Fully configurable, real-time blocklists that stop attackers in their tracks
Turn primary-source edge intelligence from the Global Observation Grid into precision blocklists for your firewalls. Specify the kinds of traffic you want to block: reconnaissance targeting certain technologies, exploitation targeting specific CVEs, traffic originating from certain countries, and more. Once you publish, your blocklists will stay up-to-date as attacker behavior and infrastructure changes.
Traditional blocklists are stuck in the past
Attackers move by the minute, but traditional blocklists don't keep up. Here is where they break down.
Always out of date
Most feeds refresh once a day at best. By the time an IP shows up on the list, the attacker has already moved on.
They overblock
Bloated lists sweep up harmless scanners and real customers along with the threats, so you end up hurting your business trying to stop the bad stuff.
All or nothing
You cannot tune them to the threats you actually care about. You take the entire list or none of it, with nothing in between.
Build. Preview. Block.
Define exactly what you want to block
Start from a library of pre-built templates covering CVE exploit attempts, technology-vendor attacks, Mirai behavior, source geographies, and recent malicious activity. Or build a custom query from scratch with the drag-and-drop Advanced builder. Every list is a live query against primary-source data from the Global Observation Grid.
Open the Query Builder →See the impact before you block anything
Query Stats show you exactly what a list will do before it goes live: total IPs, classification breakdown, source countries, top tags, actors, and ASNs, all updating live as you edit the query.
Try it with live data →Point your firewall at a URL. Done.
Every blocklist gets a dedicated URL your firewall pulls automatically. Lists provision in minutes, refresh every hour with the latest observed activity, and you can edit, download, disable, or delete them anytime. Set an IP limit to match your firewall's capacity. No rip and replace: Block feeds the perimeter tools you already run.
See the deployment guide →If it pulls an IP list, it works with Block
Blocklists deploy as standard External Dynamic Lists over HTTPS, compatible with the firewalls, WAFs, and cloud network controls you already run.











Browse the template library
Every template is a live, GreyNoise-curated query. Search the current library below, exactly as it appears in the product.
Palo Alto (All Activity)
RDP Crawler Malicious or Suspicious Activity
Cisco SSL VPN Bruteforcer Attacks
Recent Suspicious Activity
Source Country China
Source Country Russia or China
Recent Malicious Activity (3d)
Telnet-Tagged Activity
SonicWall (All Activity)
Palo Alto Networks Login Scanner
Ivanti-Tagged Activity
Recent Suspicious OR Malicious Activity
React Server Components Unsafe Deserialization CVE-2025-55182 RCE Attempt
Mirai Botnet
Citrix-Tagged Activity
F5-Tagged Activity
Technology: Palo Alto Networks
Cisco-Tagged Activity
SonicWall-Tagged Activity
Fortinet-Tagged Activity
Source Country North Korea
Source Country Russia
Source Country: Iran
Threats: 2025 CVEs
Threats: All CVEs
All GreyNoise IPs
Non-Benign IPs
Recent Unknown Activity
Recent Malicious Activity
GreyNoise Block or Platform Blocklists?
The same blocking capability, two ways to buy it. GreyNoise Block is a standalone self-service product. Platform Blocklists are built into the GreyNoise Platform for enterprise subscribers.
GreyNoise Block
Standalone and self-service, for small and mid-sized teams. Sign up at block.greynoise.io, build with the drag-and-drop Query Builder and curated templates, and subscribe entirely on your own. Up to 10 blocklists, refreshed hourly.
Best when you want blocking at the firewall today, without procurement delays.
Start your 14-day free trial →Platform Blocklists
Built into the GreyNoise Platform for enterprise subscribers. Turn any Visualizer query into a blocklist using every field in your data module, with quantities set by your Standard, Advanced, or Elite tier.
Best when your team already investigates in the Platform and wants surgical, fully query-driven blocking from the same queries.
Explore the GreyNoise Platform →Stop mass exploitation for good.
Pick a template or write a query, hit publish, and point your firewall to it. Lists will automatically update. Free 14-day trial.



