Icon depicting right-facing arrow
All integrations
SOAR
Integration

Splunk SOAR (Phantom)

Enrich Splunk SOAR playbooks with GreyNoise edge intelligence to accelerate investigations and power automated, agent-assisted response.

Integration Overview

Splunk SOAR combines playbook automation, orchestration, and case management, while its integration with Splunk Enterprise Security extends those workflows with agentic AI. GreyNoise adds real-time edge intelligence to help teams and AI-assisted workflows identify malicious scanning activity, investigate threats, and make more informed response decisions.

How GreyNoise and Splunk SOAR Work Together

On-demand IP enrichment actions, scheduled GNQL polling, GreyNoise feed webhooks, and customizable playbooks operationalize four investigation and response use cases in Splunk SOAR.

Detect Compromised Edge Devices

Overview

Compromised edge devices can scan the internet or communicate with attacker-controlled infrastructure undetected. VPN gateways, firewalls, load balancers, and IoT and OT devices cannot run endpoint agents, so security teams often do not discover the compromise until the activity is observed or reported by an external party.

‍

The GreyNoise Solution

Configure the GreyNoise On Poll action in Splunk SOAR with a GNQL query scoped to your organization's owned IP ranges. When one of your own addresses appears in GreyNoise's observation data, that device is probing the GreyNoise sensor fleet, which is a confirmation of compromise rather than a suspicion. Splunk SOAR creates a container for each result, and playbooks enrich the IP, set severity, and open the appropriate investigation or response workflow. Teams detect compromised assets before the activity causes broader exposure or reputation damage.

IP Enrichment for Faster Triage and Response

Overview

Many SOCs still rely on analysts to research IP addresses manually before determining whether an alert requires action. Repeating that process across every alert slows triage and can lead to inconsistent decisions across the team.

‍

The GreyNoise Solution

Use GreyNoise enrichment actions in Splunk SOAR playbooks to automatically add classification, tags, activity history, and network context to IP-based alerts. Pre-built playbooks can use that intelligence to update case severity, giving analysts a faster and more consistent way to determine which activity requires investigation.

Early Warning for Vendor CVE Exploitation Spikes

Overview

Individual organizations often cannot see exploitation patterns emerging across the internet. A sudden increase in scanning or exploitation against a vendor’s CVE can signal a zero-day or novel attack before the vendor publishes an advisory.

‍

The GreyNoise Solution

Use GreyNoise CVE activity alerts as an early-warning signal, then pass the relevant CVE into the pre-built Network Containment playbook in Splunk SOAR. The playbook queries GreyNoise for IPs associated with that CVE, filters the results by classification and recency, and sends eligible IPs to a configured firewall or security device for blocking. This helps teams contain malicious infrastructure and prioritize patching before exploitation becomes widespread.

Build High-Trust Blocklists

Overview

Automating blocklist updates can accelerate response, but blocking an IP associated with a legitimate business service can disrupt critical operations. Security teams need a reliable validation step before taking containment action.

‍

The GreyNoise Solution

Use the GreyNoise Business Services lookup in Splunk SOAR playbooks to identify IPs associated with known business services before adding them to a blocklist. Playbook decision rules can route business-service matches for analyst review and pass other eligible IPs to configured containment actions. This helps teams automate response with greater confidence while reducing the risk of disrupting legitimate services.

Integration Details

Delivered As
GreyNoise for SOAR connector app
Includes
Connector actions and pre-built playbooks
Refresh
On-demand, scheduled polling, and webhooks
Works with
Splunk SOAR, formerly Phantom
REQUIREMENTS
GreyNoise API key and a GNQL query for On Poll
CATEGORY
SOAR
VENDOR
Splunk
MAINTAINED BY
Joint (GreyNoise + Vendor)