GreyNoise (v2.1.0)

GreyNoise is a threat intelligence service that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats. The full integration code can be found here: https://github.com/demisto/content/tree/master/Packs/GreyNoise

Author
GreyNoise
Support
partner
URL
https://greynoise.io
Categories
Data Enrichment & Threat Intelligence

Integrations (2)

README

GreyNoise tells security analysts what not to worry about. We do this by curating data on IPs that saturate security
tools with noise. This unique perspective helps analysts confidently ignore irrelevant or harmless activity, creating
more time to uncover and investigate true threats. Includes Actions to allow IP enrichment and GNQL queries via
the GreyNoise API.

What does this pack do?

The playbooks and actions in this pack help you to reduce Internet-Background noise and benign services from your
Incident Response work.
They also help automate repetitive tasks associated with routable IPv4 addresses:

This Pack Contains two Integrations: GreyNoise and GreyNoise Community

For more information, visit our GreyNoise Documentation

For pricing information, visit our GreyNoise Pricing or contact
GreyNoise Sales

For GreyNoise support, contact GreyNoise Support

Pack Contributors


Contributions are welcome and appreciated. For more info, visit our Contribution Guide.