πŸ”’ Malicious file detection & response: Wazuh to VirusTotal with Slack alerts

⚑ 2,643 views Β· πŸ”’ SecOps & Security Automation

Description

Malicious File Detection & Threat Summary Automation using Wazuh + VirusTotal + n8n

This workflow helps SOC teams automate the detection and reporting of potentially malicious files using Wazuh alerts, VirusTotal hash validation, and integrated summary/report generation. It’s ideal for analysts who want instant context and communication for file-based threats β€” without writing a single line of code.


What It Does

When Wazuh detects a suspicious file:


Tech Stack Used


Ideal Use Case

This template is designed for security teams looking to automate file threat triage, IOC validation, and alert-to-ticket escalation, with zero human delay.


Included Nodes


Tips

πŸ”— Nodes Used

HTTP Request, Slack, Webhook, Gmail, ServiceNow

πŸ“₯ Import

Download workflow.json and import into n8n: Workflow menu β†’ Import from File

πŸ“– Importing guide Β· πŸ”‘ Credential setup