Security — entry 014 of 30

GreyNoise

Verified Jul 2026

GreyNoise fingerprints the constant background noise of internet-wide scanning, tagging IPs as mass scanners or known-benign services so analysts can filter that traffic out of real alerts. The Community API answers a quick "has this IP been seen scanning the internet" lookup for free, while the full v3 API adds classification tags, actor context, and bulk GNQL search for SIEM and SOC workflows. Community lookups need no account but are capped at 10 IP checks per day; higher volume and the broader dataset require a paid API key.

threat-intelip-reputationnoise-filteringsieminternet-scanning
AuthenticationAPI KeySign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSDisabledBrowser calls need a server-side proxy.
PricingFreemiumA usable free tier exists, with paid plans for more volume.
FormatsJSONResponses can be requested as JSON.

GreatAPIs Score

Score61out of 100
Authentication15/25API key required
Pricing17/20Freemium tier available
Docs0/20No docs or spec available
Formats9/15Single response format
Freshness20/20Verified within 6 months

Embed this badge

Scored 61 on greatapis.com
<a href="https://greatapis.com/api/greynoise/"><img src="https://greatapis.com/badge/greynoise.svg" alt="Scored 61 on greatapis.com"></a>

Auth quickstart

  1. Sign up with the provider to get an API key.
  2. Send it on every request as a headerAuthorization: <key>
  3. The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored

Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.