GreyNoise tags identify actors, tools, and CVEs, and more in our data. IPs can be labeled with one or more tag, and each tag can have a variety of IPs associated with it. Tags are not just limited to CVE based activity. They include behaviors, attribution, and unique traffic characteristics.
See the intent of the activity, associated CVEs, and Contextual information to help you understand the nature of the classification.
View up to 30 days of history of observed IP activity matching the tag, and identify interesting changes.
Pivot to see all IPs that have been tagged, or configure a dynamic blocklists to block activity hitting your perimeter.
Our GreyNoise research team stays on top of emerging vulnerabilities and exploits that result in internet-wide exploitation so that our users don’t miss an emerging threat. With our Trends feature, you can follow these emerging trends, and take action such as block malicious activity from your environment from our Tags page. We also publish regular reports that give customers insight into exploitation activity and threats.
It’s very easy! GreyNoise provides out-of-the-box integrations with many leading SIEM, SOAR, TIP, and other security solutions (view them here) . Customers can also use our comprehensive API to build custom integrations for their use cases. We also provide daily feeds of malicious or benign activity that can be used for bulk analysis integrations.
GreyNoise is constantly updating its databases in real-time. We have thousands of sensors across the world that monitor for internet-wide exploitation, and as soon as our sensors see activity, the behavior is tagged and visible to our customers. Our research team actively stays on top of emerging vulnerabilities to make sure GreyNoise’s NOISE database has the latest threats tagged. Our RIOT database, which labels common business services, is also refreshed regularly and updated with changes.