Creating a GreyNoise Lookup Table

Overview

GreyNoisearrow-up-right collects data on IP addresses, which can help you understand which events can be ignored. This may help to reduce your number of false positive alerts.

circle-exclamation

Panther has created the following resources to help you set up a GreyNoise Lookup Table via S3 syncarrow-up-right:

  • A Panther-managed GreyNoise.API.Noise schema

  • This panther-auxiliary repositoryarrow-up-right. The greynoise_noise directory contains:

    • A script to pull GreyNoise data

    • A CloudFormation template that defines an IAM role, which Panther will assume to access the S3 data

    • A definition for the Lookup Table

How to set up a GreyNoise Lookup Table in Panther

Last updated

Was this helpful?