Product
Explore

IP Similarity

We know that threat actors tend to act in herds/groups, and finding attacker infrastructure when attackers can easily recycle IPs is hard.  Manual analysis is time consuming and can be prone to human error.

A list of questions that the IP Similarity feature can help answer. These include: "Is this IP connected to a larger actor infrastructure?", "Could there be other IPs doing similar things that have compromised me?", "What other IPs are performing similar reconnaissance activities?", "I saw this IP scanning me. How do I find other IPs that might attempt to attack me in the future?".

Proactively uncover reconnaissance scanning and actor infrastructure

We built GreyNoise’s powerful IP Similarity tool to make it easy for security teams to uncover IPs behaving similarly to an IP in question, and examine the similarity and differences side-by-side.

How it works

Often we’ll see a group of IPs that have the same User-Agent or are sending payloads to the same web path...even though they are coming from different geo-locations:

A screenshot of the comparison view in the IP Similarity feature. This examples shows the overlap in web paths scanned between two IPs.

…Or, we might see a group that uses the same OS and are from the same region, but may be scanning slightly different ports:

A screenshot of the comparison view in the IP Similarity feature. This examples shows the overlap in ports scanned between two IPs.

With our IP Similarity feature, you can easily sniff out these groups without pouring over all the raw data to find combinations of similar and dissimilar information!

Cyber Threat Intelligence Analysts

Get advanced IP context.

Use IP Similarity to streamline and validate intelligence gathering for current and emerging threats targeting an organization, with rapid and data-driven identification of IP addresses that display similar patterns.

Threat Hunters

Uncover hidden threats.

Use IP Similarity to proactively search for previously unknown and potentially malicious IP addresses, driving hypothesis development or pivot points to guide in-depth hunting for existing risks to the organization.

Context

Our IP Similarity Summary view that breaks down the high level summary of what fields we found similar in our dataset, and allows you to quickly scan for common fields and tags.

A screenshot of the IP Similarity summary view in the GreyNoise visualizer.

Deep Dive

You can further break down the similarity by each IP, GreyNoise shows the matching / non-matching fields side by side with the target IP in our IP List view.

A screenshot of the comparison view in the IP Similarity feature. This examples shows the overlap in ports scanned between two IPs.

To access IP Similarity, enterprise customers can simply click “Similar IPs” on our IP details page:

FAQ

Documentation guides

Featured content