SecOps Workflows
What are SecOps n8n workflows?
SecOps n8n workflows are reusable automation templates for secops use cases. This category includes workflows that connect apps, transform data, trigger notifications, sync records, and reduce repetitive manual work. Each listing includes workflow metadata, author attribution, complexity level, relevant categories, source links when available, and a downloadable JSON file for inspection before import. Use this page to compare templates, identify the tools involved, and choose a workflow that fits your workspace before testing it safely in n8n.
Notify user in Slack of quarantined email and create Jira ticket if opened
This n8n workflow serves as an incident response and notification system for handling potentially malicious emails fl...
Monitor security advisories
This n8n workflow automates the monitoring and notification of Palo Alto Networks security advisories. It is triggere...
Analyze CrowdStrike detections - Search for IOCs in VirusTotal - Create a ticket in Jira, and post a message in Slack
This n8n workflow automates the handling of security detections from CrowdStrike, streamlining incident response and...
URL and IP lookups through Greynoise and VirusTotal
This n8n workflow serves as a powerful cybersecurity and threat intelligence tool to look up URLs or IP addresses thr...
Send TheHive alerts using SIGNL4
This sample workflow allows you to forward alerts from TheHive 5 to SIGNL4 in order to send reliable alerts to your t...
Analyze emails with S1EM
With workflow, you analyze Email with TheHive/Cortex https://github.com/V1D1AN/S1EM/wiki/Soar guide 
Get the job details using the Cortex node

Create, update and get a case in TheHive

Encrypt some data using the crypto node
Companion workflow for Crypto node docs
Report phishing websites to Steam and 托管平台
Webhook to report through Mailgun phishing websites to Steam and 托管平台 (if the domain is on 托管平台) You have to set the...