GreyNoise API

SkillDev tools

GreyNoise API reference. Internet scanner/noise classification for IPs.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the GreyNoise API skill

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/greynoise-api/SKILL.md and read by ahel’s review.

Base URL

  • Community: https://api.greynoise.io/v3/community
  • Enterprise: https://api.greynoise.io/v3

Authentication

Header: key: $GREYNOISE_API_KEY

Rate Limits

  • Community (free): 50 requests/day
  • Enterprise: Based on plan

Key Endpoints

Community IP Lookup (Free)

curl -s "https://api.greynoise.io/v3/community/{ip}" \
  -H "key: $GREYNOISE_API_KEY"

Response fields:

  • noise — true if IP is a known internet scanner
  • riot — true if IP belongs to a known benign service (CDN, DNS, etc.)
  • classification — benign|malicious|unknown
  • name — actor name if identified
  • last_seen — last observation date
  • message — human-readable summary

Enterprise Context (Paid)

curl -s "https://api.greynoise.io/v3/noise/context/{ip}" \
  -H "key: $GREYNOISE_API_KEY"

Additional fields: tags, cve, os, ports, raw_data

Classification Meaning

ClassificationMeaningAction
benign + noise:trueKnown benign scanner (Shodan, Censys, etc.)Likely false positive — deprioritise
malicious + noise:trueKnown malicious scannerReal threat, but opportunistic, not targeted
unknown + noise:trueUnclassified scannerInvestigate further
noise:false + riot:falseNot a known scannerMay be targeted — investigate
riot:trueKnown benign serviceDefinitely deprioritise

CTI Value

GreyNoise answers: "Is this IP scanning the whole internet, or is it specifically targeting us?"

  • If noise:true → opportunistic, not targeted
  • If noise:false → potentially targeted, higher priority

Response Summary Format

ip: <IP>
noise: <true/false>
riot: <true/false>
classification: benign|malicious|unknown
name: <actor name or "unknown">
last_seen: <date>
message: <summary>
verdict: benign-scanner|malicious-scanner|not-scanner|benign-service

Signals

GitHub stars
22
Forks
9
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
greynoise-api
Source
github.com/liberty91ltd/cti-skills