Threater Announces Integration with GreyNoise to Guard Against False Positives

Threater Newsletter Announcement Graphic

GreyNoise RIOT tool provides Threater with a whitelist data set of 60 million known good IPs

May 09, 2023 09:03 as seen on Business Wire

TYSONS CORNER, Va.–(BUSINESS WIRE)–Today, Threater, the autonomous cyber intelligence and active threat defense platform, and GreyNoise, one of the largest data companies in cybersecurity, announced a partnership that will enhance the Threater platform. By leveraging GreyNoise data, Threater customers now have automatic access to this enhanced cyber intelligence and the largest cyber intelligence data set that protects against false positives.

“False positives can often cause disruptions and wasted time, which can lead to security controls being deactivated and open the floodgates for bad actors,” said Pat McGarry, CTO of Threater. “By incorporating GreyNoise into our platform, we are significantly reducing this risk and are able to mitigate false positives while still maintaining security on the rest of the network. We are excited to make Threater the only security control solution on the market that can ingest this volume of data and operate on it instantaneously to help our customers.”

GreyNoise’s analogous whitelist data set, known as RIOT, enables the Threater platform to monitor 60 million known good IP addresses and reduces the risk of false positives. RIOT, short for “Rule it Out,” informs users about IPs used by common business services that are almost certainly not attacking networks. RIOT enables security practitioners to quickly eliminate logs and events generated from businesses services from their security telemetry. GreyNoise releases updates to this comprehensive RIOT list several times a day to ensure the most current and accurate data is presented to users.

Traditional threat intelligence feeds make an effort to enumerate the locations where the bad guys may be – RIOT is the exact opposite. Threater also has roadmap plans to integrate GreyNoise’s separate malicious data feeds into the platform, allowing its data to enhance Threater’s already-industry-leading ability to identify and block likely malicious traffic in real-time while providing unparalleled false positive protection.

About Threater

Threater is the only active defense cybersecurity platform that fully automates the enforcement, deployment, and analysis of cyber intelligence at a massive scale. As the foundational layer of an active defense strategy, Threater’s patented solution blocks known threats from ever reaching customers’ networks. Threater utilizes immense volumes of cyber intelligence from over 50 renowned security vendors to provide unparalleled visibility over the threat landscape resulting in a more efficient and effective security posture. Security teams at companies of all sizes use Threater to deploy active security, gain real-time network visibility into threats and policy violations, ensure their network is protected, and reduce manual work. Block. Every. Threat. at

About GreyNoise

GreyNoise is THE source for understanding internet noise. We collect, analyze and label data on IPs that saturate security tools with noise. This unique perspective helps analysts waste less time on irrelevant or harmless activity, and spend more time focused on targeted and emerging threats. GreyNoise is trusted by Global 2000 enterprises, government organizations, top security vendors and tens of thousands of threat researchers. For more information, please visit, and follow us on Twitter and LinkedIn.


Erica Stuchel 
W2 Communications