lookup-greynoise

SkillDev tools

Use when you need to classify an IP as internet scanner noise vs. targeted activity. Returns noise/riot flags, classification (benign/malicious/unknown), actor name if known. IP-only. Commonly invoked by /ip-investigation to filter out mass-scanning noise. Retrieval only.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the lookup-greynoise skill

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/lookup-greynoise/SKILL.md and read by ahel’s review.

Queries GreyNoise to classify whether an IP is internet background noise (opportunistic scanners, search engines, etc.) or targeted. IP-only. Retrieval only.

When to invoke

  • User asks if an IP is scanner noise or targeted
  • Investigation skill wants to filter out mass-scanning IPs from indicator lists
  • Deciding if an IP hitting your perimeter is worth investigating

How to invoke

Two CLIs are provided. Pick by capability needed:

Basic noise check — Node CLI (zero deps)

node tools/clis/greynoise.js ip <ip>

Hits the /v3/community/{ip} endpoint (free, 50/day). Best for fast retrieval inside an investigation chain.

Full surface — Python CLI (uses official pygreynoise SDK)

python3 tools/clis/greynoise.py community <ip>          # FREE (50/day)
python3 tools/clis/greynoise.py context <ip>            # Enterprise
python3 tools/clis/greynoise.py riot <ip>               # Enterprise
python3 tools/clis/greynoise.py quick <ip,ip,...>       # Enterprise (bulk)
python3 tools/clis/greynoise.py similarity <ip>         # Enterprise
python3 tools/clis/greynoise.py timeline <ip> [--days N]  # Enterprise
python3 tools/clis/greynoise.py query "<gnql>"          # Enterprise
python3 tools/clis/greynoise.py stats "<gnql>"          # Enterprise
python3 tools/clis/greynoise.py metadata

Self-bootstraps a private venv at tools/clis/.venv-greynoise/ on first run.

Capabilities the Node CLI doesn't have (Enterprise tier required for most):

  1. Context — full per-IP telemetry: every port/protocol/payload combination GreyNoise has observed, broken down by date.
  2. GNQL search (query) — find every IP matching a query: classification:malicious tags:Mirai metadata.country:RU. The killer pivot — discover scanner clusters by characteristic.
  3. GNQL stats — bucket counts (countries, ASNs, tags, categories) for a query without pulling individual results.
  4. Similarity — given an IP, find behaviorally similar scanners (often used to expand a single observation into a cluster).
  5. Timeline — daily activity history for an IP — useful for distinguishing a brief campaign from persistent scanning.
  6. Quick (bulk) — classify many IPs in one call (cheaper than N individual lookups).
  7. RIOT — explicit known-benign check (CDNs, search engines, ISPs) without the noise classification.

GNQL examples:

# All malicious scanners hitting port 22 from Russia in the last day
python3 tools/clis/greynoise.py query 'classification:malicious raw_data.scan.port:22 metadata.country:RU last_seen:1d'

# Stats: country distribution of Mirai-tagged IPs
python3 tools/clis/greynoise.py stats 'tags:"Mirai" last_seen:30d'

# Find IPs similar to a known scanner
python3 tools/clis/greynoise.py similarity 185.220.101.45 --limit 50

Both CLIs accept --dry-run.

Tier awareness — this matters

  • Community endpoint (/v3/community/{ip}) is public and unauthenticated. Both CLIs work without $GREYNOISE_API_KEY for the community subcommand. Rate-limited per source IP (a few per minute is fine; sustained bulk lookups will throttle).
  • Enterprise endpoints (context, RIOT, GNQL, similarity, timeline, quick) require a paid Enterprise key. As of 2026 GreyNoise no longer offers a free community API key tier — what their portal calls an "API key" gates Enterprise access. The CLIs return a 401 / 402 / "upgrade required" error if your key doesn't have access; fall back to community.
  • The community endpoint is sufficient for the most common CTI question — "is this IP a known scanner?" — for most investigation use.

Response format

source: greynoise
indicator: <IP>
query_time: <ISO8601>
noise: <boolean>          # seen as internet background noise
riot: <boolean>           # rule-it-out: known-benign common service
classification: benign | malicious | unknown
name: <actor name or unknown>
last_seen: <date>
message: <summary>

Rate limits

Community endpoint: 50 req/day free. Enterprise: much higher.

Source reliability (Admiralty default)

Default rating for downstream /score-source: B2 (usually reliable, probably true). Empirical signal. A noise: true result is strong evidence the IP is not targeted.

Operational notes

  • IP addresses only. The CLI rejects non-IP inputs.
  • riot: true is a strong signal the IP is a benign common service (CDN, search engine, etc.) — downgrade severity of any detection against it.
  • classification: malicious + noise: true = mass-scanning threat actor infrastructure, not a targeted campaign.

Related skills

  • /lookup-abuseipdb — abuse reports for the same IP
  • /lookup-virustotal, /lookup-shodan — additional IP context
  • /ip-investigation — uses GreyNoise to filter noise early in the pipeline

See also

Signals

GitHub stars
22
Forks
9
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
lookup-greynoise
Source
github.com/liberty91ltd/cti-skills