# GreyNoise Intelligence

**Canonical:** https://apis.io/providers/greynoise/  
**Website:** https://www.greynoise.io  
**APIs profiled:** 10

GreyNoise Intelligence collects and analyzes Internet-wide scan and attack traffic from a global network of sensors. Use GreyNoise to contextualize alerts, filter false positives, identify compromised devices, prioritize vulnerabilities by in-the-wild exploitation, and track emerging threats. The platform exposes a free Community API and a paid Enterprise API surface (IP Lookup, GNQL, RIOT/Business Services, Tags, CVE, Sessions, Callback, Recall, IP Timeline, Utility) plus an MCP server for AI workflows.

## Kin Score — 58.4 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 58.4).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 69.1 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 51.2 |
| Commercial Clarity | 81.6 |
| Access Clarity | 81.6 |

## Agent readiness — 41.9 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (10)

- **GreyNoise Intelligence Callback API** — The Callback API from GreyNoise Intelligence — 4 operation(s) for callback.
- **GreyNoise Intelligence Community API** — Endpoints for the community level users
- **GreyNoise Intelligence CVE API** — Endpoints that are used for retrieving information about Common Vulnerabilities and Exposures (CVEs).
- **GreyNoise Intelligence GNQL API** — Calls to interface with GNQL (GreyNoise Query Language).
- **GreyNoise Intelligence IP Lookup API** — Calls to identify whether or not an IP address is noise, or get more information about a given IP address.
- **GreyNoise Intelligence IP Timeline API** — Noise data captures internet scanning activity against GreyNoise sensors deployed globally. The IP Timeline APIs allow temporal analysis and presents the user with a view of how...
- **GreyNoise Intelligence Recall API** — Endpoint that are used for retrieving GNQL data over time. Allows users to view hourly snapshots of IP activity for IPs that return for any GNQL query.
- **GreyNoise Intelligence Sessions API** — Endpoints for querying, analyzing, and exporting raw network session (PCAP) data captured by GreyNoise sensors. Use the `scope` parameter to control data access (workspace or de...
- **GreyNoise Intelligence Tags API** — Endpoints for retrieving tag information, metadata, and associated activity data.
- **GreyNoise Intelligence Utility API** — Endpoints that are used for checking status or retrieving basic metadata

## Agentic access (1)

- **Greynoise Agentic Access** — 27 operations · 5 acting

## Security (2)

- **Greynoise Authentication** — apiKey · 1 scheme
- **Greynoise Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Greynoise Plans Pricing**

## Use cases (6)

- **Alert triage** — Drop alerts on IPs known to be benign internet noise to reduce SOC workload.
- **Incident response enrichment** — Enrich indicators of compromise with classification, tags, and historical activity during investigations.
- **Threat hunting** — Hunt across GreyNoise sensor telemetry for emerging campaigns or specific TTPs.
- **Vulnerability prioritization** — Reorder remediation queues by which CVEs are actively exploited in the wild.
- **Perimeter defense** — Generate query-based blocklists to ingest into firewalls and edge platforms.
- **AI-assisted SOC** — Let LLM agents call GreyNoise through the MCP server during automated triage and reporting.

## Tags

Security, Threat Intelligence, Cybersecurity, IP Reputation, Vulnerability Management, Network Telemetry, SOC Automation, Public APIs

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/greynoise/). Scores are computed from the provider's own public artifacts under a published rubric.
