How do I enrich IPs with GreyNoise Intelligence?

Modified on Tue, 24 Aug 2021 at 08:14 AM

1. Click the column menu and select Enrich. Note: the column must contain IP addresses only.

GreyNoise Threat Intelligence

2. Select GreyNoise from the list of enrichments, and enter your GreyNoise Enterprise API key, and click Enrich Data.

Threat Intel GreyNoise

3. The GreyNoise response will appear in the column immediately to the right of the IP address column selected in step 1. 

Large datasets may take several minutes to enrich depending on the number of rows and GreyNoise response time. You can continue working in Gigasheet while the enrichment is running.

What is GreyNoise?

GreyNoise collects and analyzes Internet-wide scan and attack traffic. Using the GreyNoise Enterprise API, you can contextualize IPs to identify false positives, compromised devices, and track emerging threats.

Indicators in GreyNoise are likely associated with opportunistic internet scanning or common business services, not targeted threats. GreyNoise helps identify IPs not worth additional attention. 

The Community API provides community users with a free tool to query IPs in the GreyNoise dataset and retrieve a subset of the full IP context data returned by the IP Lookup API.

The GreyNoise Community API provides users with the basic insight of an IP, using a subset of the GreyNoise dataset. It is available for a free trial to users without registration, and with a limited number of lookups per day.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select atleast one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article