v1

latestOpenAPI 3.0.0Proprietary2026-07-244990150.4 KB
IP Lookup

IP Lookup - Multi

Retrieves information about the submitted set of IP addresses from the Internet Scanner and Business Service intelligence datasets (consolidated response based on subscription entitlements). Returns time ranges, IP metadata (network owner, ASN, reverse DNS pointer, country), associated actors, tags, raw port scan data, web request information, classification and/or trust level, and provider information.

Use the quick parameter to return a subset of the response fields, for a faster response time.

Can process up to 10,000 IPs per request.

post/v3/ip

Query parameters

quickboolean

If true, the response will only include the IP address and the classification or trust level.

workspace_labelsstring
Example:greynoise,community

Comma-separated list of dataset scopes to include in the query. When omitted, only the default GreyNoise global dataset is queried.

Allowed values:

  • greynoise: GreyNoise's global dataset.
  • community: Aggregated community-contributed data.
  • personal: The authenticated caller's own workspace data. Requires an authenticated workspace.

Enforcement varies by endpoint; see each operation's response codes:

  • GET /v3/ip/{ip} and POST /v3/ip return 403 Forbidden when any value is supplied without the Community Dataset entitlement. Values are not validated server-side; unrecognized values yield empty results rather than an error.
  • GET /v3/noise/ips/{ip}/timeline returns 400 Bad Request for unrecognized values and for personal without an authenticated workspace. The Community Dataset entitlement is not enforced on this endpoint.

Request body

ipsstring[] required

Example request

{
  "ips": [
    "8.8.8.8"
  ]
}

Response

OK - request successful.

OR

Example response

{
  "data": [
    {
      "ip": "8.8.8.8",
      "business_service_intelligence": {
        "found": true,
        "category": "hosting",
        "name": "example.com",
        "description": "example.com",
        "last_updated": "2025-01-15T12:30:45Z",
        "reference": "https://example.com",
        "trust_level": "1"
      },
      "internet_scanner_intelligence": {
        "ip": "71.6.135.131",
        "seen": true,
        "classification": "benign",
        "first_seen": "2018-01-28",
        "last_seen": "2018-02-28",
        "last_seen_timestamp": "2025-01-15T12:30:45Z",
        "found": true,
        "actor": "Shodan.io",
        "spoofable": true,
        "cves": [
          "CVE-2020-1234",
          "CVE-2021-2345"
        ],
        "vpn": true,
        "vpn_service": "IPVANISH_VPN",
        "metadata": {
          "source_country": "United States",
          "source_country_code": "US",
          "source_city": "Seattle",
          "region": "Seattle",
          "organization": "DigitalOcean, LLC",
          "rdns": "crawl-66-249-79-17.googlebot.com",
          "asn": "AS521",
          "asn_subnet": "203.0.113.0/24",
          "category": "education",
          "os": "Windows 7/8",
          "destination_countries": [
            "Germany"
          ],
          "destination_country_codes": [
            "Germany"
          ],
          "destination_cities": [
            "Berlin"
          ],
          "destination_asns": [
            "AS1234"
          ],
          "single_destination": true,
          "carrier": "AIS",
          "datacenter": "us-west-1",
          "domain": "example.com",
          "rdns_parent": "example.com",
          "rdns_validated": true,
          "latitude": 37.7749,
          "longitude": -122.4194,
          "sensor_count": 10,
          "sensor_hits": 10
        },
        "tags": {
          "id": "ef0cc90d-d80c-436f-92c5-3d8f8665c9ac",
          "slug": "mirai",
          "name": "Mirai",
          "category": "worm",
          "intention": "malicious",
          "description": "This IP address exhibits behavior that indicates it is infected with Mirai or a Mirai-like variant of malware.",
          "references": [
            "https://en.wikipedia.org/wiki/Mirai_(malware)"
          ],
          "cves": [
            "CVE-2020-1234"
          ],
          "created_at": "2020-04-07",
          "updated_at": "2020-04-07"
        },
        "raw_data": {
          "scan": [
            {
              "port": 80,
              "protocol": "TCP"
            }
          ],
          "ja3": [
            {
              "fingerprint": "c3a6cf0bf2e690ac8e1ecf6081f17a50",
              "port": 443
            }
          ],
          "hassh": [
            {
              "fingerprint": "51cba57125523ce4b9db67714a90bf6e",
              "port": 2222
            }
          ],
          "http": {
            "md5": "9764955b67107eeb9edfae76f429e783",
            "cookie_keys": [
              "expremotekey"
            ],
            "request_authorization": [
              "Bearer exampletoken",
              "Basic username:password"
            ],
            "request_cookies": [
              "session_id=1234567890"
            ],
            "request_header": [
              "Content-Type: application/json",
              "Accept: application/json"
            ],
            "method": [
              "GET",
              "POST",
              "PUT",
              "DELETE"
            ],
            "request_origin": [
              "111.111.1.1"
            ],
            "host": [
              "example.com",
              "example.com:8080"
            ],
            "path": [
              "/robots.txt"
            ],
            "useragent": [
              "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)\n"
            ],
            "ja4h": [
              "ge11cn060000_4e59edc1297a_4da5efaf0cbd"
            ]
          },
          "tls": {
            "cipher": "TLS_AES_128_GCM_SHA256",
            "ja4": [
              "t13d1516h2_8daaf6152771_02713d6af862"
            ]
          },
          "ssh": {
            "key": [
              "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1234567890"
            ],
            "ja4ssh": [
              "c76s76_c71s59_c0s0"
            ]
          },
          "tcp": {
            "ja4t": [
              "64240_2-1-3-1-1-4_1460_8"
            ],
            "ja4l": "1460_64"
          },
          "source": {
            "bytes": 1024
          }
        }
      }
    }
  ],
  "request_metadata": {
    "restricted_fields": [
      "ip",
      "cve",
      "destination_cities"
    ],
    "message": "ok"
  }
}