Daily GreyNoise IP reputation sweep in Google Sheets

By General Input

Every morning, check your tracked IP addresses against GreyNoise and write the latest verdict straight back into your spreadsheet automatically.

Integrations

  • GreyNoise
  • Google Sheets

Type

Deterministic Code

Categories

  • Engineering
  • Operations

Build this as a code workflow. Every day at 6am, run a scheduled sweep that reads a list of IP addresses from a Google Sheets tracking sheet, checks them all against GreyNoise in one bulk lookup, and writes the results back into the same rows.

Start with Google Sheets Get Values to read the IP column from a fixed A1 range on the tracking tab (for example firewall blocklist candidates or recently seen source IPs). Treat the first row as a header and collect the IP addresses from the rows below, remembering which spreadsheet row each IP came from so the results land next to the right IP.

Send every IP address in a single GreyNoise Multi IP Lookup request. Multi IP Lookup accepts up to 10,000 IPs per call and returns the same intelligence shape as the single IP Lookup for each one: internet_scanner_intelligence, business_service_intelligence, and a combined classification.

For each IP, build a row of status columns from the response. Include the classification (benign, malicious, suspicious, or unknown); whether the IP is internet background noise, as yes or no from internet_scanner_intelligence.found; the RIOT business-service name if the IP belongs to one, taken from business_service_intelligence (otherwise record 'none'); the last-seen date from the scanner intelligence; and the timestamp of this check, which is the current run time. When GreyNoise has no record of an IP, meaning it is absent from both the scanner and business-service datasets, write 'no data' in the classification column instead of leaving the row blank.

Write everything back with Google Sheets Update Values, overwriting the status columns for every IP on every run so the sheet always reflects GreyNoise's latest verdict. Update the same fixed set of columns each time (classification, internet background noise, business service, last seen, checked at) over the same range. Do not append new rows or shift the existing IP list.

Note on limits: GreyNoise's free Community tier is limited to roughly 50 lookups per week, so sheets with more than a few dozen IPs need a paid GreyNoise plan to cover the daily sweep.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentLocal listing health board for every location you manageLet support send one-off Loops emails without an engineerStop cold emails to anyone with a live deal in PipedriveiMessage campaign console with pre-flight checks and delivery boardLinkedIn Ads budget pacing dashboard for every client accountFront desk appointment confirmation board for the next 3 daysGive your team Looker numbers without buying more seatsBuild audience segments from product usage and push to LoopsTurn the people who engage with your posts into Pipedrive leads