Using GreyNoise Alerts

Get an email if GreyNoise observes any Internet scan and attack traffic originating from networks that belong to you. It's that simple.

Input your CIDR blocks and configure the names and intervals. When an alert is triggered we'll send an email summary with IPs matched to your query.

Alerts also accept GNQL syntax. Example:"Acme, Inc" classification:malicious spoofable:false

Standard and Enterprise subscribed users will receive:

  • - Optional file attachment (JSON, CSV) with full query results
  • - Monitor an unlimited amount of networks
  • - Alerts on realtime or hourly intervals
  • - Receive notifications by webhook or Slack notification

This feature is in beta. Please send all bugs and feedback to