GreyNoise Block is a real-time, configurable IP blocklist solution built from observed attack traffic collected by the GreyNoise Global Observation Grid. The product enables organizations to ingest dynamic blocklists into network firewalls and other security platforms via External Dynamic Lists (EDL). Its purpose is to stop mass exploitation, mitigate active CVE exploits, and prevent outbound communication from compromised internal assets to malicious IP addresses. The lists focus on IP addresses observed performing targeted scanning activities within the last 24 hours and are continuously updated.
The solution provides both out-of-the-box templates and custom configurations using the GreyNoise Query Language, allowing administrators to filter traffic by geography, IP reputation, specific vulnerabilities, spoofability, and behavioral tags. Blocklists are delivered through automated static URLs with built-in authentication tokens for ingestion into security appliances. It can integrate with Threat Intelligence Platform (TIP) and SOAR platforms to automate enforcement workflows, and active lists can also be manually downloaded in various file formats or aggregated using custom scripting.