It’s hard to remember to check on specific GreyNoise queries that you’re interested in Every.Single.Day. That’s why we created GreyNoise Alerts: a quick and easy way to set up automated queries and send you a daily report if there are results.
You can use our alerts to monitor a CIDR range (example: 54.24.0.0/16), or define complex alerts with GNQL syntax such as:
Creating an alert is simple! From the Alerts page , just type the query as you would in the search bar, add any emails you want to receive the report, give it a name and click “Save”.
When an alert is triggered we'll send an email summary with IPs matched to your query.
Our GreyNoise research team stays on top of emerging vulnerabilities and exploits that result in internet-wide exploitation so that our users don’t miss an emerging threat. With our Trends feature, you can follow these emerging trends, and take action such as block malicious activity from your environment from our Tags page. We also publish regular reports that give customers insight into exploitation activity and threats.
It’s very easy! GreyNoise provides out-of-the-box integrations with many leading SIEM, SOAR, TIP, and other security solutions (view them here) . Customers can also use our comprehensive API to build custom integrations for their use cases. We also provide daily feeds of malicious or benign activity that can be used for bulk analysis integrations.
GreyNoise is constantly updating its databases in real-time. We have thousands of sensors across the world that monitor for internet-wide exploitation, and as soon as our sensors see activity, the behavior is tagged and visible to our customers. Our research team actively stays on top of emerging vulnerabilities to make sure GreyNoise’s NOISE database has the latest threats tagged. Our RIOT database, which labels common business services, is also refreshed regularly and updated with changes.
GreyNoise provides a variety of resources to ensure our users are successful, including documentation, in-product onboarding, and training. Our paid customers also get onboarding and support provided by our excellent Customer Success team.
GreyNoise alerts are used to alert via email when an IP matching the provided alert configuration (either by CIDR or GNQL search) is observed scanning the internet.
The GreyNoise University - Product Overview training series covering the alerts feature, and how you can use it to be alerted on what matters most to you.
By Nick Roy
How often do you find yourself asking “is this targeting me or just opportunistically exploiting parts of the internet?” Whether this has happened to you once or happens every single day, you probably spent too much time trying to figure out the answer.
By Nick Roy
Cyber threats are constantly evolving, and organizations need to stay on top of the latest techniques and tools to protect themselves against attacks.