GreyNoise
GreyNoise is a cybersecurity platform that analyzes internet noise to help distinguish between benign and malicious scanning activities.
GreyNoise is a cybersecurity platform that provides context on IP addresses by distinguishing between benign and malicious internet noise. The GreyNoise connector for Swimlane Turbine enables users to retrieve detailed IP context, perform quick checks, and conduct similarity lookups, enhancing threat intelligence and response capabilities. By integrating GreyNoise with Swimlane Turbine, security teams can automate the enrichment of IP data, streamline threat detection, and improve incident response efficiency.
This is a connector for GreyNoise. GreyNoise captures data on IPs that scan the internet and saturate security tools with internet noise.
Prerequisites
Before you can use the GreyNoise connector for Turbine, you'll need access to the GreyNoise API. This requires the following:
- an API key authentication using the following parameters:
- URL: The endpoint URL for accessing the GreyNoise API.
- API Key: A unique key provided by GreyNoise to authenticate API requests.
Capabilities
This connector provides the following capabilities:
- Community API
- Get IP Lookup Context
- Get IP Quick Check
- Get IP Similarity Lookup
Additional Documentation
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
key | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Community API
Retrieve IP context data for community users by querying the GreyNoise dataset with a specified IP address.
Endpoint
- URL: /v3/community/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | The IP address to query. |
Input Example
{"path_parameters":{"ip":"8.8.8.8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ip | string | Output field: ip |
noise | boolean | Output field: noise |
riot | boolean | Output field: riot |
classification | string | Output field: classification |
name | string | Name of the resource |
link | string | Output field: link |
last_seen | string | Output field: last_seen |
message | string | Response message |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 21 Nov 2024 06:53:04 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"234","Connection":"keep-alive","X-Ratelimit-Limit":"25","X-Ratelimit-Remaining":"22","X-Ratelimit-Reset":"1732776563"},"reason":"OK","json_body":{"ip":"8.8.8.8","noise":false,"riot":true,"classification":"benign","name":"Google Public DNS","link":"https://viz.greynoise.io/ip/8.8.8.8","last_seen":"2024-11-21","message":"Success"}}
Get IP Lookup Context
Retrieve detailed metadata, actor associations, activity tags, and raw scan data for a specified IP address using GreyNoise.
Endpoint
- URL: /v3/ip/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Lookup Context action |
Input Example
{"path_parameters":{"ip":"71.6.135.131"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ip | string | Output field: ip |
seen | boolean | Output field: seen |
classification | string | Output field: classification |
first_seen | string | Output field: first_seen |
last_seen | string | Output field: last_seen |
actor | string | Output field: actor |
tags | array | Output field: tags |
spoofable | boolean | Output field: spoofable |
cve | array | Output field: cve |
vpn | boolean | Output field: vpn |
vpn_service | string | Output field: vpn_service |
metadata | object | Response data |
metadata.country | string | Response data |
metadata.country_code | string | Response data |
metadata.city | string | Response data |
metadata.region | string | Response data |
metadata.organization | string | Response data |
metadata.rdns | string | Response data |
metadata.asn | string | Response data |
metadata.tor | boolean | Response data |
metadata.category | string | Response data |
metadata.os | string | Response data |
metadata.destination_countries | array | Response data |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 23 Aug 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ip":"71.6.135.131","seen":true,"classification":"benign","first_seen":"2018-01-28","last_seen":"2018-2-28","actor":"Shodan.io","tags":["Mirai","Telnet Worm"],"spoofable":true,"cve":["CVE-2020-1234","CVE-2021-2345"],"vpn":true,"vpn_service":"IPVANISH_VPN","metadata":{"country":"United States","country_code":"US","city":"Seattle","regio...
Get IP Quick Check
Perform a quick check on an IP address in GreyNoise to determine if it's classified as 'Internet background noise' or involved in scanning or attacks. Requires the IP address as a path parameter.
Endpoint
- URL: /v3/ip/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.quick | boolean | Required | Whether to perform a quick check. |
path_parameters.ip | string | Required | Parameters for the Get IP Quick Check action |
Input Example
{"parameters":{"quick":true},"path_parameters":{"ip":"71.6.135.131"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
code | string | Output field: code |
ip | string | Output field: ip |
noise | boolean | Output field: noise |
riot | boolean | Output field: riot |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 23 Aug 2023 20:37:23 GMT"},"reason":"OK","json_body":{"code":"0x01","ip":"71.6.135.131","noise":true,"riot":false}}
Get IP Similarity Lookup
Perform a similarity lookup for an IP address in GreyNoise. Requires 'ip' as a path parameter.
Endpoint
- URL: /v3/similarity/ips/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Similarity Lookup action |
parameters.limit | number | Optional | Parameters for the Get IP Similarity Lookup action |
parameters.minimum_score | number | Optional | Parameters for the Get IP Similarity Lookup action |
Input Example
{"parameters":{"limit":50,"minimum_score":0.85},"path_parameters":{"ip":"71.6.135.131"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
ip | object | Output field: ip |
ip.ip | string | Output field: ip.ip |
ip.actor | string | Output field: ip.actor |
ip.classification | string | Output field: ip.classification |
ip.first_seen | string | Output field: ip.first_seen |
ip.last_seen | string | Output field: ip.last_seen |
ip.asn | string | Output field: ip.asn |
ip.city | string | Output field: ip.city |
ip.country | string | Output field: ip.country |
ip.country_code | string | Output field: ip.country_code |
ip.organization | string | Output field: ip.organization |
similar_ips | array | Output field: similar_ips |
similar_ips.ip | string | Output field: similar_ips.ip |
similar_ips.actor | string | Output field: similar_ips.actor |
similar_ips.classification | string | Output field: similar_ips.classification |
similar_ips.first_seen | string | Output field: similar_ips.first_seen |
similar_ips.last_seen | string | Output field: similar_ips.last_seen |
similar_ips.asn | string | Output field: similar_ips.asn |
similar_ips.city | string | Output field: similar_ips.city |
similar_ips.country | string | Output field: similar_ips.country |
similar_ips.country_code | string | Output field: similar_ips.country_code |
similar_ips.organization | string | Output field: similar_ips.organization |
similar_ips.score | number | Score value |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 23 Aug 2023 20:37:23 GMT"},"reason":"OK","json_body":{"ip":{"ip":"71.6.135.131","actor":"Shodan.io","classification":"benign","first_seen":"2018-01-28","last_seen":"2018-2-28","asn":"AS521","city":"Seattle","country":"United States","country_code":"US","organization":"DigitalOcean, LLC"},"similar_ips":[{}]}}
Response Headers
Header | Description | Example |
|---|---|---|
Connection | HTTP response header: Connection | keep-alive |
Content-Length | The length of the response body in bytes | 234 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Wed, 23 Aug 2023 20:37:23 GMT |
X-Ratelimit-Limit | The number of requests allowed in the current rate limit window | 25 |
X-Ratelimit-Remaining | The number of requests remaining in the current rate limit window | 22 |
X-Ratelimit-Reset | The time at which the current rate limit window resets | 1732776563 |