Evaluating GreyNoise: what you need to know and how it can help you
ID: b2b0de36-74ba-59cc-9d27-2a16e78d7db9
STIX ID: report--b2b0de36-74ba-59cc-9d27-2a16e78d7db9
Feed Name: Expel Blog
Expel evaluated GreyNoise to enrich alert context and reduce internet-scanning noise in their SOC workflows. Through four experiments (investigative context, detecting customer IPs flagged as noise, identifying customer hosts connecting to noisy IPs, and spotting successful logins from noisy IPs) they found GreyNoise provided useful context for ~21% of sampled IPs, flagged 14 customer IPs that required follow-up, and showed ~25% of destination IPs in alerts were classified as noisy; they implemented rules to filter noise and to alert on successful access from noisy IPs to catch potential compromises or misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
