Automate Threat Intelligence Ingestion and Triage with OpenAI and Email Alerts
This workflow automates the ingestion of threat intelligence from CVE and IOC feeds, evaluates risks using OpenAI, and sends actionable alerts via email.
The workflow begins by scheduling a daily trigger to fetch threat intelligence data from CVE and IOC feeds. It merges and processes this data, leveraging OpenAI for risk evaluation and triage. Based on the evaluation, the workflow decides whether to send alerts via email or log them into Google Sheets. This setup is ideal for blue teams and SOC analysts looking to streamline their threat response processes.
- Platform
- n8n
- Category
- Development & IT
- Price
- $14.99
- Creator
- Amara Nwosu
- Threat Intake
- (ACSC E8 + ISM-Aligned)
- if
- code
- merge
- switch
- splitOut
- emailSend
- stickyNote
- httpRequest
How to import this workflow into n8n
- 1Purchase or download the workflow to get the n8n workflow JSON file.
- 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
- 3Open each node marked with a credential warning and connect your own accounts and API keys.
- 4Run the workflow once manually to verify the data flow, then toggle it to Active.
Related Development & IT workflows
- Create daily historical AI videos with Gemini, fal.ai, Telegram and YouTube$14.99
- Advanced multi-agent AI personal assistant with 250+ task capabilities (WhatsApp + GPT)$2.99
- Send Organized Security CVE Digests from NVD with AI-Polished Summaries to Gmail$4.99
- Learn n8n basics in 3 easy steps ✨$14.99
- Automated multi-platform sales agent with RAG, CRM & payment processing$2.99
- Version Control n8n Workflows in GitLab with Custom and Organization$14.99
More from Amara Nwosu
Need this deployed? We'll set it up for you.
Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.