Enriching Data with GreyNoise

The GreyNoise enrichment data is displayed on the GreyNoise tab of the Enrichments section on observable details pages for IP address observables. The GreyNoise enrichment allows you to reduce observables created by mass-internet scanning and create more time to investigate targeted attacks. It provides context into IP behavior: intent, tags, first seen, last seen, geo-data, ports, OS, and JA3. Advanced features showing a timeline and similarity-based information are available for users with those subscription features. The GreyNoise enrichment also supports Community API by entering `community` in the API Type field.

View documentation on the GreyNoise enrichment for Anomali

Before activating the GreyNoise enrichment, obtain your GreyNoise API Key and API Type from your GreyNoise account.

To activate the GreyNoise enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.

  2. Locate the GreyNoise enrichment.

  3. Click Get Access on the GreyNoise tile.
  4. Click I have credentials on the wizard page that opens.
  5. On the next wizard page, click Credentials and enter your GreyNoise API Key and API Type (Enterprise or Community) in the corresponding fields.
  6. Click Activate.

The GreyNoise enrichment is now active.