šŸ”’ SecOps & Security Automation

182 templates — šŸ”’ Security operations, threat detection, vulnerability scanning, compliance monitoring, and incident response.

ā¬…ļø Back to main index

šŸ“‹ Templates

TemplateDescriptionšŸ”— Key NodesšŸ‘€ Views
šŸ† Phishing analysis - URLScan.io and VirusTotalThis n8n workflow automates the analysis of email messages received in a Microsoft Outlook inbox to identify indicators of compromise (IOCs), specifically suspicious URLs. It can be triggered manua…HTTP Request, Slack, Microsoft Outlook, urlscan.io, Filter67,029
šŸ„‡ WebSecScan: AI-powered website security auditorThis n8n workflow provides comprehensive website security analysis by leveraging OpenAI’s models to detect vulnerabilities, configuration issues, and security misconfigurations. The workflow genera…HTTP Request, Gmail, AI Agent, OpenAI Chat Model, n8n Form Trigger31,104
🄈 Intelligent AI digest for security, privacy, and compliance feedsHow it worksRSS Read, Gmail, Schedule Trigger, Filter, AI Agent, Google Gemini Chat Model19,960
šŸ„‰ Analyze email headers for IP reputation and spoofing detection - GmailThis workflow is ideal for IT professionals, security analysts, and organizations looking to enhance their email security practices. It is particularly useful for those who need to analyze Gmail em…HTTP Request, Webhook, Gmail Trigger18,735
Ssl expiry alert with SSL-Checker.ioManaging SSL certificates manually can be time-consuming and error-prone, often leading to unexpected downtime or security risks due to expired certificates.Google Sheets, HTTP Request, Gmail, Schedule Trigger16,782
Weekly Shodan query - report accidentsThis n8n workflow, which runs every Monday at 5:00 AM, initiates a comprehensive process to monitor and analyze network security by scrutinizing IP addresses and their associated ports. It begins b…HTTP Request, TheHive, Markdown, Schedule Trigger, Filter14,399
Automate SIEM alert enrichment with MITRE ATT&CK, Qdrant & Zendesk in n8nThis workflow is ideal for:Google Drive, Zendesk, AI Agent, Embeddings OpenAI, OpenAI Chat Model, Simple Memory14,300
Website scam risk detector with GPT-4o and SerpAPIThis intelligent workflow simplifies the complex task of determining whether a website is legitimate or potentially a scam. By simply submitting a URL through a form, the system initiates a multi-a…AI Agent, OpenAI Chat Model, SerpApi (Google Search), n8n Form Trigger13,485
Monitor data breaches in real-time with Have I Been PwnedchangelogHTTP Request, Schedule Trigger, Read/Write Files from Disk, Convert to File, Extract from File11,829
URL and IP lookups through Greynoise and VirusTotalThis n8n workflow serves as a powerful cybersecurity and threat intelligence tool to look up URLs or IP addresses through industry standard threat intelligence vendors. It starts with either a form…HTTP Request, Slack, Webhook, Gmail, Filter, n8n Form Trigger9,811
Analyze & sort suspicious email contents with ChatGPTThis workflow is tailored for IT security teams, managed service providers (MSPs), and organizations aiming to streamline the detection and reporting of phishing emails. It’s especially useful for …HTTP Request, Jira Software, Gmail Trigger, Convert to File, Microsoft Outlook Trigger, OpenAI8,781
Automated URL phishing & threat analysis with NixGuard AIStop manually checking suspicious links. This free n8n workflow provides the foundation for a powerful, automated URL analysis pipeline. Using the NixGuard AI engine, you can instantly analyze susp…Slack, Webhook, Execute Sub-workflow7,843
Comprehensive SSL certificate monitoring with Discord alerts and Notion integration!Screenshot 20250704 at 18.13.54.pngHTTP Request, Discord, Notion, SSH, Schedule Trigger7,587
Analyze emails with S1EMWith workflow, you analyze Email with TheHive/CortexEmail Trigger (IMAP), Start, Cortex, TheHive7,330
Suspicious login detectionThis n8n workflow is designed for security monitoring and incident response when suspicious login events are detected. It can be initiated either manually from within the n8n UI for testing or auto…HTTP Request, Postgres, Slack, Webhook, Gmail7,242
OTX & OpenAI web security checkInput: A user provides a website URL via a simple web form.HTTP Request, Gmail, AI Agent, OpenAI Chat Model, n8n Form Trigger6,997
Monitor security advisoriesThis n8n workflow automates the monitoring and notification of Palo Alto Networks security advisories. It is triggered manually from within the n8n UI or scheduled to run daily at midnight using th…RSS Read, Jira Software, Gmail, Customer Datastore (n8n training), Schedule Trigger, Filter6,726
Analyze CrowdStrike detections - Search for IOCs in VirusTotal - Create a ticket in Jira, and post a message in SlackThis n8n workflow automates the handling of security detections from CrowdStrike, streamlining incident response and notification processes. The workflow is triggered daily at midnight by the Sched…HTTP Request, Slack, Jira Software5,804
šŸ—² Creating a Secure Webhook - MUST HAVEThis workflow demonstrates a fundamental pattern for securing a webhook by requiring an API key. It acts as a gatekeeper, checking for a valid key in the request header before allowing the request …HTTP Request, Webhook, Filter5,599
Analyze email headers for IP reputation and spoofing detection - OutlookThis workflow is ideal for security teams, IT Ops professionals, and managed service providers (MSPs) responsible for monitoring and validating email traffic. It’s especially useful for organizatio…HTTP Request, Webhook, Microsoft Outlook Trigger5,361
Analyze email headers for IPs and spoofingThis n8n workflow is designed to analyze email headers received via a webhook. The workflow splits into two main paths based on the presence of the received and authentication results headers.HTTP Request, Webhook5,071
Analyze suspicious email contents with ChatGPT VisionThis workflow is designed for IT teams, security professionals, and managed service providers (MSPs) looking to automate the process of detecting, analyzing, and reporting phishing emails.HTTP Request, Jira Software, Gmail Trigger, Microsoft Outlook Trigger, OpenAI4,718
Ssl certificate expiry notifier (no paid APIs)Great — here’s a complete Workflow Description for your n8n Creator submission based on the JSON you shared:Send Email, Google Sheets, HTTP Request, Schedule Trigger4,383
Track CVE vulnerability details & history with NVD API and Google SheetsNVD (National Vulnerability Database) data is essential for security analysts, vulnerability managers, and DevSecOps professionals who need to perform both CVE lookups and monitor historical change…Google Sheets, HTTP Request, Webhook3,785
Parse DMARC reports, save them in database and notify on DKIM or SPF errorIf you are a postmaster or you manage email server, you can set up DKIM and SPF records to ensure that spoofing your email address is hard. On your domain you can also set up DMARC record to receiv…Email Trigger (IMAP), Send Email, Rename Keys, Slack, MySQL, Extract from File3,493
Create executive security briefings with NixGuard AI & Wazuh alertsDrowning in security alerts? Spending hours translating technical logs from Wazuh, your SIEM, or other tools into business-friendly reports for leadership? This n8n workflow is your automated Secur…Send Email, Execute Sub-workflow, Schedule Trigger3,483
Get real-time security insights with NixGuard RAG and Wazuh integrationEffortlessly integrate NixGuard API into your n8n workflows for real-time security insights using your API key. This connector enables seamless interaction with Nix, providing rapid Retrieval-Augme…HTTP Request, Execute Workflow Trigger, Chat Trigger3,340
Monitor SSL certificate of any domain with uProcDo you want to check the SSL certificate expiration dates of your customers or servers?Function Item, Start, Telegram, uProc2,991
Qualys vulnerability trigger scan subWorkflow- Trigger: Launched by a parent workflow through a Slack shortcut with modal input.HTTP Request, Slack, Execute Workflow Trigger2,941
MFA multi-factor authentication (Voice call and Email) with ClickSend and SMTPThis workflow automates the process of sending voice calls for verification purposes and combines it with email verification. It uses the ClickSend API for voice calls and integrates with SMTP for …Send Email, HTTP Request, n8n Form Trigger, n8n Form2,810
Network vulnerability scanner with NMAP and automated CVE reportingThis n8n workflow provides comprehensive network vulnerability scanning with automated CVE enrichment and professional report generation. It performs Nmap scans, queries the National Vulnerability …Send Email, Webhook, Telegram, Schedule Trigger, n8n Form Trigger, Read/Write Files from Disk2,707
Malicious file detection & response: Wazuh to VirusTotal with Slack alertsThis workflow helps SOC teams automate the detection and reporting of potentially malicious files using Wazuh alerts, VirusTotal hash validation, and integrated summary/report generation. It’s idea…HTTP Request, Slack, Webhook, Gmail, ServiceNow2,643
Audit Google Drive file permissions for access control managementFile Sharing Permissions are routinely abused when access needs and scopes expand to many colleagues, clients and users. Often, granting excessively open permissions means you can get back to work …Google Sheets, Google Drive, Gmail, Schedule Trigger, Filter2,516
Filter cybersecurity news for your tech stack (OpenAI + Pinecone RAG)Collects cybersecurity news from trusted RSS feeds and uses OpenAI’s Retrieval-Augmented Generation (RAG) capabilities with Pinecone to filter for content that is directly relevant to your organiza…RSS Read, Gmail, Schedule Trigger, AI Agent, Embeddings OpenAI, OpenAI Chat Model2,275
Receive and analyze emails with rules in Sublime SecurityThis n8n workflow provides a comprehensive automation solution for processing email attachments, specifically targeting enhanced security protocols for organizations that use platforms like Outlook…Email Trigger (IMAP), HTTP Request, Slack, Convert to/from binary data2,271
Monitor SSL certificate expiry with Google Sheets and multi-channel alertThis workflow is ideal for administrators or IT professionals responsible for monitoring SSL certificates of multiple websites to ensure they do not expire unexpectedly.Google Sheets, HTTP Request, Telegram, Gmail, Schedule Trigger2,116
AI-powered vulnerability scanner with Nessus, risk triage & Google Sheets reportingSecurity teams, DevOps engineers, vulnerability analysts, and automation builders who want to eliminate repetitive Nessus scan parsing, AI-based risk triage, and manual reporting. Designed for orgs…Send Email, Function, Google Sheets, HTTP Request, Schedule Trigger2,098
Create, update and get a case in TheHive!workflow-screenshotStart, TheHive2,051
AI privacy-minded router: PII detection for privacy, security, & complianceOrganizations need AI capabilities while ensuring:AI Agent, Ollama Chat Model, Simple Memory, Chat Trigger, OpenRouter Chat Model2,042
Slack webhook - verify signatureThis template will help you verify that incoming calls from a Slack webhook actually come from Slack and not some unknown third-party services.Stop and Error, Execute Workflow Trigger2,035
Encrypt some data using the crypto nodeCompanion workflow for Crypto node docsStart2,025
Notify user in Slack of quarantined email and create Jira ticket if openedThis n8n workflow serves as an incident response and notification system for handling potentially malicious emails flagged by Sublime Security. It begins with a Webhook trigger that Sublime Securit…HTTP Request, Slack, Webhook, Jira Software2,005
Generate, retrieve and download a report using the SecurityScorecardThis workflow allows you to generate, retrieve and download a report using the SecurityScorecard node.Start, SecurityScorecard2,004
Automate Wazuh alert triage and reporting with GPT-4o-mini and TelegramThis n8n workflow supercharges your SOC by fully automating triage, analysis, and notification for Wazuh alerts—blending event-driven automation, OpenAI-powered contextual analysis, and real-time c…Webhook, Telegram, Summarization Chain, OpenAI Chat Model1,941
AI-Powered Vendor Policy & RSS Feed Analysis with Integrated Risk ScoringA dual-engine, AI-driven n8n workflow that automates the monitoring of both vendor policy webpages and compliance-related RSS feeds. It intelligently detects recent updates, evaluates their potenti…HTTP Request, RSS Read, Gmail, Schedule Trigger, Filter, AI Agent1,937
Cybersecurity assistant with GPT-4, Telegram bot & command executionQuantumDefender AI is a next-generation intelligent cybersecurity assistant designed to harness the symbolic strength of quantum computing’s promise alongside cutting-edge AI capabilities. This sop…Telegram, Telegram Trigger, AI Agent, OpenAI Chat Model, Simple Memory, Calculator1,878
IP reputation check & SOC alerts with Splunk, VirusTotal and AlienVaultThis workflow automates IP reputation analysis using Splunk alerts, enriches data via VirusTotal and AlienVault OTX, and generates actionable threat summaries for SOC teams — all without any coding.HTTP Request, Slack, Webhook, Gmail, ServiceNow1,877
Automate free IP analysis: NixGuard AI summaries & Wazuh integrationStop wasting time manually investigating suspicious IP addresses. This workflow template is your launchpad to automating real-time IP cybersecurity analysis using the NixGuard platform, which you c…Slack, Webhook, Execute Sub-workflow1,813
Subdomain enumeration with Subfinder, HTTPX & GPT-4-Mini for security reconnaissanceGenerates a wordlist of 1,000–15,000 subdomains created by an AI agent by correlating detected technologies and recurring patterns.HTTP Request, Webhook, SSH, Convert to File, Extract from File, Summarize1,807
Report phishing websites to Steam and CloudFlareWebhook to report through Mailgun phishing websites to Steam and CloudFlare (if the domain is on CloudFlare)Mailgun, Start, Webhook1,713
Monitor software compliance with Jamf patch summaries in Slack🧩 Jamf Patch Summary to SlackHTTP Request, Slack, Filter1,673
Automated SSL Certificate Monitoring and Renewal with Notion and TelegramAutomatically fetch existing domains from Notion’s Database and verify the validity of SSL certificates through SSL-Checker. If the validity period is less than 14 days, send a Telegram message not…HTTP Request, Telegram, Execute Sub-workflow, Notion, SSH, Execute Workflow Trigger1,569
Automated CVE scanning of Bug Bounty programs with Nuclei and Project DiscoveryAutomates daily CVE-driven scanning against bug bounty scopes. It fetches bug-bounty domains, pulls newly published Project Discovery templates, converts them to Nuclei rules, runs targeted scans, …HTTP Request, Gmail, SSH, Schedule Trigger, Filter, Convert to File1,401
Automate security alert triage with NixGuard AI and route to Slack or JiraAre you drowning in a sea of security notifications? Do your analysts spend more time sifting through low-level logs than investigating real threats? This workflow transforms n8n into an autonomous…Slack, Execute Sub-workflow, Schedule Trigger1,393
Complete guide to setting up and generating TOTP codes in n8n šŸ”1. Receive the QR Code from the 2FA serviceTOTP1,373
AI-powered domain & IP security check automation!AI5.png!AI4.pngGoogle Sheets, HTTP Request, Schedule Trigger, AI Agent, Simple Memory, OpenRouter Chat Model1,363
Web security scanner for OWASP compliance with Markdown reportsHow the n8n OWASP Scanner Works & How to Set It UpHTTP Request, Gmail, n8n Form Trigger, Convert to File1,340
Enhance security operations with the Qualys Slack shortcut bot!!n8nHTTP Request, Webhook, Execute Sub-workflow1,299
Qualys scan Slack report subworkflowThis workflow is a sub workflow of the Qualys Slack Shortcut Bot workflow. It is triggered when someone fills out the modal popup in slack generated by the Qualys Slack Shortcut Bot.HTTP Request, Slack, Execute Workflow Trigger1,255
Scan URLs for security threats with urlscan.io and GPT-4o mini• Webhook → urlscan.io → GPT-4o mini → GmailWebhook, Gmail, urlscan.io, OpenAI1,228
Automated GitHub scanner for exposed AWS IAM keysThis n8n workflow automatically scans GitHub for exposed AWS IAM access keys associated with your AWS account, helping security teams quickly identify and respond to potential security breaches. Wh…HTTP Request, Slack1,223
JavaScriptSentry: detect sensitive information in JavaScriptThis workflow contains community nodes that are only compatible with the self-hosted version of n8n.Gmail, AI Agent, OpenAI Chat Model, n8n Form Trigger1,186
Save Qualys reports to TheHive!n8nHTTP Request, Execute Sub-workflow, n8n, Schedule Trigger, Filter, TheHive 51,182
Automate AI vulnerability monitoring with GPT-4 and ServiceNow incident creationThis n8n workflow automatically monitors RSS feeds for the latest AI vulnerability news, extracts key threat details, and creates a corresponding Security Incident in ServiceNow for each item.RSS Read, ServiceNow, Schedule Trigger, OpenAI Chat Model, Information Extractor, Jina AI1,161
Manage group members in Bitwarden automaticallyThis workflow allows you to create a group, add members to the group, and get the members of the group.Bitwarden1,141
Venafi Cloud Slack cert botVenafi Presentation - Watch VideoHTTP Request, Slack, Webhook, Execute Sub-workflow, Venafi TLS Protect Cloud, OpenAI1,103
Automate CVE monitoring with OpenAI processing for ServiceNow security incidentsThis n8n workflow automatically fetches the latest CVE data at scheduled intervals, extracts relevant security details, and creates a corresponding Security Incident in ServiceNow for each new vuln…HTTP Request, ServiceNow, Schedule Trigger, OpenAI Chat Model, Information Extractor1,094
Monitor authentication IPs from SaaS alerts & email reports via SMTP2GoThis n8n workflow automates the process of collecting sign-in IP addresses from SaaS Alerts over the past 24 hours and emailing the results using SMTP2Go. Designed for security teams, IT administra…HTTP Request, Convert to/from binary data, n8n Form Trigger, Convert to File1,086
šŸ› ļø TheHive tool MCP serverNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger1,081
Automated lead generation & qualification with Google Maps, GPT-4 & HubSpotThis n8n workflow automates CVE tracking by retrieving vulnerability details from the NVD API šŸ›”ļø, organizing and updating the data in Google Sheets šŸ“Š, and optionally alerting teams via Slack or Ema…Google Sheets, HTTP Request, Slack, HubSpot, OpenAI1,038
Prevent prompt injection attacks with a GPT-4O security defense systemProtect your AI workflows from prompt injection attacks, XSS attempts, and malicious content with this multi-layer security sanitization system.Send Email, Webhook, OpenAI1,015
Detect multi-source transaction fraud and reconcile finances with OpenAI, Nvidia NIM, Gmail, Slack and Google SheetsThis workflow automates financial transaction surveillance by monitoring multiple payment systems, analyzing transaction patterns with AI, and triggering instant fraud alerts. Designed for finance …HTTP Request, Postgres, Slack, Webhook, Gmail, Schedule Trigger1,013
Send TheHive alerts using SIGNL4This sample workflow allows you to forward alerts from TheHive 5 to SIGNL4 in order to send reliable alerts to your team.Start, Webhook, SIGNL4, TheHive1,012
Receive updates when an event occurs in TheHive!workflow-screenshotStart, TheHive Trigger1,005
Monitor new CVEs for bug bounty hunting with Gemini AI and Slack alertsAutomatically monitors NIST’s CVE database every hour for new vulnerabilities and uses AI to assess their relevance for bug bounty hunting, delivering actionable intelligence directly to Slack.HTTP Request, Slack, Schedule Trigger, AI Agent, Google Gemini Chat Model995
Automated security alert analysis with Sophos, Gemini AI, and VirusTotalThis workflow automates the analysis of security alerts from Sophos Central, turning raw events into actionable intelligence. It uses the official Sophos SIEM integration tool to fetch data, enrich…HTTP Request, Webhook, Telegram, AI Agent, Simple Memory, Google Gemini Chat Model975
Get the job details using the Cortex node!workflow-screenshotStart, Cortex909
Monitor CISA critical vulnerability alerts with RSS feed & Slack notificationsThis concise workflow efficiently captures, filters, and delivers crucial cybersecurity-related mentions.Slack, RSS Feed Trigger879
Auto remediate endpoint infections with Wazuh, ClamAV, and GPT-4Reduce human delays between malware detection and remediation in MSSP/SOC environments. This workflow automates full endpoint antivirus scanning immediately after high-severity endpoint infection w…Webhook, Telegram, SSH, AI Agent, Summarization Chain, OpenAI Chat Model873
Security reconnaissance with Google Dorks, Parsera scraping, and Gmail reportsThis workflow contains community nodes that are only compatible with the self-hosted version of n8n.Gmail, n8n Form Trigger838
Scan single URLs for security vulnerabilities with GPT-4 (JS, PHP, Python)This workflow automates static security analysis for JavaScript, PHP, and Python codebases.Google Drive, Filter, AI Agent, OpenAI Chat Model, n8n Form Trigger830
Automated AWS IAM key compromise response with Slack & Claude AIThis n8n workflow provides a secure, enterprise-grade response system for AWS IAM access key compromises with built-in form submission and human approval mechanisms. When an AWS access key is suspe…HTTP Request, Slack, AI Agent, Anthropic Chat Model, n8n Form Trigger, AWS IAM817
Fraudulent booking detector: Identify suspicious travel transactions with Google GeminiThis automated n8n workflow detects and manages fraudulent booking transactions through comprehensive AI-powered analysis and multi-layered security checks. The system processes incoming travel boo…Google Sheets, HTTP Request, Webhook, Gmail, AI Agent, Google Gemini Chat Model810
Extract actionable security insights from HackerOne reports with Google GeminiA streamlined AI-powered tool that extracts actionable technical insights from HackerOne security reports for advanced bug bounty hunters.AI Agent, Chat Trigger, Google Gemini Chat Model773
Monitor cybersecurity brand mentions on X and send alerts to SlackThis concise workflow efficiently captures, filters, and delivers crucial cybersecurity-related mentions.Slack, X (Formerly Twitter), Schedule Trigger751
Automate external attack surface mapping with Shodan API and DNS lookupsThe Bug Bounty Target Recon n8n workflow is a powerful automation tool for security professionals and ethical hackers.Google Sheets, HTTP Request741
Automate regulatory compliance monitoring with ScrapeGraphAI and email alertsThis workflow automatically monitors government regulatory changes and provides comprehensive compliance tracking and executive alerts.Send Email, Schedule Trigger737
New TheHive case Slack notification bot!theHiveHTTP Request, Slack, Webhook, TheHive 5, TheHive 5 Trigger694
Check suspicious links via Telegram with GPT-4 analysis of VirusTotal & urlscan.io resultsThe workflow is designed to scan submitted URLs using urlscan.io and VirusTotal, combine the results into a single structured summary, and send the report via Telegram.Google Sheets, HTTP Request, Telegram, Telegram Trigger, urlscan.io, AI Agent690
Send organized security CVE digests from NVD with AI-polished summaries to GmailSummaryHTTP Request, Gmail, Schedule Trigger, OpenAI669
Monitor VPS security with GPT-4 mini analysis via SSH and Telegram alertsThis n8n template automatically monitors your VPS for suspicious processes and network connections using AI analysis. It connects to your server via SSH, analyzes running processes, and sends Teleg…Telegram, SSH, Schedule Trigger, Basic LLM Chain, OpenAI Chat Model, Structured Output Parser653
IP threat intelligence report generator with VirusTotal, OpenAI and Google DocsCybersec IP Intelligence GathererHTTP Request, Google Docs, AI Agent, OpenAI Chat Model, n8n Form Trigger643
Validate TOTP token (without creating a credential)This template allows you to verify if a 6-digit TOTP code is valid using the corresponding TOTP secret. It can be used in an authentication system.629
Monitor SSL certificate expiry with Google Sheets and email alertsThis n8n template automatically monitors SSL certificates of websites listed in a Google Sheet and sends email alerts if any are expiring within 14 days. It helps ensure you avoid downtime, securit…Send Email, Google Sheets, HTTP Request, Schedule Trigger620
Monitor domains & IPs on AbuseIPDB blacklist with Slack alertsThe automated blacklist monitor is designed to be a proactive, not reactive, tool. Here is the high-level process:HTTP Request, Slack, Schedule Trigger523
IP geolocation & HTTP port scanning with Google SheetsThis n8n template automatically enriches IP addresses with geolocation data and performs HTTP port scanning when new IPs are added to a Google Sheets document. Perfect for network monitoring, secur…Google Sheets, HTTP Request, Google Sheets Trigger513
Automated weekly security audit reports with Gmail deliveryThis workflow automatically generates and emails a comprehensive security audit report for your N8N instance every week. It identifies potential security risks related to:Cron, Gmail, n8n474
Automate CVE detection with AI-powered Nuclei template generation & Google DriveAutomates collection, technical extraction, and automatic generation of Nuclei templates from public CVE PoCs.HTTP Request, Google Drive, SSH, Schedule Trigger, AI Agent, OpenAI Chat Model431
Proxy detection by IP2Proxy - MCP serverComplete MCP server exposing 1 IP2Proxy Proxy Detection API operations to AI agents.MCP Server Trigger428
IAM compliance automation: enforce MFA and clean up access keys in AWS> This workflow leverages AWS IAM APIs and n8n automation to ensure strict security compliance by continuously monitoring IAM users for MFA (Multi-Factor Authentication) enforcement.HTTP Request, Slack, Schedule Trigger, Filter, AWS IAM407
Generate security vulnerability reports with Google Dorks, SerpAPI and PDF4meHow it Works:Gmail, n8n Form Trigger372
Intelligent real-time financial fraud detection and risk scoring engineAutomates fraud risk detection for financial transactions by analyzing real-time webhook events through AI-powered scoring. Target audience: fintech companies, payment processors, and banking teams…Send Email, Google Sheets, HTTP Request, Slack, Webhook, AI Agent370
Triage AWS security misconfigurations with GPT-4.1 Mini and send alerts to GmailAutomatically triages risky AWS misconfigurations and alerts your team.Airtable, HTTP Request, Webhook, Gmail, OpenAI368
Monitor security logs for failed login attempts with Slack alertsThis workflow efficiently processes logs to detect anomalies.HTTP Request, Slack, Schedule Trigger348
Kubernetes deployment & pod monitoring with Telegram alerts- Open the ā€œKubeconfig Setupā€ nodeWrite Binary File, Telegram, Schedule Trigger346
File hash verification for AI agents with hashlookup CIRCL APIComplete MCP server exposing 11 hashlookup CIRCL API operations to AI agents.MCP Server Trigger342
Automated DNS records lookup for subdomains with HackerTarget API reports🧠 EnumX: Auto DNS Lookup for Subdomains with Markdown ExportHTTP Request, Gmail335
Monitor remote server file integrity with SSH and Slack alertsThis workflow efficiently performs a scheduled file integrity audit.Cron, Slack, SSH334
Auto-renew AWS certificates with Slack approval workflow- SRE/DevOps teams managing many ACM certs.Slack, AWS Certificate Manager, Schedule Trigger, Filter317
šŸ› ļø Elastic Security Tool MCP Server šŸ’Ŗ all 14 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger290
Monitor & alert on inactive AWS IAM users with Slack notifications> Weekly job that finds IAM users with no activity for > 90 days and notifies a Slack channel.HTTP Request, Slack, Schedule Trigger, Filter, AWS IAM278
Monitor email data breaches with HIBP API and send Slack alertsThis workflow efficiently performs a scheduled data breach scan.HTTP Request, Slack, Schedule Trigger272
SSL/TLS certificate expiry monitor with Slack alertThis workflow efficiently monitors your domains for certificate expiry.HTTP Request, Slack, Schedule Trigger248
Scan URLs with urlscan.io and send results via GmailReceive a URL via Webhook, submit it to urlscan.io, wait ~30 seconds for artifacts (e.g., screenshot), then email a clean summary with links to the result page, screenshot, and API JSON.Webhook, Gmail, urlscan.io245
AI-powered security analysis for n8n with Google Gemini and n8n audit APIThis workflow provides a deep-dive security assessment of an n8n instance using the native Audit API and AI analysis.HTTP Request, Basic LLM Chain, Structured Output Parser, n8n Form Trigger, Google Gemini Chat Model, n8n Form244
BlueOps Auto CVE & IOC feed ingestor with OpenAI risk triage & email alertsThis Blue Team workflow ingests threat intelligence from public CVE and IOC feeds, merges the data, performs automated triage using OpenAI, and routes actionable alerts via email.Send Email, Google Sheets, HTTP Request, Schedule Trigger235
Send Slack alerts for AWS IAM access keys older than 365 daysWatch the videoHTTP Request, Slack, Schedule Trigger, Filter, AWS IAM226
Cyberpulse AI GRC: Automate security questionnaire responsesDescriptionGoogle Sheets, Webhook, Google Drive, Gmail, OpenAI199
šŸ› ļø Microsoft Entra ID tool MCP server šŸ’Ŗ all 12 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger196
Secure user emails with AES-256 encryption and verification systemProfessional-Grade AES-256 Data Protection for n8n182
Monitor SSL certificates for brand-impersonating domains with crt.sh, Urlscan.io and SlackThis workflow monitors SSL certificate logs to find and scan new domains that might be impersonating your brand.HTTP Request, Slack, urlscan.io, Schedule Trigger177
šŸ› ļø Microsoft Graph Security Tool MCP server šŸ’Ŗ all 5 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger177
šŸ› ļø MISP tool MCP server šŸ’Ŗ all 44 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger168
Automated Wazuh rule deployment pipeline with GitHub, XML validation & Telegram alertsšŸš€ Say Goodbye to Manual Rule Deployments in Wazuh!Github Trigger, HTTP Request, Telegram, SSH158
Real-time security threat dashboard with Google Sheets, AI risk analysis & email alertsšŸ‘¤ Who it’s forSend Email, Google Sheets, HTTP Request, Schedule Trigger158
šŸ› ļø Okta tool MCP server šŸ’Ŗ all 5 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger154
Monitor SSL certificate expiry dates with Google Sheets & Slack alerts> āš ļø Notice:Google Sheets, Slack, Schedule Trigger149
Automated APK security scanning & PDF reporting with MobSF, AI & Google DriveThis workflow automatically analyzes any newly uploaded APK file and produces a clean, professional PDF security report. When an APK appears in Google Drive, the workflow downloads it, sends it to …HTTP Request, Google Drive, Google Drive Trigger, OpenAI143
Auto-classify security incidents with GPT-4 and Google Sheets for SOC teamsBlue Team leads, SOC analysts, and IT responders looking to automatically classify security alerts using AI-driven logic and asset-based risk signals.Google Sheets, HTTP Request, Schedule Trigger138
šŸ› ļø SecurityScorecard tool MCP server šŸ’Ŗ all 19 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger135
Export Jamf policies to Slack as CSV for instant auditingQuickly export and review your entire Jamf policy configuration—including triggers, frequencies, and scope—directly in Slack.HTTP Request, Slack, Webhook, Convert to File133
Automate cybersecurity incident response with Claude AI, VirusTotal and SlackThis workflow automates end-to-end cybersecurity incident response by ingesting alerts from multiple sources, enriching threat intelligence, assessing severity with Claude AI, executing containment…Google Sheets, HTTP Request, Webhook, AI Agent, Anthropic Chat Model131
šŸ› ļø Bitwarden tool MCP server šŸ’Ŗ all 19 operationsNeed help? Want access to this workflow + many more paid workflows + live Q&A sessions with a top verified n8n creator?MCP Server Trigger131
Monitor zero-day threats with Anthropic Claude, Airtable, Slack and JiraThis workflow continuously monitors CVE databases, threat intelligence feeds, and public security advisories to surface emerging zero-day threats, correlates them against your registered infrastruc…Airtable, Send Email, Google Sheets, HTTP Request, Webhook, Schedule Trigger130
n8n enterprise AI security firewall — guardrails for secure agentsThis workflow provides a complete testing rig for evaluating text against seven essential AI guardrails used in production systems.Google Sheets, Google Gemini Chat Model, Guardrails124
CYBERPULSE AI RedOps: internal phishing simulation for security trainingSimulate phishing awareness campaigns using OpenAI-generated emails. Send to target lists, log clicks with a webhook, and store results in Google Sheets. Built for internal testing and cyber awaren…Google Sheets, Webhook, Gmail, AI Agent, OpenAI Chat Model123
Automate vulnerability triage from Snyk with Jira, Slack & Airtable integrationThis workflow receives vulnerability data(e.g., Snyk, Dependabot or any security scanner) from Snyk through a webhook, standardizes and validates the payload, checks Jira for duplicates using a uni…Airtable, Function, Slack, Webhook, Jira Software122
Monitor compliance with GPT-4 analysis of system logs and generate audit reportsThis solution centralizes communication data from Slack, Microsoft Teams, Gmail, and GitHub into a unified AI-powered analysis and documentation workflow for teams managing distributed knowledge. M…HTTP Request, Gmail, Schedule Trigger, AI Agent, OpenAI Chat Model, Structured Output Parser117
CYBERPULSE AI GRC: automate PCI DSS control evaluation and compliance trackingDescriptionGoogle Sheets, Filter116
Automated failed login detection with Jira tasks, Slack alerts & Notion loggingWebhook: Failed Login Attempts → Jira Security Case → Slack WarningsFunction, Slack, Webhook, Jira Software, Notion116
Discord server anti-impersonation / scammer tracker with data tablesThis n8n template demonstrates how to automatically monitor and track username and nickname changes across your Discord server members. Perfect for community moderation, security monitoring, and ma…Discord, Schedule Trigger, Data table104
Monitor SSL certificate expiry with Google Sheets and SMTP email alertsDevOps engineers, sysadmins, and website owners who manage multiple domains and need proactive SSL certificate expiration monitoring without manual checks.Send Email, Google Sheets, Schedule Trigger98
Automate security incident response with Google Sheets, email alerts and EDR isolationšŸ‘¤ Who it’s forSend Email, Google Sheets, HTTP Request, Schedule Trigger92
Monitor cybersecurity compliance and send weekly reports via SIEM, Jira, PostgreSQL, Slack and emailThis n8n workflow automates continuous compliance monitoring across IT, OT, and cloud environments by aggregating security controls, validating policies (ISO 27001, NIST, GDPR, SOC2), detecting ano…Send Email, HTTP Request, Postgres, Schedule Trigger, Filter91
Track software security patents with ScrapeGraphAI, Notion, and Pushover alerts!Workflow Preview ImageHTTP Request, Pushover, Notion, Schedule Trigger91
CYBERPULSE AI redOps: credential trap sim: fake login page simulationSimulate a phishing login page to test user behavior and SOC response. This controlled workflow sends trap links to predefined targets and logs simulated interaction results—without capturing real …Google Sheets86
CYBERPULSE AI redOps: phishing simulation with redirect trackingSimulate cloaked phishing links that redirect through a controlled proxy. This module tracks if secure email gateways (SEGs) or sandboxes trigger the redirect before users do. Logs access, response…Google Sheets85
Aggregate endpoint security risk scores with EDR, vulnerability data & Google SheetsšŸ‘¤ Who it’s forCron, Function, Google Sheets, HTTP Request85
Monitor Zoho CRM changes & alert on suspicious activity with Google SheetsThis n8n workflow automatically monitors selected Zoho CRM modules for record changes, identifies suspicious modification patterns, logs all activity into a Google Sheet, generates an audit JSON fi…Function, Google Sheets, HTTP Request, Gmail84
CYBERPULSE AI BlueOps: asset enrichment enginešŸ‘¤ Who it’s forCron, Send Email, Function, Google Sheets82
CYBERPULSE AI RedOps: generate daily RedOps security simulation reportsAutomatically compiles a daily HTML report of all RedOps simulations (Modules 1–5), summarizing offensive activity, response logs, and module effectiveness. Designed for GRC teams, Red/Purple teams…Google Sheets, Gmail79
Monitor PKI certificates & CRLs for expiration with Telegram & SMS alertsThis n8n workflow provides automated monitoring of Public Key Infrastructure (PKI) components including CA certificates, Certificate Revocation Lists (CRLs), and associated web services. It extract…HTTP Request, Write Binary File, Schedule Trigger70
Check phishing URL reputation with VirusTotal and log to Google SheetsThis n8n template helps you automatically analyze URLs for phishing and malicious activity using VirusTotal’s multi-engine threat intelligence platform. It validates incoming URLs, submits them for…Google Sheets, HTTP Request, Webhook69
Verify property ownership with blockchain, GPT-4 fraud detection, and compliance trackingThis workflow automates property registration verification, fraud detection, and blockchain-based compliance tracking by systematically assessing fraud risk, validating transactions, ensuring data …Google Sheets, HTTP Request, Webhook, AI Agent, OpenAI Chat Model, Structured Output Parser68
Orchestrate security vulnerability remediation with Port, OpenAI, Jira and SlackComplete security workflow from vulnerability detection to automated remediation, with severity-based routing and full organizational context from Port’s catalog. This template provides end-to-end …HTTP Request, Slack, Webhook, Jira Software, OpenAI65
Monitor Jamf policy integrity and send Slack alerts for changesšŸ›”ļø Jamf Policy Integrity MonitorHTTP Request, Slack, Webhook, Schedule Trigger, Data table62
Automate risk treatment tasks with Google Sheets for GRC complianceDescriptionGoogle Sheets, Schedule Trigger62
CYBERPULSE AI RedOps: validate email security gateways generated payloadsDescription:Google Sheets, OpenAI61
Track policy expiry dates and ownership with Google Sheets and Gmail notificationsPurposeGoogle Sheets, Gmail60
Report spam and phishing URLs from IMAP mailboxes to SpamhausThis workflow automates URL reporting to Spamhaus based on incoming spam/phishing sample emails. It watches one or more IMAP folders, extracts URLs from each email body, removes duplicates and comm…Email Trigger (IMAP), HTTP Request, Filter57
Filter URLs with AI-powered robots.txt compliance & source verificationVersion : 1.0HTTP Request, Postgres, Execute Workflow Trigger, Schedule Trigger, Mistral Cloud Chat Model, Google Gemini Chat Model52
Detect and route cybersecurity threats with SIEM, Slack, email and PagerDutyThis n8n workflow proactively scans and aggregates threat intelligence, network logs, and vulnerability data every 15 minutes to detect emerging risks across the infrastructure. It analyzes anomali…Send Email, HTTP Request, Postgres, Slack, Schedule Trigger50
Secure GET webhooks with query parameter validation for limited authentication casesWebhooks are special URLs that instantly trigger workflows when they receive an incoming HTTP request (like GET or POST). They’re perfect for connecting external tools to n8n in real time.Webhook, Stop and Error50
Run weekly WAF security audits with WAFtester and Slack alertsAutomated weekly WAF security assessments with Slack reporting. Detects your WAF vendor, runs a security assessment, grades your protection, and alerts your team when the grade drops below threshold.HTTP Request, Slack, Schedule Trigger46
Audit Website Security Headers with AI Remediation and Google Sheets ReportingAn automated workflow for auditing website security headers and generatingGoogle Sheets, HTTP Request, Gmail, AI Agent, n8n Form Trigger, OpenRouter Chat Model42
Audit Confluence space permissions and public links for complianceThis workflow scans selected Confluence spaces for public exposure risks, helping teams identify unintended access and potential data leakage.HTTP Request, GraphQL31
Monitor GitHub repo access and push events with GitHub and Slack alertsThis workflow monitors GitHub for high-risk activities to ensure that only authorized users can modify the repository. It periodically polls GitHub for events such as PushEvent, MemberEvent, and Pu…HTTP Request, Slack, Schedule Trigger, Data table30
Prevent phishing emails with GPT-4, VirusTotal, Slack, and Google SheetsThis n8n workflow automates real-time phishing detection by ingesting incoming emails, extracting indicators, analyzing content with AI (GPT-4), calculating risk scores, and taking immediate action…Send Email, Google Sheets, HTTP Request, Webhook, AI Agent, OpenAI Chat Model27
Detect and isolate ransomware with Claude (Anthropic), EDR, SIEM and SlackThis workflow provides real-time detection of ransomware encryption patterns using Claude AI, with automated system isolation and incident response.Send Email, Google Sheets, HTTP Request, Slack, Webhook, AI Agent22
Test WAF security interactively with an AI agent and WAFtester MCPA conversational AI agent that connects to WAFtester via MCP (Model Context Protocol) for interactive Web Application Firewall security testing. Type natural language requests — the agent picks the…AI Agent, OpenAI Chat Model, Chat Trigger, MCP Client Tool20
Detect and route gameplay security anomalies with GPT-4o, Slack and SheetsThis workflow automates cybersecurity incident detection and response for security operations centers (SOCs) managing constant threat landscapes. Designed for security analysts, IT operations teams…Send Email, Google Sheets, Slack, Schedule Trigger, AI Agent, OpenAI Chat Model20
Analyze domain threats via Telegram with VirusTotal, AbuseCH, and Gemini AI!WorkFlow.pngHTTP Request, Telegram, Telegram Trigger, Google Gemini17
Assess credential risk and route mitigation actions with GPT-4o-miniThis workflow automates comprehensive enterprise risk assessment and mitigation planning for organizations managing complex operational, financial, and compliance risks. Designed for risk managers,…AI Agent, OpenAI Chat Model, Structured Output Parser, AI Agent Tool17
Detect transaction fraud and manage compliance with GPT-4 and AirtableThis workflow automates financial transaction monitoring, fraud detection, and regulatory compliance using OpenAI GPT-4 across coordinated specialist agents. It targets compliance officers, fraud a…Airtable, Schedule Trigger, AI Agent, OpenAI Chat Model, Structured Output Parser, AI Agent Tool16
Protect public webhooks with Ainoflow Guard rate limitingStop webhook flooding before it starts. Add production-grade rate limiting to any n8n webhook in minutes - reject abusive traffic before expensive workflow logic executes.HTTP Request, Webhook14
Check file hash reputation with VirusTotal and Slack alertsFile Hash Reputation Checker is a security automation workflow that validates file hashes (MD5, SHA1, SHA256) and checks their reputation using the VirusTotal API. It is designed for SOC teams, sec…HTTP Request, Slack, Webhook9
Enrich IP addresses with country attribution using IPinfo and Slack alertsIP Enrichment & Country Attribution is a lightweight cybersecurity automation that enriches IP addresses with geographic and network intelligence. It validates incoming IPs, filters out private or …HTTP Request, Slack, Webhook8
Audit browser and proxy fingerprint/IP integrity with GPT-4o, Sheets and SlackThis workflow performs a comprehensive security audit on your web scraping infrastructure to detect potential IP leaks or bot detection flags. It iterates through a list of fingerprinting services …Google Sheets, Slack, AI Agent, Structured Output Parser, OpenRouter Chat Model7
Scan Gmail links with VirusTotal and send alerts to WhatsApp, Teams, and SheetsThis n8n workflow is designed for IT security professionals, email administrators, and organizations that want to automatically scan URLs received in emails for potential security threats. It provi…Google Sheets, HTTP Request, Microsoft Teams, Gmail Trigger5
Filter fraudulent leads with GPT-4o-mini, AbstractAPI, Google Sheets and SlackThis n8n template serves as a security layer for your marketing efforts, ensuring that only high-quality, human-verified leads reach your CRM while automatically blacklisting bots and VPN-based sub…Google Sheets, HTTP Request, Slack, Webhook, OpenAI4
Manage vulnerabilities end-to-end with GPT-4, Jira, Slack and Google SheetsAutomates the full vulnerability lifecycle — from scheduled scanning and data aggregation to intelligent prioritization, ticket creation, real-time alerting, weekly reporting, and centralized track…Send Email, Google Sheets, HTTP Request, Webhook, Schedule Trigger, AI Agent4
Detect and enforce abuse cases with OpenAI, Slack, Gmail and SheetsThis workflow automates platform trust and safety operations by deploying a multi-agent AI system that detects abuse signals, investigates behaviour, scores risk, checks policy compliance, and enfo…Send Email, Slack, Webhook, AI Agent, OpenAI Chat Model, Structured Output Parser1

šŸ“„ How to use: Click any template above, then download the workflow.json file and import it into n8n via Workflow menu → Import from File. See the importing guide for detailed instructions.