lookup-greynoise
SkillDev toolsUse when you need to classify an IP as internet scanner noise vs. targeted activity. Returns noise/riot flags, classification (benign/malicious/unknown), actor name if known. IP-only. Commonly invoked by /ip-investigation to filter out mass-scanning noise. Retrieval only.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the lookup-greynoise skill
What this skill tells your AI
The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/lookup-greynoise/SKILL.md and read by ahel’s review.
Queries GreyNoise to classify whether an IP is internet background noise (opportunistic scanners, search engines, etc.) or targeted. IP-only. Retrieval only.
When to invoke
- User asks if an IP is scanner noise or targeted
- Investigation skill wants to filter out mass-scanning IPs from indicator lists
- Deciding if an IP hitting your perimeter is worth investigating
How to invoke
Two CLIs are provided. Pick by capability needed:
Basic noise check — Node CLI (zero deps)
node tools/clis/greynoise.js ip <ip>
Hits the /v3/community/{ip} endpoint (free, 50/day). Best for fast retrieval inside an investigation chain.
Full surface — Python CLI (uses official pygreynoise SDK)
python3 tools/clis/greynoise.py community <ip> # FREE (50/day)
python3 tools/clis/greynoise.py context <ip> # Enterprise
python3 tools/clis/greynoise.py riot <ip> # Enterprise
python3 tools/clis/greynoise.py quick <ip,ip,...> # Enterprise (bulk)
python3 tools/clis/greynoise.py similarity <ip> # Enterprise
python3 tools/clis/greynoise.py timeline <ip> [--days N] # Enterprise
python3 tools/clis/greynoise.py query "<gnql>" # Enterprise
python3 tools/clis/greynoise.py stats "<gnql>" # Enterprise
python3 tools/clis/greynoise.py metadata
Self-bootstraps a private venv at tools/clis/.venv-greynoise/ on first run.
Capabilities the Node CLI doesn't have (Enterprise tier required for most):
- Context — full per-IP telemetry: every port/protocol/payload combination GreyNoise has observed, broken down by date.
- GNQL search (
query) — find every IP matching a query:classification:malicious tags:Mirai metadata.country:RU. The killer pivot — discover scanner clusters by characteristic. - GNQL stats — bucket counts (countries, ASNs, tags, categories) for a query without pulling individual results.
- Similarity — given an IP, find behaviorally similar scanners (often used to expand a single observation into a cluster).
- Timeline — daily activity history for an IP — useful for distinguishing a brief campaign from persistent scanning.
- Quick (bulk) — classify many IPs in one call (cheaper than N individual lookups).
- RIOT — explicit known-benign check (CDNs, search engines, ISPs) without the noise classification.
GNQL examples:
# All malicious scanners hitting port 22 from Russia in the last day
python3 tools/clis/greynoise.py query 'classification:malicious raw_data.scan.port:22 metadata.country:RU last_seen:1d'
# Stats: country distribution of Mirai-tagged IPs
python3 tools/clis/greynoise.py stats 'tags:"Mirai" last_seen:30d'
# Find IPs similar to a known scanner
python3 tools/clis/greynoise.py similarity 185.220.101.45 --limit 50
Both CLIs accept --dry-run.
Tier awareness — this matters
- Community endpoint (
/v3/community/{ip}) is public and unauthenticated. Both CLIs work without$GREYNOISE_API_KEYfor thecommunitysubcommand. Rate-limited per source IP (a few per minute is fine; sustained bulk lookups will throttle). - Enterprise endpoints (context, RIOT, GNQL, similarity, timeline, quick) require a paid Enterprise key. As of 2026 GreyNoise no longer offers a free community API key tier — what their portal calls an "API key" gates Enterprise access. The CLIs return a 401 / 402 / "upgrade required" error if your key doesn't have access; fall back to
community. - The community endpoint is sufficient for the most common CTI question — "is this IP a known scanner?" — for most investigation use.
Response format
source: greynoise
indicator: <IP>
query_time: <ISO8601>
noise: <boolean> # seen as internet background noise
riot: <boolean> # rule-it-out: known-benign common service
classification: benign | malicious | unknown
name: <actor name or unknown>
last_seen: <date>
message: <summary>
Rate limits
Community endpoint: 50 req/day free. Enterprise: much higher.
Source reliability (Admiralty default)
Default rating for downstream /score-source: B2 (usually reliable, probably true). Empirical signal. A noise: true result is strong evidence the IP is not targeted.
Operational notes
- IP addresses only. The CLI rejects non-IP inputs.
riot: trueis a strong signal the IP is a benign common service (CDN, search engine, etc.) — downgrade severity of any detection against it.classification: malicious+noise: true= mass-scanning threat actor infrastructure, not a targeted campaign.
Related skills
/lookup-abuseipdb— abuse reports for the same IP/lookup-virustotal,/lookup-shodan— additional IP context/ip-investigation— uses GreyNoise to filter noise early in the pipeline
See also
- Integration setup:
tools/integrations/greynoise.md - Node CLI source:
tools/clis/greynoise.js - Python CLI source:
tools/clis/greynoise.py - Official Python SDK: https://github.com/GreyNoise-Intelligence/pygreynoise
- API docs: https://docs.greynoise.io/
- GNQL syntax: https://docs.greynoise.io/docs/using-the-greynoise-query-language-gnql
Signals
- GitHub stars
- 22
- Forks
- 9
- Last commit
- Aug 2026
Advanced
- Catalog kind
- skill
- Gateway key
lookup-greynoise- Source
- github.com/liberty91ltd/cti-skills