Daily GreyNoise threat brief for your security team

Every weekday morning, turn GreyNoise internet-scanning data into a short, prioritized threat brief and email it to your security team automatically.

Agentic Task
GreyNoiseGmailEngineeringOperationsAI ReportsResearch & MonitoringEmail Automation
PromptCreate

Every weekday at 7am, build an emerging-internet-threat brief from GreyNoise and email it to our security team. The goal is to turn GreyNoise's GNQL dataset into a short, prioritized digest of what changed across internet scanning in the last 24 hours, so nobody has to dig through the GreyNoise Visualizer by hand. This is the 'track emerging threats' use case teams otherwise do manually.

Gather the data with GreyNoise. Use GNQL Query to search the full dataset for recent malicious scanning (for example a query like classification:malicious last_seen:1d, plus per-tag variants), and use GNQL Stats on the same queries to get aggregated counts broken down by tag, actor, organization, ASN, and source country. To find the biggest jumps rather than just the biggest absolute numbers, also pull the same aggregates for a comparable baseline window (for example the previous 24 hours, or a 7-day average) and compare the two, so you can flag the tags and actors whose activity spiked. Use GNQL Metadata Query when you only need the lighter metadata payload, and prefer aggregated GNQL Stats calls over pulling every raw IP.

What to surface: the malicious tags with the biggest jump in activity versus baseline; newly active scanning actors (actors showing up now that were quiet before); and the top attacking organizations, ASNs, and source countries.

Write the brief. Produce a short written threat brief of three to six bullets. Each bullet should say what changed and why it matters in one or two sentences, not just dump numbers. Keep it skimmable and lead with anything that looks like a new mass-exploitation campaign (a sharp spike on a specific exploit or CVE tag, or a newly active actor scanning aggressively) rather than routine background scanning. If the last 24 hours were quiet, say so plainly in a sentence or two instead of padding the brief with filler.

Deliver it with Gmail Send a Message. Email the brief to the security team. Use a dated subject line that leads with the headline, for example 'GreyNoise threat brief, [date]: [the biggest thing that changed]', and put the bullets in the body. Send the email even on quiet days, with a brief 'nothing notable' note, so the team knows the check ran. Set the recipient to your security team's address or distribution list.

Example output

Subject: GreyNoise threat brief, Jul 17: spike in Ivanti Connect Secure exploit scanning - Likely new mass-exploitation: scanning tagged 'Ivanti Connect Secure RCE Attempt' jumped roughly 6x in the last 24h, from ~40 to ~250 unique malicious IPs versus the 7-day baseline. Confirm your Ivanti appliances are patched today. - Newly active actor: a scanning actor not seen in the prior week is now probing exposed RDP across ~1,200 IPs, concentrated on two low-reputation networks. Worth watching. - Top attacking network: a handful of VPS providers account for most new malicious sources. This looks like routine background scanning, not a targeted campaign. - Source-country shift: malicious scanning from one Southeast Asian ASN roughly doubled day over day, driven by generic web-app fuzzing rather than a specific CVE. - Otherwise quiet: no other tags showed a meaningful jump versus baseline.

Additional information

What does this prompt do?
  • Checks GreyNoise every weekday morning to see what changed across internet scanning activity in the last 24 hours.
  • Highlights the malicious tags spiking the most, newly active scanning actors, and the top attacking organizations, networks, and source countries.
  • Writes a short, skimmable threat brief of three to six bullets that each explain what changed and why it matters.
  • Emails the brief to your security team, and says so plainly when the day was quiet instead of padding it out.
What do I need to use this?
  • A GreyNoise account with API access (GreyNoise grants this to accounts registered with a business email address).
  • A Google account connected through Gmail so the brief can be sent.
  • The email address or distribution list for your security team.
How can I customize it?
  • Change the timing: send it every weekday, seven days a week, or at a different hour.
  • Point it at a different recipient, such as an on-call alias or a shared security inbox.
  • Adjust what counts as notable, for example focusing only on exploit-related scanning or a specific region.

Frequently asked questions

What is GreyNoise?
GreyNoise watches the internet for scanning and probing activity and labels which sources are malicious, benign, or just background noise. This workflow turns that raw data into a plain-English brief so your team does not have to dig through it manually.
How often does the brief arrive?
By default it runs every weekday morning at 7am, but you can change the schedule to whatever cadence your team prefers.
What happens on a quiet day?
You still get a short note saying nothing notable changed, so you know the check ran rather than wondering whether it failed.
Do I need a paid GreyNoise plan?
Searching the full GreyNoise dataset for threat trends requires a paid or trial plan. The free community tier is limited to individual IP lookups.
Can I send it somewhere other than my security team?
Yes. You can send the brief to any inbox, a shared distribution list, or a monitored alias by changing the recipient.

Stop digging through the GreyNoise Visualizer every morning.

Let this workflow watch internet scanning trends for you and deliver a prioritized threat brief to your inbox before the day starts.