Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
GreyNoise Intelligence website screenshot

GreyNoise Intelligence

GreyNoise Intelligence collects and analyzes Internet-wide scan and attack traffic from a global network of sensors. Use GreyNoise to contextualize alerts, filter false positives, identify compromised devices, prioritize vulnerabilities by in-the-wild exploitation, and track emerging threats. The platform exposes a free Community API and a paid Enterprise API surface (IP Lookup, GNQL, RIOT/Business Services, Tags, CVE, Sessions, Callback, Recall, IP Timeline, Utility) plus an MCP server for AI workflows.

agent ready

Reference-quality API operations across every facet — a rich contract, published governance, transparent operations, and machine-readable commercial terms.

Kin Score

API Evangelist profiles GreyNoise Intelligence the way a machine reads it — 272 machine-readable artifacts across 10 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — GreyNoise Intelligence scores 73.1/100 (exemplar), with a separate agent-readiness read of 48/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 73.1/100 · exemplar
Contract Quality 17.7 / 25
Developer Ergonomics 11.7 / 20
Commercial Clarity 18.4 / 20
Operational Transparency 4.8 / 13
Governance 10.4 / 12
Discoverability 10.0 / 10
Agent readiness — 48/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile GreyNoise Intelligence

Each block below is one kind of artifact we hold for GreyNoise Intelligence. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 10

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

GreyNoise Intelligence Callback API

The Callback API from GreyNoise Intelligence — 4 operation(s) for callback.

GreyNoise Intelligence Community API

Endpoints for the community level users

GreyNoise Intelligence CVE API

Endpoints that are used for retrieving information about Common Vulnerabilities and Exposures (CVEs).

GreyNoise Intelligence GNQL API

Calls to interface with GNQL (GreyNoise Query Language).

GreyNoise Intelligence IP Lookup API

Calls to identify whether or not an IP address is noise, or get more information about a given IP address.

GreyNoise Intelligence IP Timeline API

Noise data captures internet scanning activity against GreyNoise sensors deployed globally. The IP Timeline APIs allow temporal analysis and presents the user with a view of how...

GreyNoise Intelligence Recall API

Endpoint that are used for retrieving GNQL data over time. Allows users to view hourly snapshots of IP activity for IPs that return for any GNQL query.

GreyNoise Intelligence Sessions API

Endpoints for querying, analyzing, and exporting raw network session (PCAP) data captured by GreyNoise sensors. Use the `scope` parameter to control data access (workspace or de...

GreyNoise Intelligence Tags API

Endpoints for retrieving tag information, metadata, and associated activity data.

GreyNoise Intelligence Utility API

Endpoints that are used for checking status or retrieving basic metadata

Scroll within the panel for all 10 ·

Postman Collections 1

A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.

Ready-to-run Postman collections for exercising this provider's APIs.

GreyNoise API

POSTMAN

Open Collections 1

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

GreyNoise API

OPEN COLLECTION

Arazzo Workflows 10

Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.

Multi-step API workflows described with the Arazzo specification.

GreyNoise Bulk IP Triage

Quick-lookup a batch of IPs, then deep-context the first flagged one.

ARAZZO

GreyNoise Community Classification Router

Community-check an IP and route malicious vs benign to different lookups.

ARAZZO

GreyNoise Community Deep Dive

Check an IP against the free Community API, then escalate to full context.

ARAZZO

GreyNoise Community To Timeline

Community-check an IP, escalate noisy ones to context, then chart activity.

ARAZZO

GreyNoise CVE Exposure Scan

Look up a CVE, then aggregate and sample the IPs exploiting it.

ARAZZO

GreyNoise GNQL Investigate Top Result

Run a GNQL query, then pull full context for the first matching IP.

ARAZZO

GreyNoise GNQL Stats Then Sample

Aggregate a GNQL query, confirm volume, then sample and context an IP.

ARAZZO

GreyNoise IP Context Timeline

Pull an IP's full context, then chart its activity timeline if observed.

ARAZZO

GreyNoise IP Quick Triage

Quickly classify an IP, then pull full context only when it is worth it.

ARAZZO

GreyNoise Tag Hunt To Context

Resolve an activity tag, hunt IPs carrying it, then context the top hit.

ARAZZO

Scroll within the panel for all 10 ·

GraphQL 1

Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.

GraphQL schemas published by this provider.

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Greynoise Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 14

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

IP Lookup (Quick + Context)

Fast IP enrichment with classification, RIOT trust, ASN, geo, tags, and raw scan/web telemetry.

Multi-IP Lookup

Bulk IP enrichment up to 10,000 IPs per request.

GNQL (GreyNoise Query Language)

Lucene-style query language across the GreyNoise dataset with rich facets and time-window operators.

GNQL Stats + Recall

Aggregate statistics and hourly/daily time-series over a GNQL query window.

Sessions & PCAP

Session-level packet capture, connection graphs, time-series, and PCAP export from GreyNoise sensors.

CVE Exploitation Telemetry

Per-CVE in-the-wild exploitation evidence; bulk CVE lookup.

Callback IP Intelligence

Post-exploit / C2 callback IP enrichment and aggregate statistics.

Tag Trends

Trending, anomalous, most-active, and most-recent behavior tags over the GreyNoise dataset.

Business Service Intelligence (RIOT)

Identify benign business-operated traffic to filter false positives.

C2 Detection

Identify command-and-control infrastructure.

Vulnerability Prioritization

Prioritize CVE remediation by observed in-the-wild exploitation.

Alerts, Feeds, and Blocklists

Schedule alerts, generate query-based blocklists, and consume GreyNoise feeds.

Project Swarm (sensor program)

Deploy GreyNoise sensors on owned networks for tailored intelligence.

MCP Server for AI Agents

Expose GreyNoise enterprise capabilities to LLM agents via Model Context Protocol.

Scroll within the panel for all 14 ·

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Greynoise Context

81 classes · 186 properties

JSON-LD

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

GreyNoise Intelligence API Rules

5 rules · 4 warnings

SPECTRAL

GreyNoise Intelligence API Rules

42 rules · 15 errors · 24 warnings

SPECTRAL

JSON Schema 65

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

BusinessServiceIntelligence

8 properties

JSON SCHEMA

CallbackFileResponse

9 properties

JSON SCHEMA

CallbackFileSummary

5 properties

JSON SCHEMA

CallbackFilterFields

12 properties

JSON SCHEMA

CallbackIPDetailResponse

10 properties

JSON SCHEMA

CallbackIPSummary

10 properties

JSON SCHEMA

CallbackListIPsRequest

0 properties

JSON SCHEMA

CallbackListIPsResponse

4 properties

JSON SCHEMA

CallbackOverviewResponse

14 properties

JSON SCHEMA

CallbackThreatNameStat

3 properties

JSON SCHEMA

CommunityResponse

8 properties

JSON SCHEMA

CVEAdvancedResponse

6 properties

JSON SCHEMA

CVEBasicResponse

4 properties

JSON SCHEMA

CVEDetails

6 properties

JSON SCHEMA

CVEExploitationActivity

7 properties

JSON SCHEMA

CVEExploitationDetails

4 properties

JSON SCHEMA

CVEExploitationStats

3 properties

JSON SCHEMA

CVEMinimalResponse

2 properties

JSON SCHEMA

CVETimeline

4 properties

JSON SCHEMA

GNQLStats

4 properties

JSON SCHEMA

GNQLIPContextV3

3 properties

JSON SCHEMA

GNQLV3ResponseMetadata

7 properties

JSON SCHEMA

GNQLV3Response

2 properties

JSON SCHEMA

InternetScannerIntelligence

16 properties

JSON SCHEMA

IpResponseMetadataV3

3 properties

JSON SCHEMA

IPResponseV3

4 properties

JSON SCHEMA

IPResponseV3Tags

11 properties

JSON SCHEMA

IPTimelineResponse

2 properties

JSON SCHEMA

MetadataV3

24 properties

JSON SCHEMA

MultiIpRequest

1 properties

JSON SCHEMA

MultiIPResponseV3

2 properties

JSON SCHEMA

QuickBusinessServiceIntelligence

2 properties

JSON SCHEMA

QuickGNQLV3Response

2 properties

JSON SCHEMA

QuickInternetScannerIntelligence

2 properties

JSON SCHEMA

QuickIpProfile

3 properties

JSON SCHEMA

QuickMultiIPResponseV3

2 properties

JSON SCHEMA

SessionConnectionLink

3 properties

JSON SCHEMA

SessionConnectionNode

2 properties

JSON SCHEMA

SessionConnectionsResponse

4 properties

JSON SCHEMA

SessionCountItem

3 properties

JSON SCHEMA

SessionCountsResponse

3 properties

JSON SCHEMA

SessionField

6 properties

JSON SCHEMA

SessionFieldsResponse

1 properties

JSON SCHEMA

SessionPagination

4 properties

JSON SCHEMA

SessionRequestMetadata

3 properties

JSON SCHEMA

Session

12 properties

JSON SCHEMA

SessionTimeseriesItem

3 properties

JSON SCHEMA

SessionTimeseriesPoint

2 properties

JSON SCHEMA

SessionTimeseriesResponse

4 properties

JSON SCHEMA

SessionsResponse

4 properties

JSON SCHEMA

TagsMetadata

1 properties

JSON SCHEMA

TimeSeriesHASSHEntry

2 properties

JSON SCHEMA

TimeSeriesHTTPData

10 properties

JSON SCHEMA

TimeSeriesIntelligence

14 properties

JSON SCHEMA

TimeSeriesJA3Entry

2 properties

JSON SCHEMA

TimeSeriesRawData

8 properties

JSON SCHEMA

TimeSeriesRecord

2 properties

JSON SCHEMA

TimeSeriesResponse

0 properties

JSON SCHEMA

TimeSeriesScanEntry

2 properties

JSON SCHEMA

TimeSeriesSourceData

1 properties

JSON SCHEMA

TimeSeriesSSHData

2 properties

JSON SCHEMA

TimeSeriesStatsRecord

2 properties

JSON SCHEMA

TimeSeriesStatsResponse

4 properties

JSON SCHEMA

TimeSeriesTCPData

2 properties

JSON SCHEMA

TimeSeriesTLSData

2 properties

JSON SCHEMA

Scroll within the panel for all 65 ·

JSON Structure 65

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Greynoise Callback File Response Structure

9 properties

JSON STRUCTURE

Greynoise Callback File Summary Structure

5 properties

JSON STRUCTURE

Greynoise Callback Filter Fields Structure

12 properties

JSON STRUCTURE

Greynoise Callback Ip Summary Structure

10 properties

JSON STRUCTURE

Greynoise Community Response Structure

8 properties

JSON STRUCTURE

Greynoise Cve Advanced Response Structure

6 properties

JSON STRUCTURE

Greynoise Cve Basic Response Structure

4 properties

JSON STRUCTURE

Greynoise Cve Details Structure

6 properties

JSON STRUCTURE

Greynoise Cve Exploitation Stats Structure

3 properties

JSON STRUCTURE

Greynoise Cve Minimal Response Structure

2 properties

JSON STRUCTURE

Greynoise Cve Timeline Structure

4 properties

JSON STRUCTURE

Greynoise Gnql Stats Structure

4 properties

JSON STRUCTURE

Greynoise Gnqlip Context V3 Structure

3 properties

JSON STRUCTURE

Greynoise Gnqlv3 Response Structure

2 properties

JSON STRUCTURE

Greynoise Ip Response V3 Structure

4 properties

JSON STRUCTURE

Greynoise Ip Response V3 Tags Structure

11 properties

JSON STRUCTURE

Greynoise Ip Timeline Response Structure

2 properties

JSON STRUCTURE

Greynoise Metadata V3 Structure

24 properties

JSON STRUCTURE

Greynoise Multi Ip Request Structure

1 properties

JSON STRUCTURE

Greynoise Multi Ip Response V3 Structure

2 properties

JSON STRUCTURE

Greynoise Quick Gnqlv3 Response Structure

2 properties

JSON STRUCTURE

Greynoise Quick Ip Profile Structure

3 properties

JSON STRUCTURE

Greynoise Session Count Item Structure

3 properties

JSON STRUCTURE

Greynoise Session Field Structure

6 properties

JSON STRUCTURE

Greynoise Session Pagination Structure

4 properties

JSON STRUCTURE

Greynoise Session Structure

12 properties

JSON STRUCTURE

Greynoise Sessions Response Structure

4 properties

JSON STRUCTURE

Greynoise Tags Metadata Structure

1 properties

JSON STRUCTURE

Greynoise Time Series Http Data Structure

10 properties

JSON STRUCTURE

Greynoise Time Series Ja3 Entry Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Raw Data Structure

8 properties

JSON STRUCTURE

Greynoise Time Series Record Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Response Structure

0 properties

JSON STRUCTURE

Greynoise Time Series Scan Entry Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Ssh Data Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Tcp Data Structure

2 properties

JSON STRUCTURE

Greynoise Time Series Tls Data Structure

2 properties

JSON STRUCTURE

Scroll within the panel for all 65 ·

Examples 64

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Greynoise Session Example

12 fields

EXAMPLE

Scroll within the panel for all 64 ·

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Greynoise Authentication

apiKey · 1 scheme

SECURITY

Greynoise Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Greynoise Agentic Access

27 operations · 5 acting

27 operations · 5 acting

AGENTIC

Use Cases 6

What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.

What developers build with this provider.

Alert triage

Drop alerts on IPs known to be benign internet noise to reduce SOC workload.

Incident response enrichment

Enrich indicators of compromise with classification, tags, and historical activity during investigations.

Threat hunting

Hunt across GreyNoise sensor telemetry for emerging campaigns or specific TTPs.

Vulnerability prioritization

Reorder remediation queues by which CVEs are actively exploited in the wild.

Perimeter defense

Generate query-based blocklists to ingest into firewalls and edge platforms.

AI-assisted SOC

Let LLM agents call GreyNoise through the MCP server during automated triage and reporting.

Integrations 22

Pre-built integrations with other platforms tell you where this provider already fits in a stack.

Pre-built integrations with other platforms and tools.

Splunk

SIEM enrichment via the GreyNoise Splunk app (SA-GreyNoise).

Microsoft Sentinel

TI Feed integration documented for Azure Sentinel.

Google SecOps (Chronicle) / SecOps SOAR

SIEM + SOAR integration via the greynoise-google-secops repository.

CrowdStrike NG-SIEM

Native enrichment integration.

Cribl

GreyNoise enrichment pipeline in Cribl Stream.

Cortex XSOAR (Demisto)

SOAR playbook content for incident enrichment.

Splunk SOAR (Phantom)

SOAR integration and playbooks via greynoise-splunk-soar.

FortiSOAR

SOAR connector via connector-greynoise.

Swimlane

SOAR integration via greynoise-swimlane.

Tines

SOAR integration documented for Tines.

Anomali ThreatStream

TIP integration via greynoise-anomali.

MISP

TIP integration via misp-modules.

Recorded Future

TIP integration documented.

ThreatQ

TIP integration documented.

OpenCTI

TIP connector via the OpenCTI connectors repo.

Maltego

Analyst transforms via greynoise-maltego.

Polarity

Analyst overlay integration.

Palo Alto Networks PAN-OS

GreyNoise blocklists consumable as External Dynamic Lists (EDLs).

fail2ban

Open-source enrichment plugin (greynoise-fail2ban).

Microsoft Copilot for Security

AI/ML integration plug-in for Copilot for Security.

Model Context Protocol (MCP)

Native MCP server for LLM agent integration.

Terraform

Manage alerts and blocklists declaratively (terraform-provider-greynoise).

Scroll within the panel for all 22 ·

Solutions 4

Packaged solutions the provider offers on top of the raw API surface.

Packaged solutions this provider offers.

Community (Free)

Free tier for individual researchers; Community API only.

Standard

Entry-level paid tier with Enterprise + GNQL API access.

Advanced

Most-popular tier with 30-day lookback and 2-hour freshness.

Elite

Premium tier with hourly freshness, 90-day lookback, and unlimited alerts/feeds/blocklists.

Resources

Every other property we hold for GreyNoise Intelligence — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 4

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Learn 4

Tutorials, courses, talks, and written guidance

Company 3

The organization behind the API

Other 2

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/greynoise · machine-readable index on apis.io