Instant IP address triage in your Slack security channel

By General Input

Paste a suspicious IP into your security channel and get an instant, plain-language verdict on whether it's harmless scanner noise or worth investigating.

Integrations

  • GreyNoise
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering
  • Operations

Trigger this workflow from a Slack message event on our security triage channel, for example #soc-triage. Whenever a new message is posted in that channel, start the workflow and read the full text of the message. If the platform can only trigger on app mentions rather than on every channel message, use an app mention trigger instead, so the workflow fires when an analyst @mentions the bot and includes an IP address. Read and post everything as the Slack bot.

Scan the incoming message text for any IP addresses it contains, covering both IPv4 and IPv6. If the message contains no IP address, stop immediately and do nothing. Do not post any reply in that case, so the channel stays quiet when there is nothing to triage.

For each IP address you find, run a GreyNoise IP Lookup to pull its intelligence. Capture three things: the classification (benign, malicious, suspicious, or unknown), whether the IP is opportunistic internet background noise from mass scanning, and any RIOT business-service context, such as a known Google, AWS, or other common cloud or SaaS service.

Turn the raw GreyNoise data into a short, plain-language verdict for each IP and pick a recommended action an analyst can act on at a glance. For example: 'safe to ignore, this is scanner noise' when the IP is benign internet background noise, 'known business service, likely benign' when RIOT identifies it as a recognized service like Google or AWS, or 'investigate' when it is classified as malicious or suspicious. When GreyNoise has no record of the IP, say it is unknown and lean toward investigate.

Reply in the same thread as the original message using the Slack bot's Send a Message action, with the reply attributed to the bot. Keep it short and skimmable: give one line per IP, leading with the IP address, then the verdict, then the recommended action. If the message mentioned several IP addresses, cover all of them in a single threaded reply.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them