SOC Automation | N8N Workflow + Virus Total API | AI Threat Classification | Real-Time IP Analysis | HTML Alert Reports | CRITICAL severity confirmed for 6 attacker IP's
An automated SOC threat detection workflow built using N8n that takes a suspicious IP address as input, queries VirusTotal API automatically in real time, uses AI classification logic to determine threat severity, generates a professional HTML alert report and provides SOC analyst recommendation instantly. This automates what a Tier 1 SOC analyst does manually — checking suspicious IPs against threat intelligence feeds. What takes hours manually now takes seconds automatically.
| Tool | Purpose |
|---|---|
| N8n Cloud | Visual workflow automation platform |
| VirusTotal API v3 | IP reputation and threat intelligence |
| JavaScript | Data processing and severity classification |
| HTML / CSS | Professional alert report generation |
| Step | Node | Action |
|---|---|---|
| 1 | Manual Trigger | Start the workflow |
| 2 | HTTP Request | Query VirusTotal API with suspicious IP |
| 3 | Code in JavaScript | Extract data and classify threat severity |
| 4 | HTML Template | Generate professional SOC alert report |
| Setting | Value |
|---|---|
| Method | GET |
| URL | https://www.virustotal.com/api/v3/ip_addresses/{IP} |
| Authentication | None |
| Header Name | x-apikey |
| Header Value | VirusTotal API Key |
| Send Headers | ON — enabled |
| Severity | Condition | Recommendation |
|---|---|---|
| CRITICAL | 10+ malicious vendors | BLOCK immediately at firewall |
| HIGH | 5-9 malicious vendors | Block — highly suspicious |
| MEDIUM | 1-4 malicious vendors | Investigate further |
| LOW-MEDIUM | 1+ suspicious only | Monitor closely |
| LOW | 0 detections | No action required |
All IPs tested were discovered during Project 01 Real World Threat Hunting — 84 external IPs that launched 12,431 RDP brute force attacks:
| IP Address | Project 01 Attacks | Country | Owner | Severity |
|---|---|---|---|---|
| 195.3.222.252 | 879 attempts | Netherlands | Serverius | CRITICAL |
| 193.34.212.189 | 863 attempts | Germany | Combahton GmbH | CRITICAL |
| 149.50.101.27 | 861 attempts | Unknown | Unknown | CRITICAL |
| 149.50.116.7 | 859 attempts | Unknown | Unknown | CRITICAL |
| 38.225.206.208 | 679 attempts | Unknown | Unknown | CRITICAL |
| 194.165.16.165 | 669 attempts | Monaco | Flyservers S.A. | CRITICAL |
All 6 IPs confirmed CRITICAL by VirusTotal — validating all Project 01 threat hunting findings!
| Field | Example Value | Description |
|---|---|---|
| ip_address | 194.165.16.165 | Analyzed IP address |
| severity | CRITICAL | Classified threat level |
| malicious_vendors | 15+ | Vendors flagging as malicious |
| suspicious_vendors | 3 | Vendors flagging as suspicious |
| harmless_vendors | 60+ | Vendors flagging as harmless |
| country | Monaco (MC) | IP geolocation country |
| owner | Flyservers S.A. | IP owner from WHOIS |
| recommendation | BLOCK immediately | SOC action recommendation |
| scan_time | 3/21/2026 7:25 AM | Timestamp of analysis |
| Project | Action | Connection |
|---|---|---|
| Project 01 | Found 84 attacker IPs in 40,372 Sysmon logs | Identified IPs to investigate |
| Project 02 | Auto-investigated IPs via VirusTotal API | Confirmed all as CRITICAL threats |
• How to build automated SOC workflows using N8n visual workflow platform.
• How to integrate VirusTotal threat intelligence API using HTTP Request node.
• How to write JavaScript for data processing and extraction in N8n Code nodes.
• How to implement AI-style severity classification logic for threat scoring.
• How to generate dynamic HTML alert reports from JSON threat data.
• How automation reduces manual SOC analyst workload from hours to seconds.
• How threat intelligence feeds work in enterprise security operations.
• How to connect two projects — threat hunting feeds into automation.
• How VirusTotal API v3 structures IP reputation data in JSON format.
• How modern SOC teams use SOAR for Security Orchestration Automation Response.
| Project | Topic | Status |
|---|---|---|
| Project 01 | Real World Threat Hunting — Splunk | Complete |
| Project 02 | Automated Threat Detection — N8n + AI | Complete |
Transitioning from Food Technology into Cybersecurity with a focus on SOC Analysis and Blue Team operations. This lab documents my hands-on learning journey.
- ■ LinkedIn: linkedin.com/in/saravanan-cyber
- ■ Email: career.entrydesk@gmail.com
- ■ Thiruvallur, Tamil Nadu, India
"The best SOC analyst automates the repetitive and focuses on what matters most."