Skip to main content

GreyNoise Community

This Integration is part of the GreyNoise Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

GreyNoise tells security analysts what not to worry about. We do this by curating data on IPs that saturate security tools with noise. This unique perspective helps analysts confidently ignore irrelevant or harmless activity, creating more time to uncover and investigate true threats. The Action allows IP enrichment via the GreyNoise Community API.

The GreyNoise Integration should be used by customers with a paid subscription to GreyNoise with the exception of the IP command, which is available with limit results to free users.

This integration was integrated and tested with version 3.0.0 of GreyNoise Python SDK. Supported Cortex XSOAR versions: 6.0.0 and later.

Configure GreyNoise in Cortex#

ParameterDescriptionRequired
api_keyGreyNoise API KeyTrue
proxyUse system proxy settingsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

greynoise-community-lookup#


Queries IPs in the GreyNoise Community API.

Base Command#

ip

Input#

Argument NameDescriptionRequired
ipList of IPs.Required

Context Output#

PathTypeDescription
DBotScore.IndicatorStringThe indicator that was tested.
DBotScore.ReliabilityStringThe reliability value.
DBotScore.ScoreNumberThe actual score.
DBotScore.TypeStringThe indicator type.
DBotScore.VendorStringThe vendor used to calculate the score.
IP.AddressstringIP address.
IP.ASNstringASN Value.
IP.Geo.CountrystringSource Country.
IP.Geo.DescriptionstringAdditional Geo Information - City, Region, Country Code.
IP.HostnamestringrDNS value.
IP.Malicious.DescriptionstringDescription of Malicious IP.
IP.Malicious.VendorstringVendor Identifying IP as Malicious.
GreyNoise.IP.actorstringName of identified organization scanning.
GreyNoise.IP.addressstringThe IP address of the scanning device IP.
GreyNoise.IP.botbooleanIdentifies if the IP is associated with BOT activity.
GreyNoise.IP.categorystringIf a business service, identifies the category.
GreyNoise.IP.classificationstringWhether the device has been categorized as unknown, benign, or malicious.
GreyNoise.IP.descriptionstringIf there is a business service, provides a description of the provider.
GreyNoise.IP.explanationstringIf there is a business service, provides an explanation of the category.
GreyNoise.IP.first_seenstringThe date of the first observed scanning activity.
GreyNoise.IP.foundbooleanWhether the IP is found in GreyNoise.
GreyNoise.IP.ipstringThe IP address of the scanning device IP.
GreyNoise.IP.last_seenstringThe date of the last observed scanning activity.
GreyNoise.IP.last_seen_timestampstringThe timestamp of the last observed scanning activity.
GreyNoise.IP.last_updatedstringIf there is a business service, indicates the last time the source record was parsed.
GreyNoise.IP.metadata.asnstringThe autonomous system identification number.
GreyNoise.IP.metadata.carrierstringThe carrier information for the IP address.
GreyNoise.IP.metadata.categorystringWhether the device belongs to a business, isp, hosting, education, or mobile network.
GreyNoise.IP.metadata.datacenterstringThe datacenter information for the IP address.
GreyNoise.IP.metadata.destination_countriesarrayThe list of countries targeted by scanning.
GreyNoise.IP.metadata.destination_country_codesarrayThe list of country codes targeted by scanning.
GreyNoise.IP.metadata.domainstringThe domain associated with the IP address.
GreyNoise.IP.metadata.latitudenumberThe latitude coordinate of the IP address location.
GreyNoise.IP.metadata.longitudenumberThe longitude coordinate of the IP address location.
GreyNoise.IP.metadata.mobilebooleanWhether the device is on a mobile network.
GreyNoise.IP.metadata.organizationstringThe organization that owns the network that the IP address belongs to.
GreyNoise.IP.metadata.osstringThe name of the operating system of the device.
GreyNoise.IP.metadata.rdnsstringReverse DNS lookup of the IP address.
GreyNoise.IP.metadata.rdns_parentstringThe parent domain of the reverse DNS lookup.
GreyNoise.IP.metadata.rdns_validatedbooleanWhether the reverse DNS lookup has been validated.
GreyNoise.IP.metadata.regionstringThe full name of the region the device is geographically located in.
GreyNoise.IP.metadata.sensor_countnumberThe number of sensors that observed activity from this IP.
GreyNoise.IP.metadata.sensor_hitsnumberThe number of sensors events recorded from this IP.
GreyNoise.IP.metadata.single_destinationbooleanWhether the IP targets a single destination.
GreyNoise.IP.metadata.source_citystringThe city where the IP is geographically located.
GreyNoise.IP.metadata.source_countrystringThe full name of the IP source country.
GreyNoise.IP.metadata.source_country_codestringThe country code of the IP source country.
GreyNoise.IP.namestringIf there is a business service, indicates the provider name.
GreyNoise.IP.raw_data.source.bytesnumberThe number of bytes sent by the source.
GreyNoise.IP.referencestringIf there is a business service, indicates the references used to validate the entry.
GreyNoise.IP.riotbooleanWhether the IP is in the business services dataset.
GreyNoise.IP.seenbooleanWhether the IP is in the internet scanner dataset.
GreyNoise.IP.spoofablebooleanWhether the IP complete a three-way handshake during scanning.
GreyNoise.IP.tags.categorystringThe category of the given tag.
GreyNoise.IP.tags.createddateThe date the tag was added to the GreyNoise system.
GreyNoise.IP.tags.descriptionstringA description of what the tag identifies.
GreyNoise.IP.tags.idstringThe unique id of the tag.
GreyNoise.IP.tags.intentionstringThe intention of the associated activity the tag identifies.
GreyNoise.IP.tags.namestringThe name of the tag.
GreyNoise.IP.tags.recommend_blockbooleanIndicates if IPs associated with this tag should be blocked.
GreyNoise.IP.tags.referencesstringA list of references used to create the tag.
GreyNoise.IP.tags.slugstringThe unique slug of the tag.
GreyNoise.IP.tags.updated_atdateThe date the tag was last updated.
GreyNoise.IP.torbooleanWhether the IP is on the known TOR exit node list.
GreyNoise.IP.trust_levelstringIf there is a business service, indicates the level of trustworthiness.
GreyNoise.IP.vpnbooleanWhether the IP is associated with a knwon VPN service.
GreyNoise.IP.vpn_servicestringIf the IP is part of a VPN, provides the name of the service.

Command Example#

!greynoise-community-lookup ips=1.1.1.1 !IPReputation ip=1.1.1.1

Human Readable Output#

IP: 1.1.1.1 found with Reputation: Good#

Belongs to Common Business Service: Cloudflare Public DNS#

GreyNoise Business Service Intelligence Lookup#

IPBusiness ServiceCategoryNameTrust LevelDescriptionLast Updated
1.1.1.1truepublic_dnsCloudflare Public DNS1 - Reasonably IgnoreCloudflare, Inc. is an American web infrastructure and website security company, providing content delivery network (CDN) services, distributed denial of service (DDoS) mitigation, Internet security, and distributed domain name system (DNS) services. This is their public DNS offering.2025-06-26T09:10:56Z

IP: 1.1.1.1 No Mass-Internet Scanning Observed#

GreyNoise Internet Scanner Intelligence Lookup#

IPInternet Scanner
1.1.1.1false