{"repo":"inthecyber-group/securityonion-n8n-workflows","free":true,"listed":false,"github":"https://github.com/inthecyber-group/securityonion-n8n-workflows","clone":"git clone https://github.com/inthecyber-group/securityonion-n8n-workflows.git","description":"Threat Intelligence Analysis workflows built with n8n and integrated in SecurityOnion","language":null,"stars":37,"topics":["blueteam","n8n","security-operations-center","securityonion","threat-intelligence"],"license":"GPL-3.0","category":"workflow-automation","readme_excerpt":"Automated Threat Intelligence Analysis with n8n and SecurityOnion This project aims to enhance the efficiency of threat intelligence analysis through the implementation of automated workflows using n8n, integrated within Security Onion. The primary goal is to streamline the initial alert triage process, enabling SOC analysts to conduct their analyses with greater simplicity and speed. The workflows are designed to support the analytical skills of SOC analysts, ensuring that they can focus on critical decision-making rather than getting bogged down in repetitive tasks. While the current workflows may lack strict input validation, the emphasis has been on functionality and rapid deployment for internal use. Recognizing the value and impact of automation in the SOC environment, this project is committed to exploring additional automation opportunities to further improve operational capabilities. Any contribution, feedback or idea is welcome. You can find a more detailed explanation of this project in our blog post. Technical Details workflows/IP Reputation.json is the IP workflow described in the blog post. workflows/Hash Reputation.json is the Hash workflow described in the blog post. workflows/Domain Reputation.json is the Domain workflow described in the blog post. workflows/CVE Info.json is the CVE Info workflow described in the blog post. workflows/Dispatcher.json is the Dispatcher workflow described in the blog post. We used a self-hosted instance of n8n 1.123.26 and Secur","default_branch":null,"files":null,"tree":[],"storefront":"/r/inthecyber-group","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/inthecyber-group/securityonion-n8n-workflows/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}