Auto CVE & IOC Feed Ingestor with OpenAI Risk Triage & Email Alerts

Go to Workflow
2 views
Built by Adnan Tariq Adnan Tariq
Created on June 07, 2026

Description

How it works
This Blue Team workflow ingests threat intelligence from public CVE and IOC feeds, merges the data, performs automated triage using OpenAI, and routes actionable alerts via email.

📥 CVE and IOC feeds pulled from trusted sources
🤖 AI node evaluates risk severity and recommends response
🧠 Playbook logic determines whether to notify, monitor, or isolate
📧 Alerts sent to email and also logged to Google Sheets
🧱 Built with modular, no-code logic for maximum clarity

Set up steps
Add your OpenAI API key in the AI nodes
Configure your email in the Gmail node
Update Google Sheets credentials and sheet ID
(Optional) Add a Cron or Webhook trigger to automate intake

Requirements
• OpenAI API key
• Gmail credentials
• Google Sheets access
• Internet connection

Who’s it for
• Blue teamers
• SOC analysts
• Cybersecurity students
• SME defenders using no-code tooling

This template is part of the CYBERPULSE AI BlueOps Lite & Pro plans.
Visit cyberpulsesolutions.com/blueops for the full bundle.

Nodes Used (4)

Code
n8n-nodes-base.code
Google Sheets
n8n-nodes-base.googleSheets
HTTP Request
n8n-nodes-base.httpRequest
Send Email
n8n-nodes-base.emailSend