Skip to content

Repository files navigation

Project-02-Automated-Threat-Detection

SOC Automation | N8N Workflow + Virus Total API | AI Threat Classification | Real-Time IP Analysis | HTML Alert Reports | CRITICAL severity confirmed for 6 attacker IP's

N8n Workflow + VirusTotal API + AI Classification

About This Project

An automated SOC threat detection workflow built using N8n that takes a suspicious IP address as input, queries VirusTotal API automatically in real time, uses AI classification logic to determine threat severity, generates a professional HTML alert report and provides SOC analyst recommendation instantly. This automates what a Tier 1 SOC analyst does manually — checking suspicious IPs against threat intelligence feeds. What takes hours manually now takes seconds automatically.

Tools and Technologies

Tool Purpose
N8n Cloud Visual workflow automation platform
VirusTotal API v3 IP reputation and threat intelligence
JavaScript Data processing and severity classification
HTML / CSS Professional alert report generation

Workflow Architecture

Step Node Action
1 Manual Trigger Start the workflow
2 HTTP Request Query VirusTotal API with suspicious IP
3 Code in JavaScript Extract data and classify threat severity
4 HTML Template Generate professional SOC alert report

Node 2 — HTTP Request Configuration

Setting Value
Method GET
URL https://www.virustotal.com/api/v3/ip_addresses/{IP}
Authentication None
Header Name x-apikey
Header Value VirusTotal API Key
Send Headers ON — enabled

AI Severity Classification Logic

Severity Condition Recommendation
CRITICAL 10+ malicious vendors BLOCK immediately at firewall
HIGH 5-9 malicious vendors Block — highly suspicious
MEDIUM 1-4 malicious vendors Investigate further
LOW-MEDIUM 1+ suspicious only Monitor closely
LOW 0 detections No action required

Test Results — Project 01 Attacker IPs

All IPs tested were discovered during Project 01 Real World Threat Hunting — 84 external IPs that launched 12,431 RDP brute force attacks:

IP Address Project 01 Attacks Country Owner Severity
195.3.222.252 879 attempts Netherlands Serverius CRITICAL
193.34.212.189 863 attempts Germany Combahton GmbH CRITICAL
149.50.101.27 861 attempts Unknown Unknown CRITICAL
149.50.116.7 859 attempts Unknown Unknown CRITICAL
38.225.206.208 679 attempts Unknown Unknown CRITICAL
194.165.16.165 669 attempts Monaco Flyservers S.A. CRITICAL

All 6 IPs confirmed CRITICAL by VirusTotal — validating all Project 01 threat hunting findings!

Workflow Output Fields

Field Example Value Description
ip_address 194.165.16.165 Analyzed IP address
severity CRITICAL Classified threat level
malicious_vendors 15+ Vendors flagging as malicious
suspicious_vendors 3 Vendors flagging as suspicious
harmless_vendors 60+ Vendors flagging as harmless
country Monaco (MC) IP geolocation country
owner Flyservers S.A. IP owner from WHOIS
recommendation BLOCK immediately SOC action recommendation
scan_time 3/21/2026 7:25 AM Timestamp of analysis

Connection to Project 01

Project Action Connection
Project 01 Found 84 attacker IPs in 40,372 Sysmon logs Identified IPs to investigate
Project 02 Auto-investigated IPs via VirusTotal API Confirmed all as CRITICAL threats

Complete SOC workflow: Project 01 = Detection → Project 02 = Automated Investigation → Report.

What I Learned

• How to build automated SOC workflows using N8n visual workflow platform.

• How to integrate VirusTotal threat intelligence API using HTTP Request node.

• How to write JavaScript for data processing and extraction in N8n Code nodes.

• How to implement AI-style severity classification logic for threat scoring.

• How to generate dynamic HTML alert reports from JSON threat data.

• How automation reduces manual SOC analyst workload from hours to seconds.

• How threat intelligence feeds work in enterprise security operations.

• How to connect two projects — threat hunting feeds into automation.

• How VirusTotal API v3 structures IP reputation data in JSON format.

• How modern SOC teams use SOAR for Security Orchestration Automation Response.

Project Progress

Project Topic Status
Project 01 Real World Threat Hunting — Splunk Complete
Project 02 Automated Threat Detection — N8n + AI Complete

■■ About Me

Transitioning from Food Technology into Cybersecurity with a focus on SOC Analysis and Blue Team operations. This lab documents my hands-on learning journey.

"The best SOC analyst automates the repetitive and focuses on what matters most."

About

Project 02 — SOC Automation | N8N Workflow + Virus Total API | AI Threat Classification | Real-Time IP Analysis | HTML Alert Reports | CRITICAL severity confirmed for 6 attacker IP's

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages