Greynoise Platform

Get an early warning when traffic spikes indicate a high likelihood of new disclosures.

Find out immediately if an asset communicates with a malicious IP address.

Get real-time insight into active exploitation trends to better understand risk and severity.

Filter out noisy, low priority and false-positive alerts from mass internet scanners.

Add context to incidents to speed the determinations of scope and timelines.

Quickly identify anomalous behavior and enrich your threat hunting campaigns.

Fully configurable, real-time blocklists to stop attackers in their tracks.

Enrich alerts with IP context to cut through noise and accelerate triage.

Monitor emerging CVEs and investigate active exploitation to accelerate response.

Full-depth intelligence to validate threat hypotheses and get maximum context for campaigns.

Detect compromised devices by identifying outbound connections to known command-and-control infrastructure.

Filter out known-good business infrastructure from investigations.

Prioritize what to patch based on real-world exploitation activity, not just severity scores.

DATA

Data Freshness (Triage, Investigate, Hunt, Vuln)

  • Every 8 hours

Data Freshness (Business Services)

  • Monthly

Recall (Historical Lookback)

  • Up to 10 days*

features

  • Alerts: 3
  • Feeds: —
  • Blocklists: 1
  • IP Timeline:

Services & Support

  • Availability: 8hr ET x 5d
  • SLA: None
  • Channels: Slack

Usage & Integrations

  • Searches: Up to 50 / week*
  • API: Community
  • Visualizer:
  • Integrations: —
  • Users: —

DATA

Data Freshness (Triage, Investigate, Hunt, Vuln)

  • Every 4 hours

Data Freshness (Business Services)

  • Weekly

Recall (Historical Lookback)

  • 10 days

features

  • Alerts: 10
  • Feeds: —
  • Blocklists: 3
  • IP Timeline:

Services & Support

  • Availability: 8hr ET x 5d
  • SLA: 1 business day
  • Channels: Slack, Email

Usage & Integrations

  • Searches: Unlimited
  • API: Enterprise + GNQL
  • Visualizer:
  • Integrations: All
  • Users: Unlimited

DATA

Data Freshness (Triage, Investigate, Hunt, Vuln)

  • Every 2 hours

Data Freshness (Business Services)

  • Daily

Recall (Historical Lookback)

  • 30 days

features

  • Alerts: 25
  • Feeds:
  • Blocklists: 10
  • IP Timeline:

Services & Support

  • Availability: 8hr ET x 5d
  • SLA: 8 hours
  • Channels: Slack, Email

Usage & Integrations

  • Searches: Unlimited
  • API: Enterprise + GNQL
  • Visualizer:
  • Integrations: All
  • Users: Unlimited

DATA

Data Freshness (Triage, Investigate, Hunt, Vuln)

  • Every hour

Data Freshness (Business Services)

  • Every 4 hours

Recall (Historical Lookback)

  • 90 days

features

  • Alerts: Unlimited
  • Feeds:
  • Blocklists: Unlimited
  • IP Timeline:

Services & Support

  • Availability: 12hr ET x 5d
  • SLA: 4 hours
  • Channels: Slack, Email

Usage & Integrations

  • Searches: Unlimited
  • API: Enterprise + GNQL
  • Visualizer:
  • Integrations: All
  • Users: Unlimited