Field intelligence for AI-first professionalsVol. II · Nº 56 · Saturday, August 15, 2026
← The library

232 workflows, ready to run.

Community-built n8n automations, searchable live from the template library. Open one on n8n.io and import the JSON straight into your instance.

Weekly Shodan Query - Report AccidentsThis n8n workflow, which runs every Monday at 5:00 AM, initiates a comprehensive process to monitor and analyze network security by scrutinizing IP addresses and their associated pHTTP Request · TheHive · HTML5.4k views
Receive and analyze emails with rules in Sublime SecurityThis n8n workflow provides a comprehensive automation solution for processing email attachments, specifically targeting enhanced security protocols for organizations that use platfHTTP Request · Slack · Code2k views
Notify User in Slack of Quarantined Email and Create Jira Ticket if OpenedThis n8n workflow serves as an incident response and notification system for handling potentially malicious emails flagged by Sublime Security. It begins with a Webhook trigger thaHTTP Request · Slack · Jira Software · Code1.8k views
Monitor Security AdvisoriesThis n8n workflow automates the monitoring and notification of Palo Alto Networks security advisories. It is triggered manually from within the n8n UI or scheduled to run daily at Jira Software · Gmail · Customer Datastore (n8n training)5.6k views
Analyze CrowdStrike Detections - Search for IOCs in VirusTotal - Create a Ticket in Jira, and Post a Message in SlackThis n8n workflow automates the handling of security detections from CrowdStrike, streamlining incident response and notification processes. The workflow is triggered daily at midnHTTP Request · Slack · Jira Software4.2k views
URL and IP lookups through Greynoise and VirusTotalThis n8n workflow serves as a powerful cybersecurity and threat intelligence tool to look up URLs or IP addresses through industry standard threat intelligence vendors. It starts wHTTP Request · Slack · Gmail · Code8.6k views
Send TheHive Alerts Using SIGNL4This sample workflow allows you to forward alerts from TheHive 5 to SIGNL4 in order to send reliable alerts to your team. There are two nodes for testing the TheHive connection ("SIGNL4 · TheHive897 views
Analyze emails with S1EMWith workflow, you analyze Email with TheHive/Cortex https://github.com/V1D1AN/S1EM/wiki/Soar-guideCortex · TheHive6.9k views
Manage group members in Bitwarden automaticallyThis workflow allows you to create a group, add members to the group, and get the members of the group. Bitwarden node: This node will create a new group called documentation inBitwarden938 views
Generate, retrieve and download a report using the SecurityScorecardThis workflow allows you to generate, retrieve and download a report using the SecurityScorecard node. SecurityScorecard node: This node generates a full scorecard report. BasedSecurityScorecard1.6k views
Monitor SSL certificate of any domain with uProcDo you want to check the SSL certificate expiration dates of your customers or servers? This workflow gets information of an SSL certificate using the uProc Get Certificate by domTelegram · uProc2.7k views
Receive updates when an event occurs in TheHive892 views
Get the job details using the Cortex nodeCortex680 views
Create, update and get a case in TheHiveTheHive1.8k views
Encrypt some data using the crypto nodeCompanion workflow for Crypto node docsCrypto1.7k views
Report phishing websites to Steam and CloudFlareWebhook to report through Mailgun phishing websites to Steam and CloudFlare (if the domain is on CloudFlare) You have to set the Credentials for webhook and Mailgun. You have to Mailgun1.5k views