I will build cybersecurity automation workflows using n8n
Cybersecurity Professional
Über diesen Service
Are manual SOC tasks and alert fatigue slowing down your incident response?
Hi, I'm Kenji, a certified Cybersecurity Professional (CEH, Palo Alto) specializing in Security Operations and Automation. I help security teams, startups, and IT admins streamline their threat response using n8na powerful and cost-effective alternative to expensive SOAR platforms.
What I can automate for you:
- Threat Intelligence Enrichment: Automatically extract IPs, domains, or hashes from alerts and check them against APIs like VirusTotal, AbuseIPDB, or AlienVault.
- Alert Routing & Notifications: Parse complex SIEM logs and send clean, formatted alerts directly to Slack, Telegram, Discord, or Email.
- Data Scraping for Security: Scrape threat feeds or OSINT sources and structure the data for your defensive tools.
- Incident Response Workflows: Create automated actions, such as isolating endpoints or updating firewall blocklists via API.
Why choose me? I don't just connect nodes; I understand the actual cybersecurity context behind the data. I ensure the workflows are secure, scalable, and tailored to your specific incident response playbook.
Please send me a message before ordering so we can discuss your spec
FAQ
Do I need to have n8n already installed?
You can use n8n Cloud, or you can host it yourself. If you need help deploying a self-hosted n8n instance securely (e.g., on Proxmox or Ubuntu with Cloudflare Tunnels), let me know and we can arrange a custom offer!
What kind of security APIs can you integrate with n8n?
I can integrate almost any tool that supports REST APIs or Webhooks. Common integrations include VirusTotal, AbuseIPDB, Shodan, Wazuh, Splunk, Cortex XDR, Slack, and Telegram.
Is it safe to process security logs through n8n?
Yes! Self-hosting n8n is highly recommended for security workflows because your sensitive log data (like IPs or internal hostnames) never leaves your own infrastructure.

