Charlotte Agentic SOAR combines structured workflows with agentic reasoning to drive machine-speed response. GreyNoise adds real-time intelligence to SOAR playbooks to enrich automated triage and response.
GreyNoise is headed to Fal.Con 2026! Learn how to connect with us >
Three pre-built playbooks operationalize GreyNoise intelligence inside Charlotte Agentic SOAR workflows.

Individual organizations often do not see global exploitation spikes targeting their vendors until it is too late. A surge in scanning or exploitation against a particular CVE can be an early sign of a zero-day or novel exploitation of that vendor’s products, but these are invisible to the individual customers of that vendor. By the time a vendor publishes an advisory, exploitation may have already begun.
This playbook monitors GreyNoise threat intelligence for exploitation spikes against specific CVEs and is triggered when increased exploitation activity is detected. It queries GreyNoise for the malicious IP addresses associated with that exploitation, then generates a comprehensive case file with actionable threat intelligence for security teams. Configure a CVE activity spike feed in the GreyNoise console to define which CVE alerts are sent to CrowdStrike.
Because GreyNoise CVE exploitation events land inside Fusion SOAR, the rest of the response automates from there: case creation, vulnerability management ticketing, and blocklist updates for the IPs doing the exploiting. The result is an early warning when exploitation activity spikes against a CVE relevant to your tech stack.

Most edge devices are embedded systems that cannot run an EDR agent. When these devices are compromised, they often scan the internet or call back to attacker-controlled C2 infrastructure without triggering any alerts. So you typically only find out when reported by external parties or in a post-incident investigation.
This playbook runs when GreyNoise observes your own IP ranges conducting unsolicited scanning, or when internal hosts connect to known callback infrastructure GreyNoise is tracking. Fusion SOAR ingests the alert, enriches with additional context, and creates a case severity and containment ticket. Issues stay tracked in a single case timeline through NG-SIEM's centralized case management

Most SOCs still have analysts manually looking up IPs to determine whether an alert matters. The process is slow, repetitive, and leads to inconsistent triage decisions.
This playbook automatically enriches alerts in Fusion SOAR with GreyNoise classification, tags, and helps to determine the threat level. It then applies decision rules to recategorize case severity automatically.
An alert involving an IP GreyNoise has observed conducting active exploitation can be escalated. Enrichment is written to the case, so the rationale is visible to analysts and available to downstream workflows.
The GreyNoise Fusion SOAR App is available now in the CrowdStrike Falcon Falcon Unified Content Library. Install it to deploy the Fusion SOAR playbooks in your CrowdStrike environment.