Daily GreyNoise threat brief for your security team
Every weekday morning, turn GreyNoise internet-scanning data into a short, prioritized threat brief and email it to your security team automatically.
Every weekday at 7am, build an emerging-internet-threat brief from GreyNoise and email it to our security team. The goal is to turn GreyNoise's GNQL dataset into a short, prioritized digest of what changed across internet scanning in the last 24 hours, so nobody has to dig through the GreyNoise Visualizer by hand. This is the 'track emerging threats' use case teams otherwise do manually.
Gather the data with GreyNoise. Use GNQL Query to search the full dataset for recent malicious scanning (for example a query like classification:malicious last_seen:1d, plus per-tag variants), and use GNQL Stats on the same queries to get aggregated counts broken down by tag, actor, organization, ASN, and source country. To find the biggest jumps rather than just the biggest absolute numbers, also pull the same aggregates for a comparable baseline window (for example the previous 24 hours, or a 7-day average) and compare the two, so you can flag the tags and actors whose activity spiked. Use GNQL Metadata Query when you only need the lighter metadata payload, and prefer aggregated GNQL Stats calls over pulling every raw IP.
What to surface: the malicious tags with the biggest jump in activity versus baseline; newly active scanning actors (actors showing up now that were quiet before); and the top attacking organizations, ASNs, and source countries.
Write the brief. Produce a short written threat brief of three to six bullets. Each bullet should say what changed and why it matters in one or two sentences, not just dump numbers. Keep it skimmable and lead with anything that looks like a new mass-exploitation campaign (a sharp spike on a specific exploit or CVE tag, or a newly active actor scanning aggressively) rather than routine background scanning. If the last 24 hours were quiet, say so plainly in a sentence or two instead of padding the brief with filler.
Deliver it with Gmail Send a Message. Email the brief to the security team. Use a dated subject line that leads with the headline, for example 'GreyNoise threat brief, [date]: [the biggest thing that changed]', and put the bullets in the body. Send the email even on quiet days, with a brief 'nothing notable' note, so the team knows the check ran. Set the recipient to your security team's address or distribution list.
Example output
Additional information
What does this prompt do?
- Checks GreyNoise every weekday morning to see what changed across internet scanning activity in the last 24 hours.
- Highlights the malicious tags spiking the most, newly active scanning actors, and the top attacking organizations, networks, and source countries.
- Writes a short, skimmable threat brief of three to six bullets that each explain what changed and why it matters.
- Emails the brief to your security team, and says so plainly when the day was quiet instead of padding it out.
What do I need to use this?
- A GreyNoise account with API access (GreyNoise grants this to accounts registered with a business email address).
- A Google account connected through Gmail so the brief can be sent.
- The email address or distribution list for your security team.
How can I customize it?
- Change the timing: send it every weekday, seven days a week, or at a different hour.
- Point it at a different recipient, such as an on-call alias or a shared security inbox.
- Adjust what counts as notable, for example focusing only on exploit-related scanning or a specific region.
Frequently asked questions
What is GreyNoise?
How often does the brief arrive?
What happens on a quiet day?
Do I need a paid GreyNoise plan?
Can I send it somewhere other than my security team?
Related templates
Stop digging through the GreyNoise Visualizer every morning.
Let this workflow watch internet scanning trends for you and deliver a prioritized threat brief to your inbox before the day starts.