GreyNoise Indicator Feed
GreyNoise is a cybersecurity platform that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats. This Integration provides a feed of IPv4 Internet Scanners from GreyNoise.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedGreyNoiseIndicator
Configuration parameters
- feed — Fetch indicators
- credentials — Username
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- greynoiseFeedType — GreyNoise Feed Type (required)
- feedTags — Tags
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedBypassExclusionList — Bypass exclusion list
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (1)
- greynoise-get-indicators — Gets the feed indicators.