GreyNoise module.
GreyNoise enriches your organization's IP IOCs with internet-scan noise context: whether an address is mass-scanning the internet or a known benign crawler. That distinction is what makes it useful during triage, because an address hammering every network on the internet is a different proposition from one that appears only in your reporting. It is a bring-your-own-key integration: create a GreyNoise account, generate an API key, and paste it into the module once for the whole billing account. Every new IP indicator that arrives after that is classified automatically.
You need a GreyNoise account and an API key generated from it. The key is the only thing this module asks for.
How to connect GreyNoise
- Sign in to GreyNoise, or create an account if you do not have one, and generate an API key.
- In Liberty91, go to Modules, open the Analysis Modules section, and click the GreyNoise tile.
- Paste the key into the API key field.
- Turn on Active and click update.
Checking the connection
There is no separate Test button, because saving is the health check. When you save, Liberty91 calls GreyNoise with the key you pasted and reports what came back. A green Connected banner means the credential works, and a red banner means it does not. If you leave the page and return later, a blue Status banner shows the result of the last save rather than re-testing.
| Message | What it means |
|---|---|
API key validated | The key works and the module is ready to enrich |
Invalid API key | GreyNoise rejected the key. Generate a new one and paste it again |
GreyNoise rate limit reached, try again later | Your GreyNoise plan is out of requests for the moment. Nothing is wrong with the key |
Could not reach GreyNoise | Liberty91 got no response at all, usually a transient network problem |
GreyNoise returned HTTP <code> | GreyNoise answered with something unexpected, and the code says what |
Leave the API key field blank when you save and the stored key is kept. That is how you turn Active off and on again without retyping it. Keys are encrypted at rest and never sent back to the browser, so the field looks empty even when a key is stored.
The module also shows IOCs enriched as a running total, which is the quickest way to confirm that indicators really are being processed.
What you get from GreyNoise enrichment
Every IP indicator that arrives after the key is saved is looked up, and GreyNoise's classification becomes one of the four verdicts used across the platform, together with a score from 0 to 100.
| GreyNoise classification | Verdict | Score |
|---|---|---|
malicious | Malicious | 90 |
benign | Benign | 0 |
| Anything else, including no classification | Unknown | Not set |
In the platform you see a GreyNoise chip on the indicator's row and in its panel, showing the
classification and then the actor name where GreyNoise names one, such as a known scanning
service or crawler. In an IOC CSV export, GREYNOISE appears in the enrichment_providers
column, and over the API the same value comes back in the enrichment_providers and
enrichments fields on the IOC endpoints, where you can also filter for it
with ?enrichment_provider=GREYNOISE.
A GreyNoise verdict of Benign is a real finding rather than an absence of one, and it carries weight accordingly: a benign reading from any vendor caps the indicator's confidence, which is what stops a well-known crawler in a proxy log from reading as a high-confidence threat. See IOC enrichment and decay scoring for how the readings combine.
Permissions and limits
Any member of the billing account can configure this module. There is no Owner or Admin gate on it, unlike the ransomware domain alerts, which are restricted.
- One key per billing account, shared by everyone on it.
- Saving is rate-limited to 12 attempts a minute per user, so repeated retries pause briefly.
- Enrichment runs in batches of up to 100 indicators.
Frequently asked questions
Which indicators does GreyNoise enrich?
IP addresses only. Domains, URLs, and hashes are left alone: GreyNoise adds no chip and no verdict to them.
Why do so many addresses come back as Unknown?
GreyNoise classifies an address as malicious or benign only when it has grounds to. Anything else stays Unknown, which means no signal rather than no risk.
Do I have to retype the key to turn the module off and on?
No. Leave the API key field blank when you save and the stored key is kept, so you can flip Active off or on without it.