Suspicious Login Detection and Threat Alert Workflow

Monitors suspicious login events via webhook, analyzes IP with GreyNoise, geolocation, and user agent data, then alerts via Slack and email if threats detected.

n8n
Suspicious Login Detection and Threat Alert Workflow

This n8n workflow automates security monitoring for suspicious login attempts. Triggered manually or by webhook, it extracts key data like IP, user agent, timestamp, URL, and user ID from the payload. It then branches into three parallel paths: querying GreyNoise Community API for IP reputation and assigning alert priority (High/Medium/Low) based on noise/riot classification before notifying via Slack; fetching geolocation via IP-API and merging with UserParser data for user agent insights; and directly parsing IP/user agent via UserParser API.

Data from all paths merges, and the workflow checks GreyNoise fields for unknown threats. If detected, it queries the last 10 login records for the user from a Postgres database. Discrepancies in location, device, or browser trigger an email notification to the user, enabling rapid incident response.

Benefits include real-time threat prioritization, enriched IP intelligence, and automated alerts, reducing manual investigation time. Ideal for universities or IT teams securing login systems against brute-force, anomalous access, or scanner activity. Use cases: campus authentication monitoring, research lab access protection, or integrating with SIEM tools for scalable security ops.

$24.99
Last updated October 3, 2026
30-day money-back guarantee
Instant download
Lifetime updates included

New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.

Secure checkout powered by Stripe

Support

How to import this workflow into n8n

  1. 1Purchase or download the workflow to get the n8n workflow JSON file.
  2. 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
  3. 3Open each node marked with a credential warning and connect your own accounts and API keys.
  4. 4Run the workflow once manually to verify the data flow, then toggle it to Active.

Related Education workflows

More from Nikolai Vos

Need this deployed? We'll set it up for you.

Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.