Pick your platform tier. Layer in the intelligence modules you need.
Talk to us about pricing*Some functionality may require verified Business Email
Enrich alerts with IP context to cut through noise and accelerate triage.
Monitor emerging CVEs and investigate active exploitation to accelerate response.
Full-depth intelligence to validate threat hypotheses and get maximum context for campaigns.
Detect compromised devices by identifying outbound connections to known command-and-control infrastructure.
Filter out known-good business infrastructure from investigations.
Prioritize what to patch based on real-world exploitation activity, not just severity scores.
GreyNoise customers purchase one platform license (Standard, Advanced, or Elite) plus at least one intelligence module (Triage, Investigate, or Hunt). The platform tier controls freshness, lookback, and alerting. The module determines which fields your team has access to. Add-on modules like C2 Detection, Vulnerability Prioritization, and Business Services extend coverage into specialized use cases.
Standard fits teams establishing a foundation for faster detection and response at the edge. Advanced adds Event Feeds and expanded alerting for mid-sized SOCs. Elite is built for threat hunters and mature programs that need near-real-time data, 90-day Recall, and unlimited automation.
If your primary goal is automating basic SIEM triage, start with Triage. Investigate unlocks vital CVE data and deeper threat context, making it the clear choice for early warning on emerging exploits and active alert investigation. For proactive threat hunters, Hunt unlocks fingerprinting, web-traffic insights, and deep protocol analysis. Modules nest: Hunt includes everything in Investigate, which includes everything in Triage.
Add-on modules are separately licensed and attach to any paid platform tier. C2 Detection confirms compromised devices by matching outbound traffic to known attacker callback infrastructure. Vulnerability Prioritization surfaces real-world exploitation data. Business Services filters known-good infrastructure out of investigations.
Yes. Start with the free community tier for basic IP lookups, or request a full-feature trial on a paid platform tier with the modules most relevant to your workflow.
Every paid tier includes access to all GreyNoise integrations (SIEM, SOAR, TIP, firewall) with no per-user licensing.