Product

Product announcements, new feature launches, and roadmap updates — everything you need to stay current on evolving GreyNoise solutions.

Introducing Tactics: See What Adversaries Do After They’re Inside

GreyNoise has spent years observing the earliest stages of an attack. Our Global Observation Grid sees adversaries as they scan the internet, probe exposed systems, and attempt to exploit vulnerabilities at the edge. That visibility has traditionally focused on the left side of the MITRE ATT&CK framework, from Reconnaissance through Initial Access and it’s where we built our primary-source intelligence brand.

But we’ve known that is only half the equation.

Moving Further Right on MITRE ATT&CK

Earlier this year, we launched our C2 Detection Module, expanding our visibility beyond inbound scanning to the attacker-controlled infrastructure used after exploitation. GreyNoise reads the callback destinations embedded in exploit payloads to identify where a compromised device would call home, from malware-hosting servers to suspected C2 infrastructure.

This marked our first move right of Initial Access on MITRE ATT&CK, extending visibility beyond the exploit itself to the infrastructure supporting what happens next. Defenders can match outbound traffic from their edge devices against GreyNoise callback intelligence to identify connections to confirmed malware-serving infrastructure or suspected C2 servers.

See Host Telemetry from GreyNoise Deception Sensors on Your Network 

When we launched Project Swarm, we opened our deception platform to the global security community. Participants could deploy GreyNoise Deception Sensors across their own infrastructure that looked like the firewalls, routers, VPN gateways, and other internet-facing systems that adversaries target.

Project Swarm users gained full visibility into the sessions reaching their sensors, including raw payloads, HTTP headers, TLS metadata, and other behavioral artifacts. 

But a common ask from them was deeper visibility into what happened after an exploit succeeded. What shell commands did the adversary run? What files did they touch? What did they try to do next?

Introducing GreyNoise Tactics

Today, we are launching Tactics, giving anyone deploying a GreyNoise Deception Sensor deeper visibility into what attackers do after initial compromise. 

Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping.

You can find Tactics under Observe → Tactics in the GreyNoise Visualizer. Open a detection to:

  • Follow the attacker’s complete command sequence
  • See the commands, scripts, and binaries the adversary executed
  • Inspect files created or modified, including their SHA256 hashes
  • Review outbound connections to internet destinations
  • Identify attempts to move laterally within your address space

Tactics begin populating when your workspace has a sensor running a vulnerable profile. Once an attacker compromises that profile and performs activity mapped to a MITRE ATT&CK technique, the session will appear as a detection.

Routine and unclassified sessions are filtered out, so the view focuses on meaningful adversary behavior rather than every connection your sensor receives.

See What Happens After the Shell

Because GreyNoise captures the attacker’s interaction with the host, Tactics can identify behavior across the post-compromise stages of MITRE ATT&CK.

That includes:

  • Execution: Commands, scripts, and binaries run after gaining access
  • Persistence: Scheduled jobs, new accounts, and other attempts to maintain access
  • Privilege Escalation: Attempts to gain greater control of the host
  • Defense Evasion: Actions intended to hide activity or interfere with protections
  • Credential Access: Searches for cloud credentials, private keys, service account tokens, and other secrets
  • Discovery: Commands used to inspect the operating system, processes, files, and surrounding environment
  • Lateral Movement: Attempts to reach other systems from the initial foothold, a view that keeps expanding as our deception network grows 
  • Collection: Files and data gathered from a system they think they’ve compromised 
  • Command and Control: Connections used to retrieve payloads or maintain access
  • Exfiltration: Attempts to move credentials, files, or other data off the sensor
  • Impact: Activity intended to disrupt the host, consume resources, or interfere with processes

With Tactics, GreyNoise now shows what adversaries do with access, not just how they find and exploit exposed systems.

Turn Observed Behavior Into Action

Every command, file, hash, path, and network connection captured by a sensor gives defenders a lead they can investigate inside their own environment.

  • SOC analysts and detection engineers can build and tune detections around the commands and techniques adversaries are using now.
  • Threat hunters can search production environments for observed hashes, file paths, binaries, and command patterns.
  • Threat intelligence teams can track which tactics and techniques are appearing across infrastructure relevant to their organization.

Because this intelligence comes directly from observed session activity, defenders can work from what the adversary actually did after gaining access. Mapping that activity to MITRE ATT&CK makes it easier to understand and use across existing security workflows.

What We Found After the Shell

Before launching Tactics, we analyzed weeks of post-compromise activity across our own Deception Sensor network in the Global Observation Grid.

Much of what we observed was commodity cryptomining, with adversaries treating each new foothold as more infrastructure to consume. A smaller set of sessions showed more serious behavior, going after cloud credentials, attempting container escapes, or creating backdoor accounts.

We break down these findings in After the Shell, a new GreyNoise research report published today. It examines what adversaries did after gaining access, which behaviors appeared most often, and what those observations mean for defenders.

‍

Join the Swarm

Tactics is available for all users who have deployed a GreyNoise sensor. If you already have a sensor deployed, open Tactics under Observe in the GreyNoise Visualizer to see what it has captured.

If you’re new to Project Swarm, deploy a Greynoise Deception Sensor to start observing what attackers do after compromise.

‍

‍

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

GreyNoise Use Cases: Twitter Edition

Andrew Morris got on a roll the other day and whacked out this tweetstorm describing the three key use cases for GreyNoise. You can check out the original Twitter thread here. Enjoy!

I'd like to do an overview of the three most common use-cases to use  @GreyNoiseIO  for.   1. Ignore/deprioritize pointless telemetry or alerts in the SOC 2. Identify compromised systems 3. Track which vulnerabilities are being opportunistically exploited ITW  Thread (1/26)

1. Improve SOC efficiency

Benign IPs

Let's say I get a wacky IDS alert or am seeing something strange in my logs. I'll look up the IP address in GreyNoise (either using our visualizer or our free community API.

I looked up the IP address and, oh wow! It's just Shodan! GreyNoise already marked it as benign. No big deal. Paste a link in your ticket to the GreyNoise visualizer and move on.

https://viz.greynoise.io/ip/71.6.135.131

Example of GreyNoise Visualizer showing benign IP address detail

Maybe I don't want to use the GreyNoise web interface. Let's say I look up the IP in the free unauthenticated GreyNoise Community API and... cool, reports back that it's Censys. No problemo. Move on.

Example of GreyNoise Community API showing benign IP address detail

Malicious IPs

Let's say I look up an IP address, and it comes back with this big scary red IP address that says "malicious." What does this mean?

https://viz.greynoise.io/ip/45.155.205.165

Example of GreyNoise Visualizer showing malicious IP address detail

Well, this means that the IP is probably malicious (or was observed by GreyNoise doing something bad on our sensors), but whatever attack you're seeing is not targeted at *you specifically*. It was an opportunistic attack. Background noise.

Unknown IPs (to GreyNoise)

What if the IP address... doesn't come back at all?

This means that we've never seen that IP scanning/crawling the Internet, and it doesn't belong to any benign business services. It actually *might* be targeted your organization specifically. Investigate.

Example of GreyNoise Visualizer showing "No results found"

GreyNoise APIs

The GreyNoise Community API is rate limited to a few thousand lookups per day, but it's completely free and unauthenticated. As long as we continue to add enterprise customers and can afford to pay our staff and AWS bills, this will continue to be free.

Note that you don't get context, raw data, metadata, or tags using the Community API. Sorry folks, we've gotta make our money somewhere. This is available in our Enterprise API. If you want this data via API, hit up our sales team. But hey, it's free.

Fun fact: Just about every customer we have at GreyNoise sees at least a 20% alert contextualization/reduction rate from using GreyNoise. That's a LOT of wasted human hours spent chasing ghosts.

Analyze a List of IPs

Now let's say you've had an incident, and you need to figure out which of the gazillion IP addresses in some log file compromised your device.

No problemo. Just dump the log file (or just the IP addresses) into the GreyNoise analysis page, and now you can do two things:

  1. Quickly filter out known good guys
  2. If the situation warrants it, quickly identify opportunistic bad guys.

Here's an Analysis from an SSH auth.log I grabbed on a live server on the Internet.

~*~97.22% noise~*~

Example of GreyNoise Visualizer showing Analysis results

Filter Known-Benign Services (RIOT)

Let's say I'm trawling through a ton of netflow logs, and I want to identify any connections OUT of my network that might be going to bad guys.

I can filter known-benign services (Zoom, Github, Office365, Cloudflare, etc.). I can use GreyNoise RIOT for this.

Example of netflow log with a large number of IP addresses to triage
After analysis, just a handful of IP addresses are identified as "malicious" or "unknown"
Example of GreyNoise Visualizer showing RIOT IP address detail

*I'd like to note here that the IPs in RIOT *could potentially* be used by a sufficiently advanced adversary to attack you (async c2, etc.), but that doesn't mean that 99% of bad guys will be doing this, and it's not like you can just *BLOCK ZOOM* and not expect blowback.

Don't think of RIOT as a NACL or whitelist/allowlist. Think of RIOT as added context and a time-saver. You can either find out from GreyNoise via RIOT, or you can find out from your helpdesk reps when you block an IP and execs suddenly can't send emails anymore ¯\_(ツ)_/¯

2. Identify compromised devices

Let's say I want to find compromised devices that belong to ME, my users, or just some interesting network around the world.

Just punch in a GNQL query into the web interface of the IP block I'm interested in + the facet: "classification:malicious"

Example of GreyNoise Visualizer showing malicious scanning from devices within an IP address range

You can actually also find compromised devices in other facets as well. Here are examples of finding compromised devices in a specific country or using free text search to find compromised devices in hospitals or government facilities (or both):

Example of GreyNoise Visualizer showing malicious IP addresses related to government
Example of GreyNoise Visualizer showing malicious IP addresses related to hospitals
Example of GreyNoise Visualizer showing malicious IP addresses from a country related to hospitals

You can use your FREE GreyNoise account to register alerts on any network block or IPs. Once you've registered your alerts, we email you if we see any of your IPs get compromised (e.g., unexpectedly start scanning the internet )

https://viz.greynoise.io/account/alerts

Example of GreyNoise Visualizer showing how to set up Alerts

3. Emerging vulnerability exploitation

You can use GreyNoise to find whether a given vulnerability is being opportunistically exploited or "vuln checked" at scale. Simply craft a GNQL query for CVE.

https://viz.greynoise.io/query/cve:CVE-2021-3129

Example of GreyNoise Visualizer showing malicious IP addresses related to a CVE

When a big scary vulnerability is announced, basically everyone has the exact same thought:

"How much do I **really** have to care about this? Is this... being exploited in the wild right now?"

GreyNoise is declaring war on this ambiguity.

You can also see *which* CVEs a given IP address is probing the internet for or opportunistically exploiting. This list is not exhaustive - it takes a lot of work to add coverage to these. This is what @ackmage @nathanqthai and @4b4c41 do.

Example of GreyNoise Visualizer for a malicious IP address showing targeted CVEs

Our Business Model

We have a long ways to go on properly productizing this offering. It's really hard to do at scale, and not every vulnerability can be exploited in a way that GreyNoise will ever see. That said, we'll be announcing some new offerings focusing on this use case later this year.

Our business model is pretty simple:

  • Most viz stuff == free but rate limited
  • Community API == free but rate limited
  • GreyNoise in your SIEM/TIP/SOAR == paid

Expect a lot of this stuff to shift over the next few months/years as we find better ways to price/package our features.

That pretty much covers it.

Here are my asks to you:

  • If you use GreyNoise's free products, get in touch with @SupriyaMaz and she'll hook you up with free swag
  • If you work in SOC/TI or at an MSSP and want to hear about our commercial offering, ping sales@greynoise.io

And, of course, ping me anytime. I can't promise a snappy response, but I try to clear my inbox at least every few weeks (aspirational). My email is andrew@greynoise.io.

Oh, last thing. We tag like... hundreds of activities and actors and exploits and vuln probes and tools. Check them all out here (it's searchable, but the layout is pretty unwieldy considering how massive our tag library is now).

https://viz.greynoise.io/tags

Some of the activities and actors and exploits and vuln probes GreyNoise has identified

Onward.

--Andrew

‍

GreyNoise Use Cases: Twitter Edition V2

Andrew Morris got on a roll the other day and whacked out this tweetstorm describing the three key use cases for GreyNoise. Enjoy!


No blog articles found

Please update your search term or select a different category and try again.

Get started today