Icon depicting right-facing arrow

ThreatQ

Query GreyNoise for metadata including reverse DNS tags, geolocation, and scanned paths/ports

ThreatQ is a data-driven threat intelligence platform thatallows you to automate the intelligence lifecycle, quickly understand threats, make better decisions and accelerate threat detection, investigation and response.

Use GreyNoise to query GreyNoise for additional indicator context. With this operation users can query GreyNoise for metadata including reverse DNS tags, geolocation, and scanned paths/ports. Once a query has performed, this metadata can be linked and saved to the initial indicator.

  • Ingests new, malicious IP Addresses every day. Additionally, a GNQL query can be provided to narrow down the results.
  • Query GreyNoise with IP Addresses from a Threat Collection and enriches those IP Addresses with the data that it ingests.