Internet scanning campaign explorer for security teams

Browse the mass-scanning campaigns running on the internet right now and see instantly whether any of them target software you actually run.

App
GreyNoiseGoogle SheetsJiraEngineeringOperationsResearch & MonitoringAI Reports
PromptCreate

I want an app that shows my security team which mass-scanning campaigns are running on the internet right now and whether any of them matter to the software we actually run. The audience is our security lead doing a morning review, not an on-call responder, so this is a browsing and pivoting surface rather than an alerting one. It should never try to page anyone or lean on urgency styling. It opens to a calm, dense, scannable overview that answers the question is anyone scanning for something we own before it asks anyone to read individual campaigns.

The main screen is a campaign explorer. Use GreyNoise List Tags to get the catalog of current activity tags and malware labels, and for each one use GreyNoise GNQL Stats to pull the aggregated counts of how many IPs are behind it, broken down by country, organization, ASN and actor. GNQL Stats is the right call for these aggregate counts rather than paging full result sets through GNQL Query. Render the campaigns as a browsable, filterable, sortable list showing the tag name, its label or category, the total number of scanning IPs, and the top few countries, organizations and actors inline, so the lead can pivot across the list without opening anything.

A second view reads our technology inventory from a Google Sheet using Google Sheets Get Values. The sheet is one row per vendor, product and version we run at the edge. Give it a simple documented column layout and state that layout plainly somewhere in the app so whoever maintains the sheet does not have to guess, and read it with a straightforward documented range. Match those inventory rows against the campaign list on vendor and product name, and surface the result at the very top of the app as the headline answer to is anyone scanning for something we own. Campaigns that match our inventory must always sort to the top of the explorer and render in a visually distinct state, with the matching inventory row named on the campaign so the reason for the match is immediately obvious. Inventory rows that match nothing are fine and should just be shown as unmatched rather than hidden.

Each campaign opens a detail view. Pull a sample of the IPs currently running that campaign with GreyNoise GNQL Query, and show the CVEs the tag is associated with. Keep the sample small and label it clearly as a sample rather than attempting to render every scanning IP. Show the country, organization, ASN and actor breakdowns in more depth here than the list does, and use GreyNoise GNQL Recall Stats to show how the campaign's scanning volume has moved over recent days.

Analysts can star a campaign to a watchlist that persists in the app. A starred campaign stores a free-text note and a reviewed date, both editable in place. On the watchlist view, show for each starred campaign how its scanning volume has moved since the last time someone reviewed it, comparing current volume against the volume as of that stored reviewed date using GreyNoise GNQL Recall Stats, and state the change in plain terms such as roughly three times as many scanning IPs as at your last review, or quieter than when you last looked. This movement-since-review number is a core part of the morning pass and should be prominent, not buried.

Every campaign has an Assess our exposure button that starts a background agent. The agent pulls GreyNoise Retrieve CVE Information for each CVE the campaign is associated with, checks the campaign's scanning volume trend, compares all of that against the inventory rows read from the Google Sheet, and writes a plain-language exposure assessment back into the app so it appears on the campaign and persists for whoever looks next. The assessment should say clearly whether we are exposed, which of our products and versions are implicated, what the CVE detail actually says about observed exploitation, and what the scanning trend suggests. When, and only when, the agent concludes we are genuinely exposed, it files a ticket using Jira Create Issue containing the campaign, the associated CVEs, the affected inventory rows and its reasoning, and links that ticket back onto the campaign in the app. If it concludes we are not exposed, it still writes and stores the assessment and files nothing.

Bake in the review rhythm throughout. Favour density and calm over alert styling, make the inventory-matching campaigns unmistakable at a glance, and make it obvious which campaigns have already been assessed or reviewed and which are new since the last visit. Watchlist entries, notes, reviewed dates and exposure assessments all persist in the app rather than being regenerated on every load, and the exposure agent runs in the background so the lead can keep browsing the explorer while it works.

What does this prompt do?

  • Opens on a live list of the scanning campaigns active across the internet right now, showing how many machines are behind each one and where they are coming from by country, network operator and known actor.
  • Matches every campaign against your own technology list kept in a Google Sheet, so anything scanning for software you actually run jumps to the top of the screen and stands out from the rest.
  • Lets analysts star campaigns to a watchlist with a note and a reviewed date, then shows how much each one has grown or quieted down since the last time someone looked at it.
  • Gives every campaign an Assess our exposure button that hands the work to a background assistant, which writes a plain-language verdict back into the app and raises a Jira ticket only when you are genuinely at risk.

What do I need to use this?

  • A GreyNoise account with API access. GreyNoise only grants this to accounts registered with a business email address, and the richer campaign and CVE data requires a paid or trial plan
  • A Google Sheet listing the technology you run at the edge, with one row per vendor, product and version
  • A Google account that can read that spreadsheet
  • A Jira project where exposure tickets should be filed

How can I customize it?

  • Point the app at a different spreadsheet or change which columns hold vendor, product and version as your inventory grows
  • Adjust what the assistant treats as genuinely exposed before it raises a ticket, and which Jira project and issue type that ticket lands in
  • Change how far back the scanning volume comparison looks, and which breakdowns appear on the main list

FAQs

Will this alert me or page my team?
No, and that is deliberate. It is a browsing surface built for a security lead doing a morning review, so it stays calm and dense rather than shouting about severity. You open it and pivot through what is happening; nothing chases you.
What does the technology sheet need to look like?
A simple spreadsheet with one row per vendor, product and version you run at the edge. The app documents the exact column layout it expects, so whoever maintains the sheet does not have to guess. Anything it cannot match is simply left unmatched rather than hidden.
Will it file Jira tickets on its own?
Only when someone presses Assess our exposure on a campaign and the background assistant concludes you are genuinely exposed. If it decides you are not exposed, it still writes up its reasoning in the app and files nothing.
Does this work on a free GreyNoise account?
Not fully. GreyNoise only issues API keys to accounts registered with a business email address, and most of the campaign, tag and CVE data this app reads requires a paid subscription or an enterprise trial. A free key is limited to basic single address lookups.
What if a campaign has no connection to anything we run?
It stays in the list so you can still browse what is happening on the internet, but it sorts below anything that matches your inventory. The whole point is that you answer is anyone scanning for something we own without reading every campaign.

Related templates

Prospecting desk that builds account lists from the live web

Stop buying stale lists. Reps run a saved search, work the results like an inbox, and only the accounts they approve ever reach your CRM.

Hyperbrowser
HubSpot
Google Sheets
App
Influencer campaign roster board with AI creator briefs

Drag creators through Sourced to Wrapped on a board grouped by campaign, with audience stats on every card and a one-click brief for each creator.

HypeAuditor
Google Sheets
Notion
App
Morning repricing console for Shopify with margin-safe rules

Pick a repricing rule, send an assistant out to check competitor pages, then approve the new prices that clear your margin floor.

Hyperbrowser
Shopify
Google Sheets
App
Pre-flight bounce check before you launch a cold email sequence

See the projected bounce rate for any outbound send before it goes out, and keep the launch button locked until the list is clean enough to be safe.

Hunter
Google Sheets
App
Per-device electricity cost explorer for your smart home

Pick any date range and see what each device in your home actually cost to run, not just how many kilowatt-hours it used.

Home Assistant
Google Sheets
App
Build a PR media list from real worldwide news coverage

Search three months of global coverage on your topic, rank the outlets actually writing about it, and draft a tailored pitch for each one.

GDELT
Google Sheets
Gmail
App

Stop reading every scanning campaign to find the one that matters.

Give your security lead one screen that puts the campaigns targeting your own stack at the top and explains your exposure in plain language.