GreyNoise Intelligence website screenshot

GreyNoise Intelligence

GreyNoise Intelligence collects and analyzes Internet-wide scan and attack traffic from a global network of sensors. Use GreyNoise to contextualize alerts, filter false positives, identify compromised devices, prioritize vulnerabilities by in-the-wild exploitation, and track emerging threats. The platform exposes a free Community API and a paid Enterprise API surface (IP Lookup, GNQL, RIOT/Business Services, Tags, CVE, Sessions, Callback, Recall, IP Timeline, Utility) plus an MCP server for AI workflows.

GreyNoise Intelligence publishes 10 APIs on the APIs.io network, including Callback API, Community API, CVE API, and 7 more. Tagged areas include Security, Threat Intelligence, Cybersecurity, IP Reputation, and Vulnerability Management.

The GreyNoise Intelligence catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

GreyNoise Intelligence’s developer surface includes authentication, developer console, signup flow, pricing, support, FAQ, engineering blog, and 43 more developer resources.

69.4/100 exemplar ▬ flat Agent 44/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
10 APIs 14 Features 6 Use Cases
SecurityThreat IntelligenceCybersecurityIP ReputationVulnerability ManagementNetwork TelemetrySOC AutomationPublic APIs

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 69.4/100 · exemplar
Contract Quality 18.0 / 25
Developer Ergonomics 11.7 / 20
Commercial Clarity 18.4 / 20
Operational Transparency 4.8 / 13
Governance 8.3 / 12
Discoverability 8.2 / 10
Agent readiness — 44/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/greynoise: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

GreyNoise Intelligence Callback API

The Callback API from GreyNoise Intelligence — 4 operation(s) for callback.

GreyNoise Intelligence Community API

Endpoints for the community level users

GreyNoise Intelligence CVE API

Endpoints that are used for retrieving information about Common Vulnerabilities and Exposures (CVEs).

GreyNoise Intelligence GNQL API

Calls to interface with GNQL (GreyNoise Query Language).

GreyNoise Intelligence IP Lookup API

Calls to identify whether or not an IP address is noise, or get more information about a given IP address.

GreyNoise Intelligence IP Timeline API

Noise data captures internet scanning activity against GreyNoise sensors deployed globally. The IP Timeline APIs allow temporal analysis and presents the user with a view of how...

GreyNoise Intelligence Recall API

Endpoint that are used for retrieving GNQL data over time. Allows users to view hourly snapshots of IP activity for IPs that return for any GNQL query.

GreyNoise Intelligence Sessions API

Endpoints for querying, analyzing, and exporting raw network session (PCAP) data captured by GreyNoise sensors. Use the `scope` parameter to control data access (workspace or de...

GreyNoise Intelligence Tags API

Endpoints for retrieving tag information, metadata, and associated activity data.

GreyNoise Intelligence Utility API

Endpoints that are used for checking status or retrieving basic metadata

Scroll for all 10

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

GreyNoise API

POSTMAN

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

GreyNoise API

OPEN COLLECTION

Arazzo Workflows 10

Multi-step API workflows described with the Arazzo specification.

GreyNoise Bulk IP Triage

Quick-lookup a batch of IPs, then deep-context the first flagged one.

ARAZZO

GreyNoise Community Classification Router

Community-check an IP and route malicious vs benign to different lookups.

ARAZZO

GreyNoise Community Deep Dive

Check an IP against the free Community API, then escalate to full context.

ARAZZO

GreyNoise Community To Timeline

Community-check an IP, escalate noisy ones to context, then chart activity.

ARAZZO

GreyNoise CVE Exposure Scan

Look up a CVE, then aggregate and sample the IPs exploiting it.

ARAZZO

GreyNoise GNQL Investigate Top Result

Run a GNQL query, then pull full context for the first matching IP.

ARAZZO

GreyNoise GNQL Stats Then Sample

Aggregate a GNQL query, confirm volume, then sample and context an IP.

ARAZZO

GreyNoise IP Context Timeline

Pull an IP's full context, then chart its activity timeline if observed.

ARAZZO

GreyNoise IP Quick Triage

Quickly classify an IP, then pull full context only when it is worth it.

ARAZZO

GreyNoise Tag Hunt To Context

Resolve an activity tag, hunt IPs carrying it, then context the top hit.

ARAZZO

Scroll for all 10

GraphQL 1

GraphQL schemas published by this provider.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Greynoise Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 14

Notable capabilities this provider offers.

IP Lookup (Quick + Context)

Fast IP enrichment with classification, RIOT trust, ASN, geo, tags, and raw scan/web telemetry.

Multi-IP Lookup

Bulk IP enrichment up to 10,000 IPs per request.

GNQL (GreyNoise Query Language)

Lucene-style query language across the GreyNoise dataset with rich facets and time-window operators.

GNQL Stats + Recall

Aggregate statistics and hourly/daily time-series over a GNQL query window.

Sessions & PCAP

Session-level packet capture, connection graphs, time-series, and PCAP export from GreyNoise sensors.

CVE Exploitation Telemetry

Per-CVE in-the-wild exploitation evidence; bulk CVE lookup.

Callback IP Intelligence

Post-exploit / C2 callback IP enrichment and aggregate statistics.

Tag Trends

Trending, anomalous, most-active, and most-recent behavior tags over the GreyNoise dataset.

Business Service Intelligence (RIOT)

Identify benign business-operated traffic to filter false positives.

C2 Detection

Identify command-and-control infrastructure.

Vulnerability Prioritization

Prioritize CVE remediation by observed in-the-wild exploitation.

Alerts, Feeds, and Blocklists

Schedule alerts, generate query-based blocklists, and consume GreyNoise feeds.

Project Swarm (sensor program)

Deploy GreyNoise sensors on owned networks for tailored intelligence.

MCP Server for AI Agents

Expose GreyNoise enterprise capabilities to LLM agents via Model Context Protocol.

Scroll for all 14

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Greynoise Context

81 classes · 186 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

GreyNoise Intelligence API Rules

5 rules · 4 warnings 1 info

SPECTRAL

GreyNoise Intelligence API Rules

42 rules · 15 errors 24 warnings 3 info

SPECTRAL

JSON Schema 65

Standalone JSON Schema definitions for this provider's data models.

BusinessServiceIntelligence

8 properties

JSON SCHEMA

CallbackFileResponse

9 properties

JSON SCHEMA

CallbackFileSummary

5 properties

JSON SCHEMA

CallbackFilterFields

12 properties

JSON SCHEMA

CallbackIPDetailResponse

10 properties

JSON SCHEMA

CallbackIPSummary

10 properties

JSON SCHEMA

CallbackListIPsRequest

0 properties

JSON SCHEMA

CallbackListIPsResponse

4 properties

JSON SCHEMA

CallbackOverviewResponse

14 properties

JSON SCHEMA

CallbackThreatNameStat

3 properties

JSON SCHEMA

CommunityResponse

8 properties

JSON SCHEMA

CVEAdvancedResponse

6 properties

JSON SCHEMA

CVEBasicResponse

4 properties

JSON SCHEMA

CVEDetails

6 properties

JSON SCHEMA

CVEExploitationActivity

7 properties

JSON SCHEMA

CVEExploitationDetails

4 properties

JSON SCHEMA

CVEExploitationStats

3 properties

JSON SCHEMA

CVEMinimalResponse

2 properties

JSON SCHEMA

CVETimeline

4 properties

JSON SCHEMA

GNQLStats

4 properties

JSON SCHEMA

GNQLIPContextV3

3 properties

JSON SCHEMA

GNQLV3ResponseMetadata

7 properties

JSON SCHEMA

GNQLV3Response

2 properties

JSON SCHEMA

InternetScannerIntelligence

16 properties

JSON SCHEMA

IpResponseMetadataV3

3 properties

JSON SCHEMA

IPResponseV3

4 properties

JSON SCHEMA

IPResponseV3Tags

11 properties

JSON SCHEMA

IPTimelineResponse

2 properties

JSON SCHEMA

MetadataV3

24 properties

JSON SCHEMA

MultiIpRequest

1 properties

JSON SCHEMA

MultiIPResponseV3

2 properties

JSON SCHEMA

QuickBusinessServiceIntelligence

2 properties

JSON SCHEMA

QuickGNQLV3Response

2 properties

JSON SCHEMA

QuickInternetScannerIntelligence

2 properties

JSON SCHEMA

QuickIpProfile

3 properties

JSON SCHEMA

QuickMultiIPResponseV3

2 properties

JSON SCHEMA

SessionConnectionLink

3 properties

JSON SCHEMA

SessionConnectionNode

2 properties

JSON SCHEMA

SessionConnectionsResponse

4 properties

JSON SCHEMA

SessionCountItem

3 properties

JSON SCHEMA

SessionCountsResponse

3 properties

JSON SCHEMA

SessionField

6 properties

JSON SCHEMA

SessionFieldsResponse

1 properties

JSON SCHEMA

SessionPagination

4 properties

JSON SCHEMA

SessionRequestMetadata

3 properties

JSON SCHEMA

Session

12 properties

JSON SCHEMA

SessionTimeseriesItem

3 properties

JSON SCHEMA

SessionTimeseriesPoint

2 properties

JSON SCHEMA

SessionTimeseriesResponse

4 properties

JSON SCHEMA

SessionsResponse

4 properties

JSON SCHEMA

TagsMetadata

1 properties

JSON SCHEMA

TimeSeriesHASSHEntry

2 properties

JSON SCHEMA

TimeSeriesHTTPData

10 properties

JSON SCHEMA

TimeSeriesIntelligence

14 properties

JSON SCHEMA

TimeSeriesJA3Entry

2 properties

JSON SCHEMA

TimeSeriesRawData

8 properties

JSON SCHEMA

TimeSeriesRecord

2 properties

JSON SCHEMA

TimeSeriesResponse

0 properties

JSON SCHEMA

TimeSeriesScanEntry

2 properties

JSON SCHEMA

TimeSeriesSourceData

1 properties

JSON SCHEMA

TimeSeriesSSHData

2 properties

JSON SCHEMA

TimeSeriesStatsRecord

2 properties

JSON SCHEMA

TimeSeriesStatsResponse

4 properties

JSON SCHEMA

TimeSeriesTCPData

2 properties

JSON SCHEMA

TimeSeriesTLSData

2 properties

JSON SCHEMA

Scroll for all 65

JSON Structure 65

JSON Structure definitions describing this provider's data shapes.

Greynoise Callback File Response Structure

9 properties

JSON STRUCTURE

Greynoise Callback File Summary Structure

5 properties

JSON STRUCTURE

Greynoise Callback Filter Fields Structure

12 properties

JSON STRUCTURE

Greynoise Callback Ip Summary Structure

10 properties

JSON STRUCTURE

Greynoise Community Response Structure

8 properties

JSON STRUCTURE

Greynoise Cve Advanced Response Structure

6 properties

JSON STRUCTURE

Greynoise Cve Basic Response Structure

4 properties

JSON STRUCTURE

Greynoise Cve Details Structure

6 properties

JSON STRUCTURE

Greynoise Cve Exploitation Stats Structure

3 properties

JSON STRUCTURE

Greynoise Cve Minimal Response Structure

2 properties

JSON STRUCTURE

Greynoise Cve Timeline Structure

4 properties

JSON STRUCTURE

Greynoise Gnql Stats Structure

4 properties

JSON STRUCTURE

Greynoise Gnqlip Context V3 Structure

3 properties

JSON STRUCTURE

Greynoise Gnqlv3 Response Structure

2 properties

JSON STRUCTURE

Greynoise Ip Response V3 Structure

4 properties

JSON STRUCTURE

Greynoise Ip Response V3 Tags Structure

11 properties

JSON STRUCTURE

Greynoise Ip Timeline Response Structure

2 properties

JSON STRUCTURE

Greynoise Metadata V3 Structure

24 properties

JSON STRUCTURE

Greynoise Multi Ip Request Structure

1 properties

JSON STRUCTURE

Greynoise Multi Ip Response V3 Structure

2 properties

JSON STRUCTURE

Greynoise Quick Gnqlv3 Response Structure

2 properties

JSON STRUCTURE

Greynoise Quick Ip Profile Structure

3 properties

JSON STRUCTURE

Greynoise Session Count Item Structure

3 properties

JSON STRUCTURE

Greynoise Session Field Structure

6 properties

JSON STRUCTURE

Greynoise Session Pagination Structure

4 properties

JSON STRUCTURE

Greynoise Session Structure

12 properties

JSON STRUCTURE

Greynoise Sessions Response Structure

4 properties

JSON STRUCTURE

Greynoise Tags Metadata Structure

1 properties

JSON STRUCTURE

Greynoise Time Series Http Data Structure

10 properties

JSON STRUCTURE

Greynoise Time Series Ja3 Entry Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Raw Data Structure

8 properties

JSON STRUCTURE

Greynoise Time Series Record Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Response Structure

0 properties

JSON STRUCTURE

Greynoise Time Series Scan Entry Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Ssh Data Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Tcp Data Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Tls Data Structure

2 properties

JSON STRUCTURE

Scroll for all 65

Examples 64

Example request and response payloads for these APIs.

Greynoise Session Example

12 fields

EXAMPLE

Scroll for all 64

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Greynoise Authentication

apiKey · 1 scheme

SECURITY

Greynoise Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Greynoise Agentic Access

27 operations · 5 acting

27 operations · 5 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Alert triage

Drop alerts on IPs known to be benign internet noise to reduce SOC workload.

Incident response enrichment

Enrich indicators of compromise with classification, tags, and historical activity during investigations.

Threat hunting

Hunt across GreyNoise sensor telemetry for emerging campaigns or specific TTPs.

Vulnerability prioritization

Reorder remediation queues by which CVEs are actively exploited in the wild.

Perimeter defense

Generate query-based blocklists to ingest into firewalls and edge platforms.

AI-assisted SOC

Let LLM agents call GreyNoise through the MCP server during automated triage and reporting.

Integrations 22

Pre-built integrations with other platforms and tools.

Splunk

SIEM enrichment via the GreyNoise Splunk app (SA-GreyNoise).

Microsoft Sentinel

TI Feed integration documented for Azure Sentinel.

Google SecOps (Chronicle) / SecOps SOAR

SIEM + SOAR integration via the greynoise-google-secops repository.

CrowdStrike NG-SIEM

Native enrichment integration.

Cribl

GreyNoise enrichment pipeline in Cribl Stream.

Cortex XSOAR (Demisto)

SOAR playbook content for incident enrichment.

Splunk SOAR (Phantom)

SOAR integration and playbooks via greynoise-splunk-soar.

FortiSOAR

SOAR connector via connector-greynoise.

Swimlane

SOAR integration via greynoise-swimlane.

Tines

SOAR integration documented for Tines.

Anomali ThreatStream

TIP integration via greynoise-anomali.

MISP

TIP integration via misp-modules.

Recorded Future

TIP integration documented.

ThreatQ

TIP integration documented.

OpenCTI

TIP connector via the OpenCTI connectors repo.

Maltego

Analyst transforms via greynoise-maltego.

Polarity

Analyst overlay integration.

Palo Alto Networks PAN-OS

GreyNoise blocklists consumable as External Dynamic Lists (EDLs).

fail2ban

Open-source enrichment plugin (greynoise-fail2ban).

Microsoft Copilot for Security

AI/ML integration plug-in for Copilot for Security.

Model Context Protocol (MCP)

Native MCP server for LLM agent integration.

Terraform

Manage alerts and blocklists declaratively (terraform-provider-greynoise).

Scroll for all 22

Solutions 4

Packaged solutions this provider offers.

Community (Free)

Free tier for individual researchers; Community API only.

Standard

Entry-level paid tier with Enterprise + GNQL API access.

Advanced

Most-popular tier with 30-day lookback and 2-hour freshness.

Elite

Premium tier with hourly freshness, 90-day lookback, and unlimited alerts/feeds/blocklists.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 13

Pagination, idempotency, versioning, errors, and events

Scroll for all 13

Build 10

SDKs, sample code, and the tooling you integrate with

Scroll for all 10

Access & Security 3

Authentication, authorization, and security posture

Learn 4

Tutorials, courses, talks, and written guidance

Operate 6

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: greynoise
name: GreyNoise Intelligence
description: GreyNoise Intelligence collects and analyzes Internet-wide scan and attack traffic from a global network of sensors.
  Use GreyNoise to contextualize alerts, filter false positives, identify compromised devices, prioritize vulnerabilities
  by in-the-wild exploitation, and track emerging threats. The platform exposes a free Community API and a paid Enterprise
  API surface (IP Lookup, GNQL, RIOT/Business Services, Tags, CVE, Sessions, Callback, Recall, IP Timeline, Utility) plus
  an MCP server for AI workflows.
url: https://www.greynoise.io
humanURL: https://docs.greynoise.io
baseURL: https://api.greynoise.io
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://www.greynoise.io/hubfs/Greynoise%20Logo.svg
specificationVersion: '0.20'
created: '2026-05-28'
modified: '2026-05-30'
x-type: company
x-category: Security
x-source: public-apis/public-apis
x-tier: 3
x-tier-reason: bulk-registered-from-public-apis
tags:
- Security
- Threat Intelligence
- Cybersecurity
- IP Reputation
- Vulnerability Management
- Network Telemetry
- SOC Automation
- Public APIs
apis:
- aid: greynoise:greynoise-callback-api
  name: GreyNoise Intelligence Callback API
  description: The Callback API from GreyNoise Intelligence — 4 operation(s) for callback.
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Callback
  properties:
  - type: OpenAPI
    url: openapi/greynoise-callback-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-community-api
  name: GreyNoise Intelligence Community API
  description: Endpoints for the community level users
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Community
  properties:
  - type: OpenAPI
    url: openapi/greynoise-community-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-cve-api
  name: GreyNoise Intelligence CVE API
  description: Endpoints that are used for retrieving information about Common Vulnerabilities and Exposures (CVEs).
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - CVE
  properties:
  - type: OpenAPI
    url: openapi/greynoise-cve-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-gnql-api
  name: GreyNoise Intelligence GNQL API
  description: Calls to interface with GNQL (GreyNoise Query Language).
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - GNQL
  properties:
  - type: OpenAPI
    url: openapi/greynoise-gnql-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-ip-lookup-api
  name: GreyNoise Intelligence IP Lookup API
  description: Calls to identify whether or not an IP address is noise, or get more information about a given IP address.
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - IP Lookup
  properties:
  - type: OpenAPI
    url: openapi/greynoise-ip-lookup-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-ip-timeline-api
  name: GreyNoise Intelligence IP Timeline API
  description: 'Noise data captures internet scanning activity against GreyNoise sensors

    deployed globally.

    The IP Timeline APIs allow temporal analysis and presents the user with a

    view of how this data has changed over the time.'
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - IP Timeline
  properties:
  - type: OpenAPI
    url: openapi/greynoise-ip-timeline-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-recall-api
  name: GreyNoise Intelligence Recall API
  description: 'Endpoint that are used for retrieving GNQL data over time. Allows users

    to view hourly snapshots of IP activity for IPs that return for any

    GNQL query.'
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Recall
  properties:
  - type: OpenAPI
    url: openapi/greynoise-recall-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-sessions-api
  name: GreyNoise Intelligence Sessions API
  description: 'Endpoints for querying, analyzing, and exporting raw network session (PCAP)

    data captured by GreyNoise sensors. Use the `scope` parameter to control

    data access (workspace or demo). Required entitlements vary by scope.'
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Sessions
  properties:
  - type: OpenAPI
    url: openapi/greynoise-sessions-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-tags-api
  name: GreyNoise Intelligence Tags API
  description: Endpoints for retrieving tag information, metadata, and associated activity data.
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Tags
  properties:
  - type: OpenAPI
    url: openapi/greynoise-tags-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
- aid: greynoise:greynoise-utility-api
  name: GreyNoise Intelligence Utility API
  description: Endpoints that are used for checking status or retrieving basic metadata
  humanURL: https://docs.greynoise.io
  baseURL: https://api.greynoise.io
  tags:
  - Utility
  properties:
  - type: OpenAPI
    url: openapi/greynoise-utility-api-openapi.yml
  - type: Documentation
    url: https://docs.greynoise.io
  - type: APIReference
    url: https://docs.greynoise.io/reference/getcommunityip
  - type: Authentication
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/getting-started
  - type: GettingStarted
    url: https://docs.greynoise.io/docs/using-the-greynoise-api
  - type: GraphQL
    url: graphql/greynoise-graphql.md
common:
- type: AgenticAccess
  url: agentic-access/greynoise-agentic-access.yml
- type: DomainSecurity
  url: security/greynoise-domain-security.yml
- type: Authentication
  url: authentication/greynoise-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/greynoise-intelligence/overview
- type: Arazzo
  url: arazzo/greynoise-bulk-ip-triage-workflow.yml
  name: GreyNoise Bulk IP Triage
- type: Arazzo
  url: arazzo/greynoise-community-classification-router-workflow.yml
  name: GreyNoise Community Classification Router
- type: Arazzo
  url: arazzo/greynoise-community-deep-dive-workflow.yml
  name: GreyNoise Community Deep Dive
- type: Arazzo
  url: arazzo/greynoise-community-to-timeline-workflow.yml
  name: GreyNoise Community To Timeline
- type: Arazzo
  url: arazzo/greynoise-cve-exposure-scan-workflow.yml
  name: GreyNoise CVE Exposure Scan
- type: Arazzo
  url: arazzo/greynoise-gnql-investigate-top-result-workflow.yml
  name: GreyNoise GNQL Investigate Top Result
- type: Arazzo
  url: arazzo/greynoise-gnql-stats-then-sample-workflow.yml
  name: GreyNoise GNQL Stats Then Sample
- type: Arazzo
  url: arazzo/greynoise-ip-context-timeline-workflow.yml
  name: GreyNoise IP Context Timeline
- type: Arazzo
  url: arazzo/greynoise-ip-quick-triage-workflow.yml
  name: GreyNoise IP Quick Triage
- type: Arazzo
  url: arazzo/greynoise-tag-hunt-to-context-workflow.yml
  name: GreyNoise Tag Hunt To Context
- type: Website
  url: https://www.greynoise.io
- type: DeveloperPortal
  url: https://docs.greynoise.io
- type: Console
  url: https://viz.greynoise.io
- type: Signup
  url: https://viz.greynoise.io/signup
- type: Login
  url: https://viz.greynoise.io/login
- type: Pricing
  url: https://www.greynoise.io/pricing
- type: Plans
  url: plans/greynoise-plans-pricing.yml
- type: RateLimits
  url: rate-limits/greynoise-rate-limits.yml
- type: Support
  url: https://support.greynoise.io
- type: StatusPage
  url: https://status.greynoise.io
- type: Contact
  url: https://www.greynoise.io/contact
- type: FAQ
  url: https://docs.greynoise.io/docs/vulnerability-prioritization-faq
- type: Glossary
  url: https://docs.greynoise.io/docs/swarm-glossary
- type: TermsOfService
  url: https://www.greynoise.io/terms
- type: PrivacyPolicy
  url: https://www.greynoise.io/privacy
- type: TrustCenter
  url: https://trust.greynoise.io
- type: Blog
  url: https://www.greynoise.io/blog
- type: ChangeLog
  url: https://docs.greynoise.io/changelog
- type: Academy
  url: https://www.greynoise.io/university
- type: Training
  url: https://docs.greynoise.io/docs/greynoise-university-series-list
- type: Tutorials
  url: https://docs.greynoise.io/docs/api-and-cli-training-modules
- type: Webinars
  url: https://docs.greynoise.io/docs/community-resources
- type: GitHubOrganization
  url: https://github.com/GreyNoise-Intelligence
- type: GitHubRepository
  url: https://github.com/GreyNoise-Intelligence/api.greynoise.io
- type: LinkedIn
  url: https://www.linkedin.com/company/greynoise-intelligence
- type: X
  url: https://x.com/GreyNoiseIO
- type: SDKs
  name: pygreynoise (Python SDK + CLI)
  url: https://github.com/GreyNoise-Intelligence/pygreynoise
- type: SDKs
  name: GreyNoisePS (PowerShell module)
  url: https://github.com/GreyNoise-Intelligence/GreyNoisePS
- type: SDKs
  name: greynoiselabs (Python client for the Labs GraphQL API)
  url: https://github.com/GreyNoise-Intelligence/greynoiselabs
- type: CLI
  name: greynoise (bundled with pygreynoise)
  url: https://github.com/GreyNoise-Intelligence/pygreynoise
- type: SpectralRules
  url: rules/greynoise-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/greynoise-vocabulary.yml
- type: JSONLD
  url: json-ld/greynoise-context.jsonld
- type: Tools
  name: GreyNoise MCP Server
  description: Official Model Context Protocol server for the GreyNoise Enterprise API. Exposes IP reputation, RIOT/business-service
    checks, tag and CVE intelligence, GNQL stats, and more as MCP tools.
  url: https://github.com/GreyNoise-Intelligence/greynoise-mcp-server
- type: Tools
  name: Terraform Provider for GreyNoise
  description: Manage GreyNoise alerts and blocklists via Terraform.
  url: https://github.com/GreyNoise-Intelligence/terraform-provider-greynoise
- type: Tools
  name: GreyNoise Splunk App (SA-GreyNoise)
  description: Splunk integration enriching events with GreyNoise data.
  url: https://github.com/GreyNoise-Intelligence/SA-GreyNoise
- type: Features
  data:
  - name: IP Lookup (Quick + Context)
    description: Fast IP enrichment with classification, RIOT trust, ASN, geo, tags, and raw scan/web telemetry.
  - name: Multi-IP Lookup
    description: Bulk IP enrichment up to 10,000 IPs per request.
  - name: GNQL (GreyNoise Query Language)
    description: Lucene-style query language across the GreyNoise dataset with rich facets and time-window operators.
  - name: GNQL Stats + Recall
    description: Aggregate statistics and hourly/daily time-series over a GNQL query window.
  - name: Sessions & PCAP
    description: Session-level packet capture, connection graphs, time-series, and PCAP export from GreyNoise sensors.
  - name: CVE Exploitation Telemetry
    description: Per-CVE in-the-wild exploitation evidence; bulk CVE lookup.
  - name: Callback IP Intelligence
    description: Post-exploit / C2 callback IP enrichment and aggregate statistics.
  - name: Tag Trends
    description: Trending, anomalous, most-active, and most-recent behavior tags over the GreyNoise dataset.
  - name: Business Service Intelligence (RIOT)
    description: Identify benign business-operated traffic to filter false positives.
  - name: C2 Detection
    description: Identify command-and-control infrastructure.
  - name: Vulnerability Prioritization
    description: Prioritize CVE remediation by observed in-the-wild exploitation.
  - name: Alerts, Feeds, and Blocklists
    description: Schedule alerts, generate query-based blocklists, and consume GreyNoise feeds.
  - name: Project Swarm (sensor program)
    description: Deploy GreyNoise sensors on owned networks for tailored intelligence.
  - name: MCP Server for AI Agents
    description: Expose GreyNoise enterprise capabilities to LLM agents via Model Context Protocol.
- type: UseCases
  data:
  - name: Alert triage
    description: Drop alerts on IPs known to be benign internet noise to reduce SOC workload.
  - name: Incident response enrichment
    description: Enrich indicators of compromise with classification, tags, and historical activity during investigations.
  - name: Threat hunting
    description: Hunt across GreyNoise sensor telemetry for emerging campaigns or specific TTPs.
  - name: Vulnerability prioritization
    description: Reorder remediation queues by which CVEs are actively exploited in the wild.
  - name: Perimeter defense
    description: Generate query-based blocklists to ingest into firewalls and edge platforms.
  - name: AI-assisted SOC
    description: Let LLM agents call GreyNoise through the MCP server during automated triage and reporting.
- type: Integrations
  data:
  - name: Splunk
    description: SIEM enrichment via the GreyNoise Splunk app (SA-GreyNoise).
  - name: Microsoft Sentinel
    description: TI Feed integration documented for Azure Sentinel.
  - name: Google SecOps (Chronicle) / SecOps SOAR
    description: SIEM + SOAR integration via the greynoise-google-secops repository.
  - name: CrowdStrike NG-SIEM
    description: Native enrichment integration.
  - name: Cribl
    description: GreyNoise enrichment pipeline in Cribl Stream.
  - name: Cortex XSOAR (Demisto)
    description: SOAR playbook content for incident enrichment.
  - name: Splunk SOAR (Phantom)
    description: SOAR integration and playbooks via greynoise-splunk-soar.
  - name: FortiSOAR
    description: SOAR connector via connector-greynoise.
  - name: Swimlane
    description: SOAR integration via greynoise-swimlane.
  - name: Tines
    description: SOAR integration documented for Tines.
  - name: Anomali ThreatStream
    description: TIP integration via greynoise-anomali.
  - name: MISP
    description: TIP integration via misp-modules.
  - name: Recorded Future
    description: TIP integration documented.
  - name: ThreatQ
    description: TIP integration documented.
  - name: OpenCTI
    description: TIP connector via the OpenCTI connectors repo.
  - name: Maltego
    description: Analyst transforms via greynoise-maltego.
  - name: Polarity
    description: Analyst overlay integration.
  - name: Palo Alto Networks PAN-OS
    description: GreyNoise blocklists consumable as External Dynamic Lists (EDLs).
  - name: fail2ban
    description: Open-source enrichment plugin (greynoise-fail2ban).
  - name: Microsoft Copilot for Security
    description: AI/ML integration plug-in for Copilot for Security.
  - name: Model Context Protocol (MCP)
    description: Native MCP server for LLM agent integration.
  - name: Terraform
    description: Manage alerts and blocklists declaratively (terraform-provider-greynoise).
- type: Solutions
  data:
  - name: Community (Free)
    description: Free tier for individual researchers; Community API only.
  - name: Standard
    description: Entry-level paid tier with Enterprise + GNQL API access.
  - name: Advanced
    description: Most-popular tier with 30-day lookback and 2-hour freshness.
  - name: Elite
    description: Premium tier with hourly freshness, 90-day lookback, and unlimited alerts/feeds/blocklists.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com