flâneur — a map of the web's best reading

Introducing Sift: Automated Threat Hunting

greynoise.io · 1,039 words · saved by 1 readers

GreyNoise is exposing a new internally developed tool, Sift, to the public for the first time. Sift curates a report of new/interesting traffic observed by GreyNoise sensors daily after doing much of the analysis and triage work itself. Check it out at https://sift.labs.greynoise.io/ Note that it is a new and experimental feature and will probably have some bugs and change without warning. We will soon be integrating direct marker.io feedback capability. For now, please direct all feedback to labs@greynoise.io. We really want to know what you think! There is a lot of traffic bouncing around the internet. Full stop. GreyNoise sees ~2 million HTTP requests (along with tens of millions of events from other protocols) a day. For our on-staff Detection Engineers and your engineers and analysts facing similar loads, analyzing millions of HTTP requests can be extremely tiresome and stressful. It’s like looking for a needle in a haystack each day. Most of them are harmless, but some could be h

Introducing Sift: Automated Threat Hunting Now Live! P roject Swarm: Join the Collective. Defend the Edge Join the Swarm Plans Integrations Resources Company Login Search for free Get a demo Plans Integrations Resources Company Blog > GreyNoise Research Follow us GreyNoise Research Introducing Sift: Automated Threat Hunting Daniel Grant October 2, 2023 TLDR: GreyNoise is exposing a new internally developed tool, Sift, to the public for the first time. Sift curates a report of new/interesting traffic observed by GreyNoise sensors daily after doing much of the analysis and triage work itself. No

Explore this link on the map →

related reading