Greynoise api
Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.
npx -y skills add Liberty91LTD/cti-skills --skill greynoise-apiAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
GreyNoise API reference. Internet scanner/noise classification for IPs.
SKILL.md
2.1 KB, as published. Nobody here has run it
GreyNoise API
Base URL
- Community:
https://api.greynoise.io/v3/community - Enterprise:
https://api.greynoise.io/v3
Authentication
Header: key: $GREYNOISE_API_KEY
Rate Limits
- Community (free): 50 requests/day
- Enterprise: Based on plan
Key Endpoints
Community IP Lookup (Free)
curl -s "https://api.greynoise.io/v3/community/{ip}" \
-H "key: $GREYNOISE_API_KEY"
Response fields:
noise— true if IP is a known internet scannerriot— true if IP belongs to a known benign service (CDN, DNS, etc.)classification— benign|malicious|unknownname— actor name if identifiedlast_seen— last observation datemessage— human-readable summary
Enterprise Context (Paid)
curl -s "https://api.greynoise.io/v3/noise/context/{ip}" \
-H "key: $GREYNOISE_API_KEY"
Additional fields: tags, cve, os, ports, raw_data
Classification Meaning
| Classification | Meaning | Action |
|---|---|---|
benign + noise:true | Known benign scanner (Shodan, Censys, etc.) | Likely false positive — deprioritise |
malicious + noise:true | Known malicious scanner | Real threat, but opportunistic, not targeted |
unknown + noise:true | Unclassified scanner | Investigate further |
noise:false + riot:false | Not a known scanner | May be targeted — investigate |
riot:true | Known benign service | Definitely deprioritise |
CTI Value
GreyNoise answers: "Is this IP scanning the whole internet, or is it specifically targeting us?"
- If
noise:true→ opportunistic, not targeted - If
noise:false→ potentially targeted, higher priority
Response Summary Format
ip: <IP>
noise: <true/false>
riot: <true/false>
classification: benign|malicious|unknown
name: <actor name or "unknown">
last_seen: <date>
message: <summary>
verdict: benign-scanner|malicious-scanner|not-scanner|benign-service