{"repo":"JoasASantos/n8n-CyberSecurity-Workflows","free":true,"listed":false,"github":"https://github.com/JoasASantos/n8n-CyberSecurity-Workflows","clone":"git clone https://github.com/JoasASantos/n8n-CyberSecurity-Workflows.git","description":"Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.","language":null,"stars":948,"topics":["appsec","blue-team","cybersecurity","n8n","n8n-workflow","red-team","security-automation","n8n-cybersecurity"],"license":"MIT","category":"workflow-automation","readme_excerpt":"🚀 100 n8n Cybersecurity Workflow Ideas Automation blueprints for Red Team & Pentest , Blue Team (SOC/DFIR/TI) , Application Security (AppSec/DevSecOps) , and Platform/General Security — all using n8n . Each idea lists Purpose , Integrations , and a Flow Outline you can translate into n8n nodes (HTTP Request, Execute Command, IF/Switch, Function, Code, Split In Batches, Merge, Set, Move Binary Data, Wait, Cron, Webhook, Email/Slack/Teams, PostgreSQL/MongoDB/Redis, AWS, GCP, Azure, RabbitMQ, Kafka, etc.). --- Index - A. Red Team & Pentest (30) - B. Blue Team / SOC / DFIR (35) - C. Application Security / DevSecOps (25) - D. Platform & General Security (10) - E. Reference Integrations - F. Import & Build Tips - G. License --- A. Red Team & Pentest (30) 1) Automated Subdomain Recon Hub Purpose: Consolidate subdomain intel continuously. Integrations: Subfinder/Amass (Exec), DNSDB/PassiveTotal (HTTP), Shodan/Censys, Slack, PostgreSQL. Flow: Cron → Exec(Subfinder/Amass) → HTTP(DNS/Passive) → HTTP(Shodan/Censys) → Merge/Unique → DB upsert → Slack summary. 2) Attack Surface Change Detector Purpose: Detect new hosts/ports/services vs last run. Integrations: Nmap/Naabu/Masscan (Exec), Diff (Function), Jira/Slack. Flow: Cron → Exec(scan) → Compare with last snapshot (DB) → Create Jira issues per delta → Slack alert. 3) Cloud Bucket Finder (S3/GCS/Azure) Purpose: Enumerate public buckets & misconfigs. Integrations: AWS/GCP/Azure APIs, HTTP HEAD/GET, Slack, CSV export. Flow: Cron → List bu","default_branch":null,"files":null,"tree":[],"storefront":"/r/JoasASantos","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JoasASantos/n8n-CyberSecurity-Workflows/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}