

The difference is that Greynoise now extends beyond inbound activity to surface high-confidence signals from outbound traffic. What was once context is now a detection signal.

Start Using C2 Detection

C2 Detection is available as a dataset add-on for existing GreyNoise customers, with access delivered directly in the Visualizer and via API.

Already a customer? Contact your account team or email support@greynoise.io to enable access.

Not a customer? Get access with an Enterprise Trial.

(An existing GreyNoise Community Visualizer Account is required, create one free here.)

Want the technical details first? Explore the documentation:

GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities

GreyNoise integration with Google Security Operations enables improved dashboards, detection rules, playbooks, and webhook support

Your SIEM ingests everything. Every port scan, every crawl, every opportunistic spray across the internet. The problem isn't the collection — it's context. Which of those IPs are scanning everyone, and which ones are targeting you?

That's the question GreyNoise answers. We observe over over 800,000 unique IPs daily across 5,000+ sensors in 80+ countries, classifying each as malicious, suspicious, benign, or unknown, and tagging them with 3,000+ behavioral descriptors. Traditional threat feeds add more indicators to investigate. GreyNoise removes the ones that don't matter.

Today, we're announcing a new and improved integration with Google Security Operations — delivering standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, and ready-to-deploy playbooks.

What's New: Event Management

New Ingestion Script

The GreyNoise ingestion script is now available in Google Security Operations ingestion-scripts repository — a standardized process for importing threat intelligence indicators into your environment. Deployed as a Google Cloud function, it pulls IP reputation data and GNQL query results from the GreyNoise API and ingests them via the Google Security Operations API. The default configuration focuses on malicious IPs observed in the last 24 hours, but teams can customize the GNQL query to match their threat profile.

New Dashboards

Two interactive dashboards ship with the integration into Google Security Operations:

Indicator Dashboard — 15+ visualization panels covering classification distribution (Malicious, Suspicious, Benign, Unknown), top 10 rankings for organizations, actors, tags, ASNs, categories, operating systems, and source countries, plus CVE distribution, trend analysis, and business service intelligence.

GreyNoise Indicator Dashboard in Google Security Operations

Correlation Dashboard — Shows IOC matches between GreyNoise intelligence and events from your environment, with geolocation mapping, event match trends, classification breakdowns, and top IP indicator rankings.

GreyNoise Correlation Dashboard in Google Security Operations

Indicators broken down by classification

New YARA-L Detection Rules

Three ready-to-deploy rules that start correlating immediately:

  • IP Match — Detects events where a source or principal IP matches a malicious or suspicious GreyNoise indicator, correlating over a 1-hour window.
  • Inbound Network Traffic with ASN Context — High-severity rule monitoring firewall logs for permitted inbound connections from GreyNoise-flagged malicious IPs, enriched with ASN attribution.
  • Brute Force Attack Detection — High-severity rule flagging 5+ blocked login attempts from GreyNoise-flagged IPs within a 15-minute window.

New Saved Searches

Four pre-built UDM queries for investigation workflows:

  • IP Risk & Vulnerability Details — Classification, anonymization signals, CVEs, and activity timelines
  • Indicator Context Summary — Actor attribution, geographic details, organizations, and tags
  • High Risk Indicators — Filters for MALICIOUS or SUSPICIOUS classifications only
  • All Indicator Lookup — Browse all ingested GreyNoise indicators for ad-hoc investigation

IOC Geolocation Overview — mapping matched indicators globally

What's New: Response Workflows

Updated Response Actions (v7.0)

The GreyNoise response integration has been updated to version 7.0 with the full suite of actions:

Action What It Does
IP Lookup Full enrichment — classification, tags, metadata
Quick IP Lookup Fast context check on any IP
IP Timeline Lookup Historical view of scanning behavior over time
Execute GNQL Query Run arbitrary GreyNoise queries within a playbook
Get CVE Details Vulnerability context from exploitation activity
Ping Validate API connectivity

New Webhook Support

A major addition: webhook support for ingesting GreyNoise alerts and event feeds directly into Google Security Operations. Three webhook types are now available:

  • Alert Webhook — Ingests IP, CVE, TAG, and GNQL Query alerts
  • IP Change Webhook — Tracks classification changes in real time
  • CVE/Tag Webhook — Monitors CVE spikes, status changes, vendor activity, and tag spikes

New Playbooks

Pre-built playbooks ship with the integration, providing ready-made automation workflows that teams can deploy or customize. Combined with the webhook connectors and the Generate Alert from GreyNoise GNQL connector, security teams can build end-to-end automated triage pipelines.

On-demand IP Lookup 

How It Works Together

  • 1. Ingest — The event management integration continuously pulls GreyNoise indicators into Google Security Operations with fresh scanner data.
  • 2. Detect — YARA-L detection rules flag events that correlate with known scanners. Dashboards provide visual context.
  • 3. Investigate — Saved searches surface IP risk details, actor attribution, and CVE context without writing queries.
  • 4. Respond — Response playbooks enrich flagged IPs automatically. Mass scanners get deprioritized. Targeted activity escalates for review.

Webhooks close the loop by pushing GreyNoise alerts — including classification changes and CVE spikes — directly into Google Securioty Operations for quick action.

Who Has Access

This integration is available to any joint Google Security Operations customer with a GreyNoise API key. No additional licensing required — just configure and go.

Learn More and Get Started

Ready to bring GreyNoise intelligence into your Google Security Operations environment? Learn more here:

GreyNoise Intelligence Is Available Across the CrowdStrike Falcon Platform

Every SOC analyst knows the feeling: another morning, another queue of hundreds of alerts, and the gnawing question of which ones actually matter. The volume of internet background noise — automated scanners, research probes, vulnerability crawlers — hasn’t slowed down. If anything, it’s accelerating. And as adversaries adopt AI to move faster, the cost of chasing the wrong signals isn’t just frustrating — it’s dangerous.

That’s the problem GreyNoise was built to address. We operate one of the largest passive sensor networks on the internet — more than 5,000 sensors across 80 countries, analyzing up to one billion sessions per day and tracking over 50 million IPs. That scale lets us classify internet-wide scanning and reconnaissance activity with confidence: which IPs are known benign scanners, which are actively malicious, and which are unknown — meaning we haven’t observed them scanning the internet indiscriminately.

That classification data is now available across the CrowdStrike Falcon platform — in Next-Gen SIEM, Falcon Fusion SOAR, and the agentic workflows that are defining the next era of security operations.

GreyNoise Intelligence Across CrowdStrike Falcon

For teams running Falcon, GreyNoise intelligence is operationalized across three integrated capabilities — inline investigation context in Next-Gen SIEM, automated enrichment and response in Falcon Fusion SOAR, and agentic collaboration through Charlotte AI.

Falcon Next-Gen SIEM: GreyNoise Classification Inside Your Existing Queries

The GreyNoise Foundry App — available directly on the CrowdStrike Marketplace — is the operational core of the integration. Once installed, it automatically imports a fresh GreyNoise indicator lookup file into Next-Gen SIEM every day. No manual feed management. No stale data.

That lookup file contains GreyNoise’s full dataset of classified IPs — benign scanners, malicious actors, CVE-targeting sources, and tagged threat infrastructure. Inside Next-Gen SIEM, analysts use the match() function to incorporate that data directly into their searches and analytics. GreyNoise classification columns — classification, observed activity, exploited CVEs — surface right alongside event data in the query view, with no pivot to an external tool required.

Detections tied to IPs that GreyNoise has identified as active exploit sources or malicious infrastructure stand out. Teams can build correlation rules and dashboards that weight GreyNoise-validated threats higher. And IPs that GreyNoise has classified as benign — known research scanners, internet measurement services, well-documented security vendors — carry that context right in the query results, giving analysts the information they need to make confident triage decisions.

The Foundry App ships with a pre-built app template containing GreyNoise threat intelligence actions, ready to deploy in Foundry and extend into Fusion SOAR workflows.

Falcon Fusion SOAR: Automated Enrichment and Response

Knowing an IP is malicious is useful. Acting on that intelligence automatically is where the efficiency gain lives.

The GreyNoise Foundry App includes a native Falcon Fusion SOAR integration that puts GreyNoise enrichment directly into workflow logic. Security teams can build — or extend — automated playbooks that take action based on GreyNoise IP context:

  • Alert on malicious IPs — trigger high-priority notifications when GreyNoise identifies adversary activity at the perimeter
  • Prioritize vulnerability response — surface CVE exploitation data to inform which vulnerabilities need immediate patching attention
  • Initiate threat hunts — automatically kick off hunt workflows when GreyNoise identifies coordinated scanning tied to known threat infrastructure
  • Automate blocking or containment — close the loop on confirmed malicious IPs

GreyNoise’s benign classification is particularly valuable here. Because GreyNoise classifies known-good IPs — security researchers, CDN health checks, legitimate vulnerability scanners — SOAR workflows have a higher-confidence basis for automated routing decisions. That confidence is grounded in what our sensor network directly observes, not aggregated from third-party sources.

Charlotte AI: GreyNoise as a Trusted Ecosystem Participant

CrowdStrike’s blog on building an agentic security workforce names GreyNoise among the trusted ecosystem participants supported in Charlotte AI’s Agentic Response Collaboration capability — alongside Corelight, ExtraHop, Proofpoint, Google, Abnormal AI, and Zscaler. These integrations provide what CrowdStrike describes as “deep cross-domain context to drive faster, more accurate analysis.”

Charlotte AI’s use of ecosystem data is still maturing, and we’ll share more as it develops. But the direction is clear: as agentic workflows become a core part of how SOC investigations run, GreyNoise intelligence can be part of the reasoning loop.

Here’s what that looks like in practice. An alert fires on a suspicious external IP. Charlotte AI’s Detection Triage Agent is working the case. As part of its investigation, GreyNoise context is available: Is this IP part of a known mass scanner campaign? Has it been observed exploiting the specific vulnerability that generated the alert? Is it tied to active threat infrastructure? That intelligence informs the agent’s triage decision — contributing internet-wide scanning context to a process that already draws from endpoint, identity, and cloud telemetry.

Charlotte AI’s agentic response can trigger workflows in Falcon Fusion SOAR, which means GreyNoise intelligence already available in your SOAR playbooks carries naturally into AI-driven triage. CrowdStrike’s mission-ready agents — covering detection triage, malware analysis, exposure prioritization, and threat hunting — are trained on years of expert decisions from Falcon Complete analysts. GreyNoise’s classification data adds internet-wide reconnaissance context to those workflows.

What Falcon Users Get

GreyNoise intelligence across the Falcon platform produces three specific outcomes:

  • Higher-confidence triage — GreyNoise classification gives analysts a clear signal on which external IPs are known internet scanners and which warrant deeper investigation
  • Contextualized alerts — every IP-based detection carries GreyNoise behavior, classification, and CVE context from the moment it fires
  • Faster investigation and response — inline enrichment and automated SOAR workflows compress the time from alert to action
  • Prioritized vulnerability response — CVE exploitation intelligence from GreyNoise’s sensor network informs which vulnerabilities are being actively targeted right now

Getting Started

The GreyNoise Foundry App is available on the CrowdStrike Marketplace for Falcon Next-Gen SIEM and Falcon Insight XDR customers. Installation takes minutes, and the daily automated indicator import requires no ongoing maintenance.

Install the GreyNoise Foundry App on the CrowdStrike Marketplace

Read the technical integration documentation

Learn more about GreyNoise

New in Event Feeds: Vendor CVE Spike & Tag Spike

There is a critical gap in defense: the window between when an attacker starts hammering a specific vendor’s infrastructure and when a specific CVE is assigned or a signature is written.

In that window, defenders are often flying blind, waiting for a vulnerability disclosure to tell them what to look for. But the network noise is often already there. The most dangerous threats don't always start with a named vulnerability—they start with a sudden, coordinated shift in attacker behavior toward a specific technology stack.

Today, we are closing that visibility gap by expanding GreyNoise Event Feeds with two new signals: Vendor CVE Spike and Tag Spike.

These new feed types allow you to monitor the behaviors and technologies that matter to your environment, without needing to manually track every individual vulnerability or signature.

1. Vendor CVE Spike

Individual CVEs and tags are continually added, updated, and deprecated as new research emerges. This creates significant overhead and potential blind spots if your team attempts to track these changes manually.

The Vendor CVE Spike feed reduces this complexity by alerting only when exploitation activity across a vendor meaningfully increases.

How it helps: This feed is designed to help you focus on when attacker interest spikes, rather than managing lists of specific CVEs. As vulnerabilities and tags associated with a vendor evolve, the feed updates its coverage to include them, ensuring you are monitoring the broader technology stack rather than just static indicators.

Use Cases:

  • Vendor-wide vulnerability monitoring: Monitor all CVE exploitation activity across a vendor's products without manually tracking individual CVEs as they are published.
  • Patch prioritization: Prioritize patching cycles based on vendor-level exploitation trends. A spike in activity for your firewall vendor signals it is time to accelerate remediation.
  • Proactive threat hunting: Use vendor spikes as an early warning signal to investigate whether associated CVEs have been attempted against your environment.

Real-World Context: The Fortinet & Palo Alto Surge

Attackers often target the technology stack, not just a single bug. In our analysis from the week of January 19, 2026, GreyNoise sensors observed a coordinated campaign targeting enterprise VPN infrastructure. Specifically, we saw a significant elevation in targeting of both Fortinet SSL VPNs and Palo Alto GlobalProtect portals.

This activity validates findings from our Early Warning Signals research: vendor-level spikes—whether from credential stuffing, scanning, or exploitation of older vulnerabilities—often precede the disclosure of new CVEs for that same vendor. A Vendor CVE Spike would have flagged this anomaly, providing the early warning needed to enforce tighter MFA controls or geo-blocking before the specific threat was fully characterized.

How It Works:

 Setting up a Vendor CVE Spike is designed to be a "set and forget" workflow that integrates directly into your existing Event Feeds. When you search for a vendor name (e.g., "Palo Alto"), the feed uses wildcard matching to find all tags containing that term. It then resolves those tags to their associated CVEs and monitors activity for those CVEs.

  1. Create a Feed: In the GreyNoise Visualizer, navigate to the Event Feeds section.
  2. Name Your Feed: Assign your feed a recognizable name (e.g., "Critical [Vendor] Monitor").
  3. Select Spike Type: Choose Vendor CVE Spike from the available signals.
  4. Define Threshold: Select the vendor you want to monitor and set the activity threshold that matters to you.
  5. Connect: Add your webhook link (SIEM, SOAR, etc.).
  6. Test & Save: Verify the connection and save the feed.

Example Payload:
{ "vendor": "Acme", "event_type": "Vendor CVE Spike Spike", "old_state": { "benign_ip_count_1d": 40, "threat_ip_count_1d": 40 }, "new_state": { "benign_ip_count_1d": 90, "threat_ip_count_1d": 90 }, "timestamp": "2025-04-30T08:10:00Z" } 

Watch the video below to see Vendor CVE Spike in action:

2. Tag Spike

Sometimes, the threat isn't a specific vulnerability—it is a behavior, a tool, or a botnet. Tag Spike feeds allow you to monitor for sudden increases in activity associated with specific GreyNoise tags directly.

How it helps: Tag Spike lets you monitor activity for specific threats, botnets, or scanning behaviors directly by tag name. Unlike Vendor CVE Spike, which resolves matching tags to their associated CVEs, Tag Spike tracks the tags themselves. This is essential for tracking threats where a CVE may not yet be assigned.

Use Cases:

  • Monitoring emerging exploit activity: Track activity for specific products or vendors before CVEs are assigned.
  • Tracking specific threats: Monitor botnets (e.g., "Mirai"), scanners, or malware families by tag name.
  • Early warning detection: Get notified when threat actors ramp up scanning for specific technologies.

How It Works:

You define a tag or keyword (e.g., "Mirai," "Worm," or "Cisco"), and the feed uses wildcard matching to find all tags containing that term. GreyNoise then watches for significant changes in IP counts for tags matching your filter criteria over a rolling 2-hour window.

  1. Create a Feed: In the GreyNoise Visualizer, click Create Feed.
  2. Name Your Feed: Give it a clear name (e.g., "Mirai Botnet Tracker").
  3. Select Event Type: Choose Tag Spike.
  4. Define Threshold: Enter the tag or keyword you want to monitor (e.g., mirai) and set the percentage increase threshold.
  5. Connect: Paste your webhook URL.

Watch the video below to see Tag Spike feed in action:

💡 Quick Tip: Which feed should I use?

  • Use Vendor CVE Spike if you want to track exploits. (e.g., "Tell me if Palo Alto products are being exploited via any CVE.")
  • Use Tag Spike if you want to track behaviors or botnets. (e.g., "Tell me if the Mirai botnet is active" or "Tell me if worm behavior is spiking.")

Access and Availability

Vendor CVE Spike and Tag Spike are available now in the GreyNoise Visualizer.

  • Who has access: These feeds are available to Advanced and Elite platform customers with the appropriate data modules. 
  • Where to find it: Navigate to the Feeds tab in the Visualizer to configure your first alert.

Ready to get started?

GreyNoise Introduces Recall: Time-Series Intelligence for GreyNoise Query Language (GNQL)

Time is the one variable defenders can’t control. The gap between an exploit disclosure and a patch, or between an initial compromise and its discovery, is where attackers thrive. They automate everything—recon, scanning, and exploitation—shifting their infrastructure by the hour to stay ahead of static blocklists.

To keep pace, defenders need more than a snapshot of what is happening right now. They need to see how behavior evolves.

At GreyNoise, our standard GreyNoise Query Language (GNQL) has always provided a highly accurate, 90-day aggregated view of "the now." It tells you what an IP is doing today. But we realized that for incident responders and threat hunters, a summary isn't always enough. You need to know exactly what was happening during a specific window in the past.

Today, we are launching Recall to address these challenges.

What is Recall? 

Recall is a time-series capability that enables customers to query GreyNoise data over specific historical ranges. Instead of a static summary of current IP behavior, Recall allows you to see exactly how scanner activity looked at any given hour.

Recall eliminates the need for manual data collection pipelines, acting as a time- and cost-saver by providing historical insights on-demand. This allows teams to move from observing "what is this IP doing now?" to understanding how that behavior has evolved.

What Recall Enables

Retrospective Incident Analysis

When investigating a compromise, Recall lets you reconstruct the attacker’s timeline. You can see when an IP first appeared in GreyNoise, whether it scanned your perimeter days earlier, and how its behavior changed before a successful exploit. This gives you context you cannot get from point-in-time enrichment.

Trend and Campaign Identification

Recall helps determine whether a surge is new or part of a recurring pattern. For example, you can compare a single-day spike in exploitation activity against prior weeks to understand if you are seeing the start of a coordinated campaign or a known cycle.

Pre-Disclosure Signal Detection

GreyNoise consistently observes scanning and exploitation activity against enterprise edge technologies before public CVE disclosure. Recall allows teams to look back and confirm when these early signals began, helping validate whether suspicious activity preceded an advisory or zero-day announcement.

Historical Benchmarking

Teams can compare traffic across regions, products, or time ranges to see how attacker focus shifts. This is especially useful for measuring changes in exposure or validating whether defensive actions had a real impact.

How It Works

Recall exposes two API endpoints. Use Stats to identify the spike, then Data to pull the raw records.

Recall Stats API — The Trend Line

Endpoint: GET /v3/gnql/timeseries/stats

Returns unique IP counts per hour or day for your query. Use this to visualize activity volume before pulling detailed records.

Parameter Required Description
query Yes GNQL query
start Yes Range start (ISO8601)
end Yes Range end (ISO8601)
interval Yes hour or day

Response: count (total unique IPs), min/max (bucket extremes), data (array of { date, count })

curl 'https://api.greynoise.io/v3/gnql/timeseries/stats?query=tags%3A*Scanner*&start=2025-08-08T06%3A00%3A00Z&end=2025-10-12T23%3A00%3A00Z&interval=day' \
  --header 'key: <your-api-key>'

Recall Data API — The Raw Records

Endpoint: GET /v3/gnql/timeseries

Returns full GreyNoise context for each IP, keyed by hour. Use this when you need the actual records—tags, ports, ASN, classification—as they appeared at each timestamp.

Parameter Required Description
query Yes GNQL query
start Yes Range start (ISO8601)
end Yes Range end (ISO8601)
limit No Max IPs to return
offset No Pagination

Response: JSON keyed by hour (yyyy-mm-dd-hh), each containing ip and internet_scanner_intelligence context.

curl 'https://api.greynoise.io/v3/gnql/timeseries?query=ip%3A212.18.104.107&start=2025-09-08T06%3A00%3A00Z&end=2025-10-23T12%3A00%3A00Z' \
  --header 'key: <your-api-key>'

Visibility for Every Workflow

Recall is built to integrate into the way modern security teams work:

  • SOC / Threat Intel: Perform retrospective analysis to see if a suspicious IP was active during a critical incident window.
  • Detection Engineering: Track how scanning and exploitation behaviors change over time to refine and tune detection logic.
  • Security Data Teams: Build dashboards and enrichment pipelines based on historical shifts, rather than just current state.

Availability

Recall is available now. Lookback window depends on your license tier:

License Lookback Window
Standard Platform 10 days
Advanced Platform 30 days
Elite Platform 90 days

Syntax note: Recall enforces stricter GNQL parsing for performance. Escape spaces with backslashes: tags:*Palo\ Alto* instead of tags:*"Palo Alto"*.

What's Next

We'll be publishing research built on Recall in the coming weeks—including a retrospective timeline of the React2Shell campaign and analysis of scanning patterns preceding recent zero-day disclosures.

For implementation details and query examples, see the Recall documentation.

Introducing Query-Based Blocklists: Fully Configurable, Real-Time Threat Blocking in the GreyNoise Platform

Attackers move fast. Their infrastructure changes by the hour—IP addresses spin up, burn out, and shift constantly. Defenders, meanwhile, require controls that strike a balance without overblocking or disrupting legitimate traffic.

That’s why we’re excited to announce that starting today, customers can turn any GreyNoise query directly into a real-time blocklist for their firewall, SOAR, or other enforcement points.

Real-Time, Dynamic, and Completely Configurable

Traditional static blocklists quickly age out, creating blind spots or false positives. GreyNoise blocklists are different. They’re:

  • Real-Time: Continuously refreshed with the latest IP intelligence collected by GreyNoise’s global sensor network.

  • Dynamic: As attacker infrastructure changes, your blocklists automatically update—no manual uploads or scripts required.

  • Configurable: You control what’s blocked. Build blocklists tuned precisely to your organization’s risk tolerance and threat model.

With our query-based blocklists, you can automatically block the activity that matters to you—whether that’s opportunistic scanning, specific exploit campaigns, or known attacker infrastructure—without interrupting legitimate traffic.

Build Blocklists from Any GreyNoise Query

GreyNoise Query Language (GNQL) gives customers a powerful way to explore and segment global internet noise. Now, that same query power drives automated blocking and enforcement.

Each query you create can become a live, continuously updated feed for perimeter defense. As GreyNoise observes new IPs that match your query criteria, they’re added instantly to your blocklist.

When we first launched GreyNoise Block as a standalone product, it provided a simple and effective way to create real-time dynamic blocklists. To optimize for simplicity and speed, Block users could build lists from a set of common metadata about each IP. Block also offers useful templates as starting points for building blocklists.

With the new platform-integrated query-based blocklists,

  • You can now build blocklists using the full depth of GreyNoise metadata—every field, tag, and attribute you have access to in the platform. This gives you complete control to shape and refine your blocklists exactly the way you want.

  • These blocklists are tightly woven into your existing GNQL workflows. There’s no need to build queries specifically for blocking—any query you’ve already built can instantly become a live blocklist with a single click.

  • The result is a seamless experience: research, query, and enforcement—all in one place.

While the standalone Block product offered a fast on-ramp to real-time blocking, the platform-integrated query-based blocklists give you total flexibility and control on the nuance of your blocklist, directly inside the GreyNoise platform.

Available Now

Query-Based Blocklists are available today to all GreyNoise platform customers.

If you already use the GreyNoise Visualizer, you can start creating your first blocklist immediately—no new integration or license required.

For a walkthrough, visit the GreyNoise documentation or reach out to your GreyNoise account team.

Introducing GreyNoise Block: Fully configurable, real-time blocklists

The World Needs A Better Blocklist

Security teams already have access to blocklists; commercial feeds, community lists, vendor-curated sets of bad IPs — they’ve been around for decades. And yet, every practitioner has experienced the same frustrations: the lists are too noisy, too static, too opaque, too slow to update, or just not quite meeting the right criteria.

That’s why GreyNoise built Block, a blocklist approach designed to be highly configurable, grounded in primary-sourced intelligence, and updated in real-time as attacker behavior changes.

The Limits of Traditional Blocklists

Most blocklists share common issues:

  • Lack of context — You see an IP is bad, but not why.
  • Lagging updates — Exploitation campaigns evolve by the minute, while lists update daily (or worse).
  • Overblocking — Feeds often include research scanners, crawlers, or actual business service infrastructure, causing collateral damage.
  • Rigid design — Few ways to tune blocklists to match the unique risk tolerance of your environment.

As a result, network security teams struggle to balance security and availability, concerned that they’ll block legitimate traffic or fail to block malicious traffic.

Why GreyNoise Block is Different

GreyNoise approaches blocklists from a different angle:

  • Configurable with GreyNoise Query Language (GNQL) — Security teams can define exactly what they want to block. For example:
    • IPs exploiting a specific CVE.
    • Hosts scanning your technology stack.
    • Sources from certain geographies.
  • Accurate and timely — Data is updated continuously. When a new exploitation campaign starts, it shows up in GreyNoise in near real time.
  • Reduced noise — Traffic like academic research or vendor scanners is categorized as benign and can be easily excluded from blocklists, avoiding the overblocking that plagues generic feeds.
  • Primary-sourced data — All entries come from the GreyNoise global sensor network, which collects unsolicited internet traffic at scale. These are IPs actively scanning, exploiting, or behaving like attacker-controlled infrastructure.

Practical Advantages for Network Security

GreyNoise Block delivers practical benefits to cybersecurity teams:

  • Focus on most relevant malicious traffic  — Stop traffic targeting technology vendors important to your network.
  • Respond faster during incidents — Use GNQL to generate emergency blocks for malicious IPs while you buy time for patching or remediation.
  • Reduce analyst fatigue — By blocking mass scanners and exploitation before it enters the network, GreyNoise Block reduces the number of alerts triggered by IDS/IPS and SIEM systems, reducing the burden on network security and SOC teams.

How Easy it is to Configure

Creating blocklists within GreyNoise Block could not be easier. To optimize flexibility, each blocklist is associated with a GNQL query. For ease of use, GreyNoise includes a set of query templates that provide pre-built blocklists. Start by either selecting a pre-built template or writing a query from scratch.

When selecting a template, you can click “Block These IPs” to create a blocklist immediately or click “Edit Query” to refine the blocklist’s criteria even further. When editing the query, you can add, remove, or modify fields and group them logically through and/or clauses. As you modify fields, the Query Stats panel on the right updates automatically.

Once you have the query looking as you want it in the Query Builder, click the “Block These IPs” button to turn the query into a blocklist. 

In the Create Blocklist dialog box, give the query a name and assign it an IP limit, which might be necessary if your firewall has a maximum supported size.

Once the block list is created, click the My Blocklists link at the top of the page to view the new block list and any others you have created. From the list, you can copy the blocklist URL to your firewall. 

That’s all there is to it. Your firewall will periodically poll the blocklist URL and keep that bad traffic out of your network.

Sign Up Now for a Free Trial

GreyNoise Block is available now with a free trial for 14 days.

Introducing GreyNoise Feeds: Real-Time Intel for Real-Time Response

Time is critical in incident response. The gap between exploit disclosure and patching, between compromise and containment, or between detection and recovery often determines the difference between a near miss and a major breach. Attackers automate everything from recon to exploit creation. Defenders need to close the speed gap.

Most threat intelligence workflows still rely on polling. Analysts or automated systems query APIs or dashboards on fixed schedules—every few minutes, every hour, sometimes even less frequently. By the time new data is pulled in, attackers may have already rotated infrastructure, moved laterally, or pivoted to a new exploit. This delay undermines automation investments, keeping defenders stuck in reaction mode.

Real-Time Feeds Instead of Polling

GreyNoise Feeds eliminate the need for polling by delivering event-driven webhook-based push notifications the moment something changes. Instead of waiting for the next scheduled query, your automation receives the update as soon as GreyNoise sees it. Teams can subscribe to three types of events:

  • CVE status changes: Get notified when a vulnerability moves into active exploitation (or back to inactive). Use these events to trigger automated patching, blocking, or monitoring workflows.
  • CVE activity spikes: Receive alerts when scanning or exploitation traffic against a CVE suddenly surges. These spikes often precede new disclosures, making them an early warning—even if your environment is already patched.
  • IP classification changes: Get immediate notice when an IP flips state, such as unknown to malicious. Because attackers gain and lose control of infrastructure quickly, reacting fast is the only way to block the right traffic at the right time.

Practical Use Cases

GreyNoise Feeds are designed to be wired directly into automation platforms like SIEMs and SOARs. With feeds in place, teams can:

  • Alert to Zero Day Risk. GreyNoise research has demonstrated that spikes of traffic against legacy CVEs often predicts the arrival of a zero day attack and new CVE disclosure. The Feeds event type CVE Activity spike provides organizations an early warning that provides organizations time to consider hardening, patching, and additional monitoring.
  • Proactive blocking. Use GreyNoise Feeds to directly update firewall blocking rules to stop reconnaissance and exploitation attempts against edge devices, often before damage occurs.
  • Vulnerability prioritization. Use GreyNoise Feeds to update vulnerability prioritizations as soon as GreyNoise observes new scanning and exploitation traffic. With the number of CVEs growing each year, many organizations face a backlog of vulnerabilities requiring remediation. While attackers have no means to exploit most CVEs, it’s critical to react once an exploitation is observed in active use.
  • Threat mitigation. When attackers target a vulnerability exposed on your network, it may be necessary to mitigate that attack while a remediation is implemented. GreyNoise Feeds can help automate that mitigation by providing immediate notifications of IP addresses engaged in malicious activities.


Easy Configuration

GreyNoise Feeds are quite easy to configure. Give the Feed a name, specify the type, that is whether IP classification change, CVE status change, or CVE activity spike, indicate the direction of the change (such as from unknown to malicious), and specify whether to notify on all IP addresses and CVEs or a select subset. 

You will also need to configure where GreyNoise should deliver the notifications, and each feed can have a unique delivery address. The address is a url that has been configured to receive webhook feeds. In order to support authentication and other features, GreyNoise Feeds supports adding custom HTTP headers.

GreyNoise Feeds take intelligence out of batch mode. Instead of asking what changed after the fact, your systems can respond the moment GreyNoise sees new exploitation, malicious activity, or infrastructure shifts. For defenders racing against automated attackers, that time advantage matters.

Learn more and watch videos on how to use at GreyNoise docs.

GreyNoise Intel Now Available Through MCP

While we may not know when the agentic SOC will arrive, we do know it will need timely and accurate intelligence to make good decisions. To provide that intel, we’re making the GreyNoise MCP Server available today, enabling easy integration of GreyNoise intel by Model Context Protocol (MCP) compatible AI agents. 

When an AI agent sees an IP address or CVE in a workflow, it can query GreyNoise in real time and learn:

  • Whether that IP is a benign mass scanner (safe to deprioritize),
  • A known hostile source actively exploiting CVEs (requires escalation), or
  • Completely absent from GreyNoise data (possibly targeted activity worth deeper investigation).

This grounding mitigates the risk of hallucinations and prevents agents from treating every alert equally, enabling more realistic, risk-based automation.

Practical Uses in the SOC

With GreyNoise data inside the reasoning loop, agents can handle several critical tasks more effectively:

  • Noise Reduction and Alert Triage
    GreyNoise filters out the background chatter of benign scanners and research infrastructure.
  • Exploitation Awareness and Vulnerability Prioritization
    When GreyNoise tags indicate active exploitation of a CVE, agents can prioritize remediation workflows accordingly.
  • Incident Response and Threat Hunting
    By pivoting on ASN, domain, and behavioral tags, agents can connect what appear to be isolated alerts to larger coordinated activity and trigger or suggest containment actions (e.g., pushing firewall blocks, updating IPS rules) in a way that minimizes false positives.
  • Continuous Monitoring and Risk Awareness
    Agents can watch GreyNoise observations in near real time, flagging when exploitation patterns overlap with an organization’s technology stack or internet-facing services.


Why GreyNoise Data Fits Agentic Workflows

SOC teams already use GreyNoise to separate background scanning from true threats. What changes with the MCP Server is that the same logic is now available directly to AI agents.

  • Real-Time Intel: Agents query GreyNoise live, ensuring their decisions reflect the latest activity rather than cached or stale data.
  • Behavioral Tags: Exploit attempts and reconnaissance behaviors are labeled, allowing agents to reason in higher-level terms than raw IPs and ports.
  • Analyst-Equivalent Context: GreyNoise fields—classification, CVE tags, first/last seen, ASN, sensor hit counts—mirror the attributes human analysts check when validating alerts.

This combination makes GreyNoise data especially well-suited to agentic SOC environments, where decisions need to be fast but also defensible.

Lighten the Work of Creating Intel Reports

Let’s say your manager wants an intelligence report, perhaps regarding an external threat, a set of IP addresses, or a vulnerability. For example, I may need to create a report based on a CVE, so I open Claude with the GreyNoise MCP server installed and enter the prompt:

Notice how Claude is making several calls to the GreyNoise MCP server as well as other sources so that it can combine these sources into a report.

Because of the GreyNoise MCP, the report includes details about IP address counts and recent surges in activity. Adding more to the prompt, such as “Tell me about the source geography of the attacks”, causes Claude to generate a much more detailed report. With minimal effort, you can write a prompt that creates just the report that you need. You can even ask for vendor risk reports and threat hunting plans. It’s a great way to reliably use AI to lighten your workload.

Final Thoughts

Agentic SOCs are still an emerging concept, but the risks can be mitigated and the value better realized if AI agents make decisions grounded in trustworthy data. The GreyNoise MCP Server provides a way to embed that grounding directly into agentic workflows.

For security teams, this doesn’t mean replacing analysts—it means giving agents access to the same noise-filtering and exploitation-awareness that practitioners already rely on, so that automation can act responsibly at scale.

Indeed, analysts can make great use of the MCP just by interacting with an LLM application that supports MCP, such as Claude. Conduct research. Look into trends. Generate reports. It’s as easy as it is fun.

Find everything you need to know in the GreyNoise MCP Server docs.

Faster Threats, Faster Defense: GreyNoise Launches Real-Time Threat Defense Capabilities at Black Hat 2025

In today’s threat landscape, speed isn’t optional — it’s existential. As attacks get faster, so too must your defense.

Attackers increasingly leverage automation, AI, and vast, ephemeral infrastructure to launch mass exploitation campaigns that scan, breach, and pivot within minutes — sometimes before a CVE is even publicly disclosed. Defenders, meanwhile, are often stuck pulling data manually, querying APIs, or waiting for threat feeds to update.

That’s the speed gap that attackers exploit. Today, we're launching a series of new capabilities to help defenders close that gap. These new capabilities help security teams leverage real-time threat intel to detect, block, and respond faster than ever before

The Speed Problem: Why Traditional Threat Intelligence Isn’t Fast Enough

The game has changed:

  • Automation is everywhere: Bots and AI-driven tools are running scans and exploitation campaigns at machine speed.
  • Exploitation is instant: Exploits are often deployed within minutes of discovery — or even before public disclosure.
  • Volume is relentless: Millions of IP addresses rotate constantly in mass scanning campaigns.

Yet many defenders still operate in batch mode: querying APIs, pulling feeds manually, or reacting only after the damage is done. GreyNoise is flipping that script. We’re giving defenders real-time, automation-ready intelligence — designed to meet the speed, volume, and precision required by modern security teams.

What’s New from GreyNoise

1. Real-Time Dynamic Blocklists

Stop mass exploitation at the edge — before it gets in.

GreyNoise-verified malicious IPs involved in opportunistic reconnaissance and exploitation are delivered in real time, designed to be integrated directly into your perimeter defenses.

  • Updated dynamically, second by second
  • Tuned for high confidence and low false positives
  • Compatible with firewalls, WAFs, and other edge devices
  • Subscribe once, get live protection — no manual updates required

Use it to:

  • Auto-block mass scanners and exploit attempts within seconds of detection
  • Proactively protect exposed assets before CVEs are weaponized
  • Harden your perimeter against “spray and pray” campaigns

2. GreyNoise Feeds

Threat intelligence that comes to you — automatically.

Say goodbye to the delays caused by polling APIs. Our new push-based data delivery means GreyNoise intelligence is streamed directly to your systems via webhooks — the moment we detect something new.

  • Real-time threat indicators, no polling delay
  • Zero lag between detection and delivery
  • Seamless integration into existing platforms and workflows

In security, minutes (even seconds) matter. Push-based intelligence closes the speed gap between attack and defense.

3. SOAR Integrations for Response Automation

From detection to action — with zero manual steps.

GreyNoise now integrates natively with leading SOAR platforms–such as Splunk SOAR, Palo Alto Networks XSOAR, IBM QRadar SOAR–to help teams turn intelligence into action, instantly and automatically.

Automate key workflows like:

  • Blocking malicious IPs without analyst intervention
  • Enriching IP data during incident investigations
  • Triggering alerts or playbooks when mass exploitation campaigns are detected

The result:

  • Faster containment
  • Consistent, repeatable response
  • More time for your analysts to focus on what matters

Why This Matters

These launches are part of GreyNoise’s commitment to empowering defenders with:

  • Speed: Intelligence and action in real time — because modern threats don’t wait.
  • Automation: Automate your security with reliable, real-time intelligence and reduced risk of false positives.
  • Integration: Delivered where you already work — firewalls, SOARs, SIEMs, and more.
  • Noise Reduction: High-confidence signals only — no alert fatigue, no chasing ghosts

Who It’s For

These new capabilities are built for:

  • Security operations teams seeking to automate blocking rules in near real time with reliable and actionable intelligence about IP addresses exploiting exposed vulnerabilities. Real-Time Dynamic Blocklists and SOAR integrations enable this automation use case.

  • Incident responders who need to quickly understand the extent of an incident by narrowing in on the malicious network traffic that have exploited a vulnerability. Realtime updates through Feeds and SOAR integrations enable rapid responses.

  • Threat intel teams looking for real-time context on emerging discovery and exploitation attempts tied to high priority risks as well as intel that enables immediate investigations to discover damages caused before vulnerability disclosures. Subscribing to web hook feeds ensures that intel teams stay updated in real time.

Modern Attacks Move Fast. Your Defense Should Too.

GreyNoise is building the future of threat intelligence for defenders who don’t have time to wait. 

Meet with us at Black Hat 2025 to learn more — or get started today.

The Tortilla Test: Ensuring Your Vulnerability Intelligence is Always Fresh

All of my friends (and my bathroom scale, honestly) will tell you that I love tortillas.  Not just any tortillas, however…they have to be homemade.  I make sure we have homemade tortillas every week and keep them in the fridge.  They are better than anything you can buy in a store, and they are simply amazing when they are hot off the comal.  My kids know this; when they see the comal on the stove, they make a point of hanging around the kitchen to snag one (often a few!) while they are fresh because they understand that freshness is everything for tortillas.

It turns out the same is true for vulnerability intelligence!

In just the first 6 months of 2024, we’ve seen over 2,000 remotely exploitable, no-authentication-necessary CVEs be published.  These are the kinds of vulnerabilities that are exploited on the Internet - via APTs and criminals or botnets driving mass exploitation - every minute of every day.  This is a huge amount to deal with, and what we’ve seen this year is that they are occurring more frequently on edge devices that don’t have many mitigating controls to protect them.  When these things happen, it forces security teams to drop what they are doing and scramble for a fix.

There are many existing vulnerability prioritization solutions that can help by including information like “Known Exploits Available” or “In the Wild”. The issue is that these attributes quickly become stale.  Technically, a snippet of proof-of-concept code is an available exploit, but it isn’t the same as a mass exploitation attack by a criminal organization.  A hard-to-exploit race condition that requires a lot of time and effort might be “In the Wild”, but that doesn’t require the same urgency to fix as something an actor is actively exploiting today.  In many ways, these attributes (in addition to CVSS Base Scores, Vendor bulletins, etc) are like stale tortillas - edible but ultimately unsatisfying.

At GreyNoise we believe that security teams deserve actionable information that is fresh enough to know what attackers are doing right now, so that they can respond with the speed and urgency required.  Consequently, today we’re launching GreyNoise for Vulnerability Prioritization to give our customers exactly that.

Here’s how it works:

We run a global network of thousands of sensors that emulate the types of assets enterprises have exposed to the Internet:  web servers, network gear, etc.  We see when attackers and bots start probing them, and we collect the data as they are attacked in real-time.  We compare this against known bad behaviors and known IPs; our ML models are even capable of alerting us to unknown but suspicious or malicious activities that are the hallmarks of novel exploits. This is all unique, primary data that we collect rather than simply aggregating from third-party sources.  In other words, we make fresh tortillas from scratch rather than just reselling ones we bought from a supermarket.

As we collect this information, we make it immediately available via our Visualizer for ad-hoc usage and through our API for inclusion in your existing automation.  We ensure that information is always fresh, so that you can get the most up-to-date intel for as long as you need until you fix the problem.

There are many good vulnerability prioritization tools out there, but we believe that only we can tell vulnerability teams which CVEs need attention now based on what attacks are actually happening today.  Because Vuln Intel is based on all the same data that powers GreyNoise, you’ll also be able to share what you know seamlessly with your SOC analysts and threat hunters.

We think you’ll enjoy having fresh and actionable information with Greynoise Vulnerability Prioritization.  You can visit our website to learn more or schedule time to talk with us directly. 

I know you’ll also love having fresh and delicious tortillas, so please enjoy this recipe.  I look forward to hearing from you about both!

Flour Tortillas Recipe

Ingredients:

  • 4 parts all-purpose flour 
  • .1 part salt
  • 1 parts lard (or shortening, but lard is the best)
  • 2 parts water - hot water for thin and chewy tortillas, cold water for thick and fluffy

For example, I find 300gm (4 x 75gm)  flour + 75gm lard (1 x 75gm) + 8gm salt (.1 x 75gm) mixed with 150gm (2 x 75gm) hot water makes 8 burrito-sized or 12 fajita-sized tortillas.

Instructions:

  • Place flour, salt, and lard in a bowl.  Add in water; if using hot water, give it 30 seconds to melt the lard.
  • Knead for 1 minute - it should be tacky but not so sticky it won't easily come off your fingers; you can add a little flour if needed.
  • Let stand covered for 30 minutes.
  • Heat a cast iron griddle (a skillet works too) on med-high for 5 minutes (i.e. at the 25-minute mark)
  • Divide the dough into golf ball-sized portions.
  • Using a rolling pin, roll one into 6-9 inch diameter rounds.
  • Cook 30 seconds on one side - you'll see bubbles form on the top when it is time to flip.  Now is a great time to roll the next round while it cooks.
  • Flip and cook for another 15-30 seconds; I like longer to get a few charred spots.
  • Stack on a plate and cover with a towel.

Eat them soon — they will be unbelievably good for 60 minutes, very good the rest of the day, and better than anything you can buy in the store for at least a week if you keep them in the fridge. 

Exploring GreyNoise: The User-Centric Design Approach in Cybersecurity

In today’s cyber landscape, blending robust security with effective design is not just beneficial—it’s essential. At GreyNoise, we integrate design principles from the very beginning of our development process, ensuring that every security measure is user-focused and seamlessly integrated. This approach doesn't just enhance the security of digital services; it also ensures that updates and innovative controls fit perfectly within existing systems.

Empowering Users with User-Centric Design

Our philosophy at GreyNoise centers around understanding and addressing your needs, challenges, and feedback. By prioritizing user-centric design, we ensure that each feature and update is not just powerful, but also relatable and engaging.

Putting You First: Your needs, challenges, and feedback are what drive us at GreyNoise. We believe that understanding your perspective is key to making our cybersecurity solutions not just powerful, but also relatable and engaging.

Anticipating Security Needs: We proactively incorporate mechanisms like security logging, monitoring, alerting, and response capabilities into our systems, preparing for potential security incidents before they occur [1].

Join Our Community on Slack: Your insights are invaluable. Engage with us on Slack to share your experiences and suggestions, playing a pivotal role in our product iteration process. Join our Community on Slack.

Simplicity and Accessibility: The Hallmarks of GreyNoise Design

Our commitment to simplicity and accessibility ensures that our tools are straightforward and can be used by everyone. Here’s how we achieve this:

Clutter-Free Interface: Simplicity is central to GreyNoise’s design ethos. Our interfaces are streamlined, focusing on delivering essential information efficiently to prevent overload and facilitate quick, informed decisions.

Focused Feature Set: We hone in on the most impactful features, ensuring our tools are straightforward and effective, making complex threat analysis accessible to all users.

Inclusive Design Philosophy: Upholding the principle that cybersecurity should be accessible to everyone, GreyNoise designs tools that cater to a wide range of abilities, embodying our inclusive design philosophy. Our proof of promise and commitment to accessibility is demonstrated through our Voluntary Product Accessibility Template (VPAT), which details how our products adhere to recognized accessibility standards. This transparency underscores our belief in making security tools accessible to everyone, affirming that effective security is a universal right.

Visual Engagement: Simplifying Complex Information

GreyNoise uses visual elements like infographics to break down complex information, making cybersecurity concepts more understandable and engaging, illustrating the practical benefits of our design-driven approach.

View: https://viz.greynoise.io/tags/palo-alto-pan-os-cve-2024-3400-rce-attempt?days=10

Real-World Applications and User Experiences

GreyNoise consistently demonstrates its commitment to enhancing user capabilities through various educational and interactive platforms. We offer comprehensive demos and case studies, which are pivotal for users looking to deepen their understanding of cybersecurity practices [2]. These resources are tailored to help both novice and advanced users by providing practical, real-world applications of GreyNoise's cybersecurity solutions.

Additionally, GreyNoise is proactive in addressing future cybersecurity concerns by hosting webinars, such as the recent discussion on the future of honeypots. These events aim to educate participants on strategies to combat targeted attacks, reflecting GreyNoise's dedication to keeping the cybersecurity community informed and prepared [3].

A Fusion of Cybersecurity and Design

At GreyNoise, we are redefining the synergy between security and design. Our dedication to user-centric, simple, and accessible design propels us to deliver tools that are not just powerful but also intuitive and inclusive. With GreyNoise, you are equipped with cybersecurity tools designed for the modern digital landscape, where effective security seamlessly integrates with exceptional user experience.

Key Innovations and Features

1. Explore and Investigate: Users can delve into detailed analyses of IP activities, enhancing their understanding and ability to react swiftly to potential threats [4].

2. IP Timeline and Details: Offers a comprehensive view of an IP's history and current status, allowing users to track and analyze behavior patterns over time [5].

3. Alerts and Blocklists: Enables proactive responses with customized alerting systems, ensuring users can respond to threats promptly [6].

At GreyNoise, we don’t just create tools; we build solutions that integrate effective security with exceptional user experience. Our commitment to user-centric, simple, and accessible design drives us to deliver products that not only protect but also empower our users.

Explore GreyNoise’s Design-Centric Cybersecurity Solutions

Dive deeper into how our design-centric cybersecurity solutions can transform your security strategy. Interact with our tools, join our community forum on Slack to share your insights and help shape the future of cybersecurity.

FAQs: 

How does GreyNoise ensure its design is user-centric?

GreyNoise integrates user feedback throughout the design and development process, ensuring that our tools meet real user needs effectively and intuitively.

What are GreyNoise’s key design principles?

We focus on simplicity, user-centricity, and accessibility to ensure our cybersecurity tools are effective and easy to use for everyone.

How can I provide feedback on GreyNoise products?

Join our Slack community! It’s a vibrant space where you can provide direct feedback, suggest improvements, and influence our product development.

Reference: 

  1. Secure by Design Principles
  2. GreyNoise Blog
  3. GreyNoise Resources
  4. GreyNoise Product Overview
  5. IP Timeline Feature
  6. Alerts and Blocklists

GreyNoise Tags Its Way to 1337 Elite Status

Yesterday, GreyNoise reached a fun and significant milestone after publishing our 1,337th tag. 1337 is a cherished number in hacker culture, as it is a numerical shorthand for "leet", which itself stands for "elite". This term has deep roots, going all the way back to the 80's when one had to make modems scream to access bulletin board systems (now, we humans are the ones screaming whenever we go online to see what fresh hades awaits us each day).

What makes this milestone even more significant is how it was achieved.

The chart, below, shows the cumulative sum of tag counts by year. While there was a modest improvement in intra-year tag creation from 2022 to 2023, we're just into the first few weeks of Q2 in 2024 and are almost at the total tag count for 2023.

We will almost certainly blow past 2023's tag count well-before the end of Q2, and this has all been made possible by our focused and practical use of AI. This system helps our incredible detection engineers quickly triage the millions of events our sensor fleet absorbs every day. With it, they discover and tag novel payloads to help inform and protect our customers, community, and the internet as a whole. The application that fuels this work is called Sift, and we've waxed poetic about it quite a bit over the past few months.

This boost to the tag inventory has also meant an increase in CVE coverage.

(Since it most likely drew your attention, the jumps in 2022 were due numerous factors, including the increase in Russian hostilities towards Ukraine.)

60% of 2024 tags are based on CVEs, and — along with plenty of "modern" vulnerabilities — Sift has helped us catch exploitation attempts of some very old CVEs, too:

I'm incredibly proud of our team of data scientists, security researchers, and detection engineers. Their leet expertise powers the detections that folks rely on every day, and we hope you'll join in our celebration of achieving this epic milestone!

To learn more about GreyNoise tags and how they differ from "traditional" detections, check out our Tags Webinar Series.

No blog articles found

Please update your search term or select a different category and try again.

Get started today