This app provides investigative capabilities using the GreyNoise plugin and supports receiving alerts and feeds via webhook from GreyNoise
Supported Actions
- test connectivity: Validate the asset configuration for connectivity using the supplied configuration
- lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
- ip reputation: Get full GreyNoise reputation and context for a specific IP
- gnql query: Use the GreyNoise Query Language to run a query
- lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
- on poll: Get details on a specific GNQL query
- noise ip timeline: GreyNoise IP Timeline lookup for events matching a specific field
- get cve details: Retrieve details about a specific Common Vulnerabilities and Exposures (CVE)