post https://api.greynoise.io/v2/noise/multi/quick
Check whether a set of IP addresses are "Internet background noise", or
have been observed scanning or attacking devices across the Internet.
This endpoint is functionality identical to the /v2/noise/quick/{ip}
endpoint, except it processes more than one checks simultaneously.
This endpoint is useful for filtering through large log files.
Can process up to 1,000 IPs per request.
Notes:
- This API endpoint updates in real-time
- This API endpoint can either be used via GET parameter or within the
body of the request - This API endpoint contains a “code” which correlates to why
GreyNoise labeled the IP as "noise" - This API endpoint checks the IP against the RIOT data set, setting
the bool flag of "riot" if it appears - An IP delivered via this endpoint does not include "malicious" or
"benign" categorizations - This API endpoint only checks against the last 90 days of Internet
scanner data
Code:
- 0x00: The IP has never been observed scanning the Internet
- 0x01: The IP has been observed by the GreyNoise sensor network
- 0x02: The IP has been observed scanning the GreyNoise sensor network,
but has not completed a full connection, meaning this can be spoofed - 0x05: This IP is commonly spoofed in Internet-scan activity
- 0x06: This IP has been observed as noise, but this host belongs to
a cloud provider where IPs can be cycled frequently - 0x07: This IP is invalid
- 0x08: This IP was classified as noise, but has not been observed
engaging in Internet-wide scans or attacks in over 90 days - 0x09: This IP was found in RIOT
- 0x10: The IP has been observed by the GreyNoise sensor network and
was found in RIOT
Search Usage: This endpoint consumes one Search per API request.