CrowdStrike Detection Analysis: VT IOC Search, Jira Tickets & Slack Alerts
Automates daily analysis of CrowdStrike security detections, enriches with VirusTotal IOC lookups, creates Jira tickets, and notifies via Slack for efficient incident response.
This n8n workflow automates security incident handling from CrowdStrike detections. Triggered daily at midnight via Schedule Trigger, it fetches recent detections using HTTP Request to CrowdStrike API, splits them into individual items, and enriches each with detailed info from another CrowdStrike API call. Processing occurs sequentially via Split In Batches to manage load.
Next, it queries VirusTotal for behavioral data using SHA256 hashes and IOC values through two HTTP Requests, incorporating a 1-second Wait node to avoid rate limiting. Data from CrowdStrike and VirusTotal is then consolidated using Set nodes and Item Lists, capturing key details like detection links, confidence scores, filenames, and usernames.
Finally, for each detection, it creates a Jira issue with severity-based summaries, hostnames, and enriched descriptions, then posts a Slack message to notify users. Benefits include streamlined incident response, reduced manual effort, and proactive threat hunting. Ideal for security teams in IT environments needing automated triage of alerts from EDR tools.
Use cases: Daily security monitoring in enterprises, integrating threat intel platforms like VirusTotal with ITSM (Jira) and collaboration (Slack). Handles potential issues like API rate limits and timezone configs for reliable operation.
New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.
Related bundle
Content Repurposing Engine
8 hand-picked workflows for $29.00.
That is $3.63 each, vs $24.99 for this one alone.
View bundleSecure checkout powered by Stripe
Tags
Support
How to import this workflow into n8n
- 1Purchase or download the workflow to get the n8n workflow JSON file.
- 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
- 3Open each node marked with a credential warning and connect your own accounts and API keys.
- 4Run the workflow once manually to verify the data flow, then toggle it to Active.
Related Crypto & Blockchain workflows
- Real-time Crypto Insights with CoinMarketCap and AI via Telegram$14.99
- Automated Multi-Timeframe Trading Analysis for WEEX Spot Market with GPT-4 and Telegram$24.99
- Automate Crypto News Digest to Telegram with RSS and GPT-4$14.99
- Automate AI-Driven Stock Trading with Alpaca and Google Sheets$14.99
- Automated Crypto RSI Alerts with EODHD and Telegram Integration$9.99
- Automate Binance Spot Trading with Limit and Market Orders$14.99
More from Mateusz Rahman
Need this deployed? We'll set it up for you.
Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.