Threat intelligence · GreyNoise Intelligence
GreyNoise
Classifies internet-wide scanning traffic as benign, malicious, or unknown so SOC teams can filter background noise out of alerts.
GreyNoise continuously observes traffic hitting internet-facing sensors and devices such as VPN gateways, firewalls, and load balancers, and classifies the senders as internet background noise: mass scanners, research crawlers, and other automated probing not targeted at a specific organization. Feeding that classification into a customer's alerts lets a SOC suppress the routine scanning that would otherwise drown out genuine, targeted threats, and separately flags active exploitation of specific CVEs as it begins, sometimes ahead of public disclosure. GreyNoise sells its data through selectable modules, Triage, Investigate, and Hunt, each building on the last, plus add-ons for C2 detection, business-services identification, and vulnerability prioritization, layered under Free, Standard, Advanced, and Elite platform tiers that vary by data freshness, lookback window, and alert or blocklist limits. It is one of the few vendors in this category to publish a working free tier.
At a glance
| Vendor | GreyNoise Intelligence |
|---|---|
| Pricing model | Free tier + paid plans |
| Free tier | Yes |
| Deployment | Cloud |
| Open source | No |
| Best for | SOC teams that want to suppress routine internet scanning noise and catch early exploitation of specific CVEs. |
Pricing
A published Free tier (data refreshed every 8 hours, 10-day lookback, limited alerts/searches) plus Standard, Advanced, and Elite tiers that require a sales quote.
| Plan | Price | Notes |
|---|---|---|
| Free | $0 | Data refreshed every 8 hours, up to 10-day lookback, 3 alerts, 1 blocklist, ~50 searches/week |
| Standard | contact sales | 4-hour data refresh, 10-day lookback, 10 alerts, 3 blocklists, unlimited searches |
| Advanced | contact sales | 2-hour data refresh, 30-day lookback, 25 alerts, 10 blocklists, feeds included |
| Elite | contact sales | 1-hour data refresh, 90-day lookback, unlimited alerts and blocklists, feeds included |
Prices read from the vendor's own page on September 21, 2026. Vendors change prices; check the source before you budget.
Features
- Classification of internet background scanning noise
- Early active-exploitation detection, sometimes pre-disclosure
- Compromised-asset detection via scanning/beaconing signals, no agent required
- Alert enrichment with intent, CVE, and attacker-tooling context
- Dynamic, configurable IP blocklists
- Selectable Triage/Investigate/Hunt intelligence modules
- C2 detection and vulnerability-prioritization add-ons
Profile last reviewed September 21, 2026