GreyNoise Block · For Small & Mid-Sized Teams

Fully configurable, real-time blocklists that stop attackers in their tracks

Turn primary-source edge intelligence from the Global Observation Grid into precision blocklists for your firewalls. Specify the kinds of traffic you want to block: reconnaissance targeting certain technologies, exploitation targeting specific CVEs, traffic originating from certain countries, and more. Once you publish, your blocklists will stay up-to-date as attacker behavior and infrastructure changes.

GREYNOISE BLOCK FIREWALL YOUR NETWORK GLOBAL OBSERVATION GRID Scanning · blocked Malicious · blocked Legitimate · allowed
The Challenge

Traditional blocklists are stuck in the past

Attackers move by the minute, but traditional blocklists don't keep up. Here is where they break down.

Always out of date

Most feeds refresh once a day at best. By the time an IP shows up on the list, the attacker has already moved on.

They overblock

Bloated lists sweep up harmless scanners and real customers along with the threats, so you end up hurting your business trying to stop the bad stuff.

All or nothing

You cannot tune them to the threats you actually care about. You take the entire list or none of it, with nothing in between.

How It Works

Build. Preview. Block.

1. Build

Define exactly what you want to block

Start from a library of pre-built templates covering CVE exploit attempts, technology-vendor attacks, Mirai behavior, source geographies, and recent malicious activity. Or build a custom query from scratch with the drag-and-drop Advanced builder. Every list is a live query against primary-source data from the Global Observation Grid.

Open the Query Builder →
block.greynoise.io/query-builder
QUERY BUILDER29+ TEMPLATES
Blocklist query
tags:"RDP Crawler" last_seen:10d classification:malicious OR suspicious
Query fields
Classification Tag Name CVE ID Source Country Actor CIDR Block First / Last Seen
block.greynoise.io · query stats
TOTAL IP RESULTS: 42.8KBLOCK THESE IPS
Malicious21.09K
Suspicious21.9K
Non-spoofable43.03K
Top sourceUnited States
Top tags
RDP CrawlerTelnet ProtocolMirai
Known benign · excluded
ShadowServer.orgCensysBinaryEdge.io
2. Preview

See the impact before you block anything

Query Stats show you exactly what a list will do before it goes live: total IPs, classification breakdown, source countries, top tags, actors, and ASNs, all updating live as you edit the query.

Try it with live data →
3. Block

Point your firewall at a URL. Done.

Every blocklist gets a dedicated URL your firewall pulls automatically. Lists provision in minutes, refresh every hour with the latest observed activity, and you can edit, download, disable, or delete them anytime. Set an IP limit to match your firewall's capacity. No rip and replace: Block feeds the perimeter tools you already run.

See the deployment guide →
block.greynoise.io/blocklists
RDP Crawler · Malicious REFRESHING ENABLED
IP count / limit31,099 / 1,000,000
RefreshEvery hour
ProvisioningMinutes
FormatExternal Dynamic List
Blocklist URL
https://api.block.greynoise.io/v1/blocklist/…
Actions
Edit queryDownload IPsDisableDelete
Two Ways to Build

Templates for speed. Query Builder for precision.

Deploy an out-of-box list in one click, or tune every condition yourself with the drag-and-drop advanced builder. Either way, the result is a live query and your blocklists update automatically.

Block exploitation of specific CVEs

When a new vulnerability drops, patching takes days. Blocking the IPs actively firing exploits takes minutes, buying critical time for remediation.

1
GN
Pick a template: Threats: All CVEs, 2025 CVEs, or a single CVE
2
last_seen:10d AND spoofable:false AND cve:*CVE*
3
Review query stats
4
Block these IPs

Block IPs attacking your technology stack

Attackers probe for specific appliances. Templates cover the vendors on your edge: Cisco, Citrix, F5, Fortinet, Ivanti, Palo Alto, SonicWall, and more.

1
GN
Pick your vendor template, e.g. Fortinet-Tagged Activity
2
last_seen_malicious:1d AND classification:malicious AND tags:*Fortinet*
3
Review query stats
4
Block these IPs

Block by observed intent

Every IP GreyNoise observes is classified by behavior: malicious, suspicious, benign, or unknown. Choose how aggressive to be.

1
GN
Pick a posture: Recent Malicious, Suspicious, or Non-Benign
2
last_seen_malicious:1d AND classification:malicious AND spoofable:false
3
Tune lookback: 1, 3, 7, or 10 days
4
Block these IPs

Block by source geography

Some organizations have policy reasons to block scanning traffic from specific countries. Templates make it one click.

1
GN
Pick a country template: Russia, China, Iran, North Korea
2
last_seen:1d AND spoofable:false AND metadata.source_country:russia
3
Combine countries with OR groups
4
Block these IPs

Build queries visually, on a canvas

Not everyone writes query languages. The Advanced builder turns queries into blocks you drag onto a canvas, with the query preview updating live.

1
Drag a field: Classification, Tag, CVE ID, Source Country, Actor, CIDR
2
Pick values from dropdowns
3
GN
Query preview + stats update live
4
Block these IPs

Match multiple values with OR groups

Real policies need compound logic: "malicious OR suspicious," "Russia OR China."

2
Add two Classification blocks
2
Set the operator to OR
3
Select both, click Group
4
GN
(classification:malicious OR classification:suspicious)

Exclude what you never want to block

One overblocked business partner ruins trust in the whole list. Every block on the canvas has a NOT toggle.

1
Build your malicious-IP query
2
Add Source Country or CIDR block
3
Toggle NOT to exclude it
4
GN
classification:malicious AND -ip:1.2.3.4/32

Tune recency and rule out spoofed traffic

How aggressive a list should be depends on your risk tolerance. Recency and connection quality are the two dials.

1
Set lookback: 1, 3, 7, or 10 days
2
Choose classification recency: malicious, suspicious, benign, or any
3
GN
Scope to non-spoofable: full TCP connections only

Set it up once, let it run

A blocklist only helps if it stays current without babysitting. Every Block list is a live URL your firewall re-pulls on a schedule.

1
GN
Copy the blocklist URL
2
Add it to your firewall as an External Dynamic List
3
GreyNoise refreshes the list every hour
4
Download current IPs anytime for audit
Two Ways to Build

Templates for speed. Query Builder for precision.

Deploy an out-of-box list in one click, or tune every condition yourself with the drag-and-drop advanced builder. Either way, the result is a live query and your blocklists update automatically.

Pre-Built templates

One click, GreyNoise -recommendations
●  4 categoories

Block exploitation of specific CVEs

When a new vulnerability drops, patching takes days. Blocking the IPs actively firing exploits takes minutes, buying critical time for remediation.

1
GN
Pick a template: Threats: All CVEs, 2025 CVEs, or a single CVE
2
last_seen:10d AND spoofable:false AND cve:*CVE*
3
Review query stats
4
Block these IPs

Block IPs attacking your technology stack

Attackers probe for specific appliances. Templates cover the vendors on your edge: Cisco, Citrix, F5, Fortinet, Ivanti, Palo Alto, SonicWall, and more.

1
GN
Pick your vendor template, e.g. Fortinet-Tagged Activity
2
last_seen_malicious:1d AND classification:malicious AND tags:*Fortinet*
3
Review query stats
4
Block these IPs

Block by observed intent

Every IP GreyNoise observes is classified by behavior: malicious, suspicious, benign, or unknown. Choose how aggressive to be.

1
GN
Pick a posture: Recent Malicious, Suspicious, or Non-Benign
2
last_seen_malicious:1d AND classification:malicious AND spoofable:false
3
Tune lookback: 1, 3, 7, or 10 days
4
Block these IPs

Block by source geography

Some organizations have policy reasons to block scanning traffic from specific countries. Templates make it one click.

1
GN
Pick a country template: Russia, China, Iran, North Korea
2
last_seen:1d AND spoofable:false AND metadata.source_country:russia
3
Combine countries with OR groups
4
Block these IPs

Advanced Query Builder

Drag-and-drop queries, full control
●  5 capabilities

Build queries visually, on a canvas

Not everyone writes query languages. The Advanced builder turns queries into blocks you drag onto a canvas, with the query preview updating live.

1
Drag a field: Classification, Tag, CVE ID, Source Country, Actor, CIDR
2
Pick values from dropdowns
3
GN
Query preview + stats update live
4
Block these IPs

Match multiple values with OR groups

Real policies need compound logic: "malicious OR suspicious," "Russia OR China."

2
Add two Classification blocks
2
Set the operator to OR
3
Select both, click Group
4
GN
(classification:malicious OR classification:suspicious)

Exclude what you never want to block

One overblocked business partner ruins trust in the whole list. Every block on the canvas has a NOT toggle.

1
Build your malicious-IP query
2
Add Source Country or CIDR block
3
Toggle NOT to exclude it
4
GN
classification:malicious AND -ip:1.2.3.4/32

Tune recency and rule out spoofed traffic

How aggressive a list should be depends on your risk tolerance. Recency and connection quality are the two dials.

1
Set lookback: 1, 3, 7, or 10 days
2
Choose classification recency: malicious, suspicious, benign, or any
3
GN
Scope to non-spoofable: full TCP connections only

Set it up once, let it run

A blocklist only helps if it stays current without babysitting. Every Block list is a live URL your firewall re-pulls on a schedule.

1
GN
Copy the blocklist URL
2
Add it to your firewall as an External Dynamic List
3
GreyNoise refreshes the list every hour
4
Download current IPs anytime for audit
Use With Any Firewall

If it pulls an IP list, it works with Block

Blocklists deploy as standard External Dynamic Lists over HTTPS, compatible with the firewalls, WAFs, and cloud network controls you already run.

Next-Gen Firewall
Cloud & Edge
Load Balancer / WAF
Open Source
Ready On Day One

Browse the template library

Every template is a live, GreyNoise-curated query. Search the current library below, exactly as it appears in the product.

Palo Alto (All Activity)

All IPs observed with Palo Alto-related attack tags in the last 10 days.
last_seen:10d AND spoofable:false AND ((classification:suspicious AND last_seen_suspicious:10d) OR (classification:malicious AND last_seen_malicious:10d)) AND tags:*Palo\ Alto*

RDP Crawler Malicious or Suspicious Activity

IPs observed crawling the internet for Remote Desktop Protocol (RDP) by initiating a connection request in the last 10 days.
tags:"RDP Crawler" AND last_seen:10d AND (classification:malicious OR classification:suspicious)

Cisco SSL VPN Bruteforcer Attacks

IPs observed attempting to bruteforce credentials against Cisco SSL VPNs (WebVPN).
last_seen:10d AND spoofable:false AND (classification:malicious OR classification:suspicious) AND tags:Cisco\ SSL\ VPN\ Bruteforcer

Recent Suspicious Activity

IPs observed with suspicious activity in the last day.
last_seen_suspicious:1d AND classification:suspicious AND spoofable:false

Source Country China

Any IPs that originate from China over the last day.
last_seen:1d AND spoofable:false AND metadata.source_country:china

Source Country Russia or China

Any IPs that originate from Russia or China over the last day.
last_seen:1d AND spoofable:false AND (metadata.source_country:russia OR metadata.source_country:china)

Recent Malicious Activity (3d)

IPs observed with malicious activity in the last 3 days.
last_seen_malicious:3d AND classification:malicious AND spoofable:false

Telnet-Tagged Activity

IPs observed with Telnet-related attack tags in the last 10 days.
last_seen_malicious:10d AND classification:malicious AND spoofable:false AND tags:*Telnet*

SonicWall (All Activity)

IPs observed with SonicWall-related attack tags in the last 10 days.
last_seen:10d AND spoofable:false AND ((classification:suspicious AND last_seen_suspicious:10d) OR (classification:malicious AND last_seen_malicious:10d)) AND tags:*SonicWall*

Palo Alto Networks Login Scanner

IPs observed attempting to log in to the Palo Alto Networks PAN-OS GlobalProtect login portal.
last_seen:10d AND spoofable:false AND (classification:malicious OR classification:suspicious) AND tags:Palo\ Alto\ Networks\ Login\ Scanner

Ivanti-Tagged Activity

IPs observed with Ivanti-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*Ivanti*

Recent Suspicious OR Malicious Activity

IPs observed with suspicious or malicious activity in the last day.
last_seen:1d AND spoofable:false AND ((classification:suspicious AND last_seen_suspicious:1d) OR (classification:malicious AND last_seen_malicious:1d))

React Server Components Unsafe Deserialization CVE-2025-55182 RCE Attempt

IPs observed attempting to exploit CVE-2025-55182.
tags:*React\ Server*

Mirai Botnet

IPs exhibiting Mirai behavior in the last week.
last_seen_malicious:7d AND tags:*Mirai*

Citrix-Tagged Activity

IPs observed with Citrix-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*Citrix*

F5-Tagged Activity

IPs observed with F5-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*F5*

Technology: Palo Alto Networks

Any IPs engaged in recon/attack activity for Palo Alto
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*Palo\ Alto*

Cisco-Tagged Activity

IPs observed with Cisco-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*Cisco*

SonicWall-Tagged Activity

IPs observed with SonicWall-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*SonicWall*

Fortinet-Tagged Activity

IPs observed with Fortinet-related attack tags in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false AND tags:*Fortinet*

Source Country North Korea

Any IPs that originate from North Korea over the last day.
last_seen:1d AND spoofable:false AND metadata.source_country:"North Korea"

Source Country Russia

Any IPs that originate from Russia over the last day.
last_seen:1d AND spoofable:false AND metadata.source_country:russia

Source Country: Iran

Any IPs that originate from Iran over the last day.
last_seen:1d AND spoofable:false AND metadata.source_country:iran

Threats: 2025 CVEs

Any IPs engaging in recon or attack activity for any 2025 CVE.
last_seen:10d AND spoofable:false AND cve:CVE-2025*

Threats: All CVEs

Any IPs engaging in recon or attack activity for any CVE.
last_seen:10d AND spoofable:false AND cve:*CVE*

All GreyNoise IPs

All IPs observed in the last 10 days regardless of classification.
last_seen:10d

Non-Benign IPs

Anything observed by GreyNoise in the last day that isn't a known benign organization.
last_seen:1d AND spoofable:false AND -classification:benign

Recent Unknown Activity

IPs observed by GreyNoise with unknown activity in the last day.
last_seen:1d AND spoofable:false AND classification:unknown

Recent Malicious Activity

IPs observed with malicious activity in the last day.
last_seen_malicious:1d AND classification:malicious AND spoofable:false
Which One Is Right for You?

GreyNoise Block or Platform Blocklists?

The same blocking capability, two ways to buy it. GreyNoise Block is a standalone self-service product. Platform Blocklists are built into the GreyNoise Platform for enterprise subscribers.

GreyNoise Block

Standalone and self-service, for small and mid-sized teams. Sign up at block.greynoise.io, build with the drag-and-drop Query Builder and curated templates, and subscribe entirely on your own. Up to 10 blocklists, refreshed hourly.

Best when you want blocking at the firewall today, without procurement delays.

Start your 14-day free trial →

Platform Blocklists

Built into the GreyNoise Platform for enterprise subscribers. Turn any Visualizer query into a blocklist using every field in your data module, with quantities set by your Standard, Advanced, or Elite tier.

Best when your team already investigates in the Platform and wants surgical, fully query-driven blocking from the same queries.

Explore the GreyNoise Platform →

Stop mass exploitation for good.

Pick a template or write a query, hit publish, and point your firewall to it. Lists will automatically update. Free 14-day trial.