NoiseLetter July 2026

Table of Contents
Loading nav...

We just got back from Black Hat and DEF CON 2026 in Las Vegas, where we hosted our fourth annual NoiseFest. Thanks to everyone who came out and made it our best one yet. We have plenty more stops coming this fall, so check out where we'll be below and come find us at a show near you. In the meantime, we've also got new product updates and fresh research to dig into.

Featured

After the Shell: What Attackers Do After They Land a Shell at the Internet's Edge

GreyNoise has always watched the left side of the attack chain. Now we're publishing what we see on the right. "After the Shell" is the first report from GreyNoise Tactics, built from more than 110,000 host sessions read command by command. The headline finding: volume doesn't predict risk. Serious activity was rare, fewer than 1 in 1,000 sessions, and it concentrated on quiet, credential-rich services. The report walks through one React2Shell session that went from a landed shell to cloud credentials, a backdoor superuser, and a container escape in about 82 minutes with no human at the keyboard.

Download the report to see what attackers do after they get in, which of your services they go for, and how to tell the session that matters from the noise.

Download Report >

Product Announcements

Introducing GreyNoise Tactics: See What Adversaries Do After They’re Inside

Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping. Tactics is available for all users who have deployed a GreyNoise Sensor. Join Project Swarm to deploy a GreyNoise Sensor and start observing what attackers do after compromise.
Learn More >>

Intelligence Dashboards in the GreyNoise Platform

The Intelligence Dashboard gives you one always-current view of the threats you care about most. Pin CVEs, tags, countries, IPs, or GNQL queries and quickly spot changes in exploitation activity and trends using primary-source GreyNoise data. Set it up once and check it every morning. Intelligence Dashboards are available to all users.
Learn More >> | View in the Visualizer >>

Coming Soon: A New Way to Navigate GreyNoise...

Fresh Content

At the Edge Clear: This is a preview of GreyNoise’s weekly At the Edge intelligence brief that we provide our customers, featuring select insights distilled from internet activity observed across the GreyNoise Global Observation Grid.  View our latest report >> 

Where to find us

  • Fal.Con
    • 📅 August 31 - September 3, 2026
    • 📍Las Vegas, NV
  • Blue Team Con
    • 📅 September 10 - 13, 2026
    • 📍Chicago, IL
  • FIS-ISAC 2026 Americas Fall Summit
    • 📅 October 26  - 29, 2026
    • 📍Austin, TX 
  • IT-SA Expo & Congress
    • 📅 October 27 - 29, 2026
    • 📍Nuremberg, Germany
  • Fal.Con Europe
    • 📅 November 2 - 4, 2026
    • 📍Barcelona, Spain

Recent Tags and Vulnerabilities

View the recently created tags in the GreyNoise Visualizer. View Recent Tags >

Community

  • GreyNoise Block is available now with a free trial for 14 days. Test it out to build, manage, and deploy GreyNoise blocklists.
  • Try our Free Account - Quickly identify noisy scanners and trending attacks with our free plan.
  • Request a New GreyNoise Tag - Check out our page where our amazing community can submit tag requests to the GreyNoise team. 
  • Join our Community Slack + Discord- We share intel, give real time updates, and the occasional Dad joke. 

Not subscribed to our NoiseLetter? Subscribe here.

Read the transcript

We just got back from Black Hat and DEF CON 2026 in Las Vegas, where we hosted our fourth annual NoiseFest. Thanks to everyone who came out and made it our best one yet. We have plenty more stops coming this fall, so check out where we'll be below and come find us at a show near you. In the meantime, we've also got new product updates and fresh research to dig into.

Featured

After the Shell: What Attackers Do After They Land a Shell at the Internet's Edge

GreyNoise has always watched the left side of the attack chain. Now we're publishing what we see on the right. "After the Shell" is the first report from GreyNoise Tactics, built from more than 110,000 host sessions read command by command. The headline finding: volume doesn't predict risk. Serious activity was rare, fewer than 1 in 1,000 sessions, and it concentrated on quiet, credential-rich services. The report walks through one React2Shell session that went from a landed shell to cloud credentials, a backdoor superuser, and a container escape in about 82 minutes with no human at the keyboard.

Download the report to see what attackers do after they get in, which of your services they go for, and how to tell the session that matters from the noise.

Download Report >

Product Announcements

Introducing GreyNoise Tactics: See What Adversaries Do After They’re Inside

Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping. Tactics is available for all users who have deployed a GreyNoise Sensor. Join Project Swarm to deploy a GreyNoise Sensor and start observing what attackers do after compromise.
Learn More >>

Intelligence Dashboards in the GreyNoise Platform

The Intelligence Dashboard gives you one always-current view of the threats you care about most. Pin CVEs, tags, countries, IPs, or GNQL queries and quickly spot changes in exploitation activity and trends using primary-source GreyNoise data. Set it up once and check it every morning. Intelligence Dashboards are available to all users.
Learn More >> | View in the Visualizer >>

Coming Soon: A New Way to Navigate GreyNoise...

Fresh Content

At the Edge Clear: This is a preview of GreyNoise’s weekly At the Edge intelligence brief that we provide our customers, featuring select insights distilled from internet activity observed across the GreyNoise Global Observation Grid.  View our latest report >> 

Where to find us

  • Fal.Con
    • 📅 August 31 - September 3, 2026
    • 📍Las Vegas, NV
  • Blue Team Con
    • 📅 September 10 - 13, 2026
    • 📍Chicago, IL
  • FIS-ISAC 2026 Americas Fall Summit
    • 📅 October 26  - 29, 2026
    • 📍Austin, TX 
  • IT-SA Expo & Congress
    • 📅 October 27 - 29, 2026
    • 📍Nuremberg, Germany
  • Fal.Con Europe
    • 📅 November 2 - 4, 2026
    • 📍Barcelona, Spain

Recent Tags and Vulnerabilities

View the recently created tags in the GreyNoise Visualizer. View Recent Tags >

Community

  • GreyNoise Block is available now with a free trial for 14 days. Test it out to build, manage, and deploy GreyNoise blocklists.
  • Try our Free Account - Quickly identify noisy scanners and trending attacks with our free plan.
  • Request a New GreyNoise Tag - Check out our page where our amazing community can submit tag requests to the GreyNoise team. 
  • Join our Community Slack + Discord- We share intel, give real time updates, and the occasional Dad joke. 

Not subscribed to our NoiseLetter? Subscribe here.