Splunk SOAR combines playbook automation, orchestration, and case management, while its integration with Splunk Enterprise Security extends those workflows with agentic AI. GreyNoise adds real-time edge intelligence to help teams and AI-assisted workflows identify malicious scanning activity, investigate threats, and make more informed response decisions.
On-demand IP enrichment actions, scheduled GNQL polling, GreyNoise feed webhooks, and customizable playbooks operationalize four investigation and response use cases in Splunk SOAR.
Compromised edge devices can scan the internet or communicate with attacker-controlled infrastructure undetected. VPN gateways, firewalls, load balancers, and IoT and OT devices cannot run endpoint agents, so security teams often do not discover the compromise until the activity is observed or reported by an external party.
Configure the GreyNoise On Poll action in Splunk SOAR with a GNQL query scoped to your organization's owned IP ranges. When one of your own addresses appears in GreyNoise's observation data, that device is probing the GreyNoise sensor fleet, which is a confirmation of compromise rather than a suspicion. Splunk SOAR creates a container for each result, and playbooks enrich the IP, set severity, and open the appropriate investigation or response workflow. Teams detect compromised assets before the activity causes broader exposure or reputation damage.
Many SOCs still rely on analysts to research IP addresses manually before determining whether an alert requires action. Repeating that process across every alert slows triage and can lead to inconsistent decisions across the team.
Use GreyNoise enrichment actions in Splunk SOAR playbooks to automatically add classification, tags, activity history, and network context to IP-based alerts. Pre-built playbooks can use that intelligence to update case severity, giving analysts a faster and more consistent way to determine which activity requires investigation.
Individual organizations often cannot see exploitation patterns emerging across the internet. A sudden increase in scanning or exploitation against a vendor’s CVE can signal a zero-day or novel attack before the vendor publishes an advisory.
Use GreyNoise CVE activity alerts as an early-warning signal, then pass the relevant CVE into the pre-built Network Containment playbook in Splunk SOAR. The playbook queries GreyNoise for IPs associated with that CVE, filters the results by classification and recency, and sends eligible IPs to a configured firewall or security device for blocking. This helps teams contain malicious infrastructure and prioritize patching before exploitation becomes widespread.
Automating blocklist updates can accelerate response, but blocking an IP associated with a legitimate business service can disrupt critical operations. Security teams need a reliable validation step before taking containment action.
Use the GreyNoise Business Services lookup in Splunk SOAR playbooks to identify IPs associated with known business services before adding them to a blocklist. Playbook decision rules can route business-service matches for analyst review and pass other eligible IPs to configured containment actions. This helps teams automate response with greater confidence while reducing the risk of disrupting legitimate services.