AutomationMart
Home/Browse/Score DNS threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini
n8n

Score DNS threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini

n8nn8n34 modulesv1.0
GmailGitHubGemini

Score DNS Threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini An end-to-end Cyber Threat Intelligence pipeline that turns raw DNS traffic into actionable security verdicts — without manual triage, without leaking credentials, and without alert fatigue. What this workflow does This workflow ingests passive DNS observations, enriches each indicator with multi-source threat intelligence, and uses Google Gemini as a senior security analyst to produce a single, defensible verdict per indica

At a glance

Score DNS threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini is a ready-made n8n workflow you import as a workflow JSON file — no build required. It connects Gmail, GitHub, Gemini. It's free to download. Follow the 5-step import below to go live in minutes.

Platform
n8n
Connects
Gmail, GitHub, Gemini
Modules
34
Price
Free
Version
v1.0
Score DNS threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini workflow diagram

About this workflow

Score DNS Threats with VirusTotal, Abuse.ch, HashiCorp Vault and Gemini An end-to-end Cyber Threat Intelligence pipeline that turns raw DNS traffic into actionable security verdicts — without manual triage, without leaking credentials, and without alert fatigue. What this workflow does This workflow ingests passive DNS observations, enriches each indicator with multi-source threat intelligence, and uses Google Gemini as a senior security analyst to produce a single, defensible verdict per indicator. Every step that touches a secret pulls it from HashiCorp Vault at runtime, and only confirmed threats reach your inbox. Problems it solves Manual threat triage takes hours. A SOC analyst checking a suspicious indicator across VirusTotal, ThreatFox, and URLhaus, then writing up the verdict, typically spends 10-20 minutes per IoC. This workflow performs the same correlation in seconds and produces a structured report ready for review or downstream automation. Hardcoded credentials are a breach waiting to happen. API keys, database passwords, and provider tokens commonly end up in workflow JSON, environment files, or git history. This workflow fetches every secret directly from HashiCorp Vault during execution, so credentials never live inside n8n configuration. Alert fatigue trains analysts to ignore real threats. The AI agent applies a detection-first scoring model on a 1–5 scale, with email alerts firing only on confirmed malicious indicators (score ≥ 4). Clean traffic and low-signal noise are silently logged for trend analysis, not pushed to the operator. Single-source intelligence is misleading. Indicators flagged by one provider but absent from others are often false positives — and indicators marked clean by one source may already be active C2 infrastructure tracked by another. This workflow correlates across three independent CTI sources before assigning a verdict. Trusted infrastructure produces noise. Cloud providers, CDNs, and developer platforms (AWS, Cloudflare, GitHub, Bitbucket) frequently appear in threat feeds because attackers abuse them — the platforms themselves are not malicious. The scoring model recognizes "big player" infrastructure and caps the score unless a specific malware family is confirmed, eliminating a major source of false positives. How it works The workflow runs as five coordinated stages: 1. Indicator capture. Passive DNS logs are read from MySQL using credentials retrieved from Vault. Indicators that have not yet been analyzed are queued for enrichment. 2. Multi-source enrichment. Three independent CTI branches run in parallel: - VirusTotal — primary source for IP/domain reputation and ownership - ThreatFox (Abuse.ch) — primary source for active C2 infrastructure and malware family attribution - URLhaus (Abuse.ch) — supporting context on URLs historically hosted at the indicator 3. AI-driven verdict. Google Gemini receives the consolidated intelligence, applies a detection-first scoring policy loaded dynamically from the database, and returns a structured JSON verdict including a numeric score, malicious flag, threat label, English technical summary, and Polish operator commentary. 4. Persistence. Results are written to MySQL with full referential integrity, ready for Grafana dashboards or further automation. 5. Conditional alerting. Only indicators with score ≥ 4 trigger an email notification. Email styling adapts to severity: green for informational, amber for review, red for confirmed threats. Architecture components | Layer | Component | Role | |---|---|---| | Traffic source | Passive DNS (MySQL) | Identifies new IoCs from observed network traffic | | Secret engine | HashiCorp Vault | Provides all credentials and API tokens at runtime | | Intelligence | VirusTotal, ThreatFox, URLhaus | Independent CTI sources for cross-validation | | AI reasoning | Google Gemini | Acts as a senior security analyst, correlating data and generating verdicts | | Persistence | MySQL (partitioned) | Stores results with 6-month automated retention | | Alerting | Gmail via SMTP | Severity-aware notifications, only for confirmed threats | Release v1.0.2-rc1 Highlights This is the release candidate for the first stable v1.0.2 build, available on the Cyber Sentinel GitHub repository. - Detection-first scoring (1–5 scale) — replaces the previous 1–10 scale with a clearer mapping to operator actions: Allow, Monitor, Review, Block, Block + Alert. - Dynamic threat scale — score definitions are loaded from the database at every AI invocation, enabling future self-healing workflows that can auto-tune the scoring model. - Source weighting — VirusTotal and ThreatFox drive the score; URLhaus contributes only as a supporting modifier, eliminating false positives on legitimate platforms. - Severity-aware email alerts — color and header adapt to score (green INFO / amber REVIEW / red ALERT) instead of every indicator triggering a red alarm banner. - Partitioned database with automated retention — DNS queries, network events, and threat indicators are partitioned monthly with automatic cleanup after 6 months. - Unified Vault provisioning — single Ansible playbook handles initialization, unsealing, and secret provisioning idempotently. - Full Infrastructure-as-Code deployment — the entire stack (Nginx, Vault, MySQL, MongoDB, n8n) deploys via Ansible with credentials managed through Ansible Vault. - Tested on Proxmox (Debian) and Raspberry Pi 5 — production-grade stability validated on both home-lab and resource-constrained environments. Documentation - GitHub repository: - Project documentation: - Release notes:

n8n

How to import this n8n workflow

  1. 1

    Download the workflow JSON file after purchase.

  2. 2

    Open n8n → click the menu → Import from File.

  3. 3

    Select the downloaded JSON and import.

  4. 4

    Set up credentials for each node that requires them.

  5. 5

    Click Execute Workflow to test, then activate.

Setup guide

Setup guide included

Purchase to unlock the full step-by-step guide

Related N8n workflows

Send emails from Gmail for new Google Calendar events

Every time this scenario is run, Make will automatically send an email via Gmail with a summary of new Google Calendar events to a specified email address.

Free

Automate bug reports with Gemini AI: Jotform to GitHub with Telegram alerts

Execution video: This workflow automates the process of handling bug reports submitted through a form, from checking for duplicates on GitHub to logging the report and sending a notification. --- 1. A Bug is Reported 🐛 Trigger: The entire process kicks off when a user submits a bug report through a JotForm. This form collects the user's name, email, and a description of the bug. --- 2. The AI Agent Gets to Work 🤖 Action: The submitted bug description is sent to an AI Agent powered by Google G

Free

Create GitHub issues from new SuiteCRM 7 campaigns

Every time a new campaign is created in SuiteCRM 7, Make will automatically create a new issue in GitHub.

Free

Automate HS code lookup & enrichment with Google Sheets and customs API (beta)

I used to spend hours every week just copy-pasting product descriptions to find the right tariff codes for our international shipments. It was tedious and prone to errors." - Accounting specialist. This workflow eliminates that manual work entirely. It automatically finds customs tariff numbers (also known as HS Codes or "Zolltarifnummern") for your products and enriches your data in Google Sheets. It offers two powerful modes: bulk processing for entire product lists and an on-demand chat

Free

Add GitHub pull requests as Trello cards

When you have new pull requests in GitHub, this automation will retrieve the requests and creates Trello cards for you.

Free

Automated Instagram comment replies using Gemini AI with context-aware responses

Instagram Auto-Comment Responder with AI Agent Integration Version: 1.1.0 ‧ n8n Version: 1.88.0+ ‧ License: MIT A fully automated workflow for managing and responding to Instagram comments using AI agents. Designed to improve engagement and save time, this system listens for new Instagram comments, verifies and filters them, fetches relevant post data, processes valid messages with a natural language AI, and posts context-aware replies directly on the original post. --- K

Free

Fireflies transcripts to meeting summaries & task extractor to Slack & ClickUp

AI-powered Meeting Summaries and Action Items to Slack and ClickUp How it Works 1. Webhook Trigger: The workflow starts when Fireflies notifies that a transcription has finished. 2. Transcript Retrieval: The transcript is pulled from Fireflies based on the meeting ID. 3. Pre-processing: The transcript is split into sentences and then aggregated into a raw text block. 4. AI Summarization: The aggregated transcript is sent to Google Gemini, which generates a short summary and a structured list

Free

Populate Retell dynamic variables with Google Sheets data for call handling

Overview - This workflow provides Retell agent builders with a simple way to populate dynamic variables using n8n. - The workflow fetches user information from a Google Sheet based on the phone number and sends it back to Retell. - It is based on Retell's Inbound Webhook Call. - Retell is a service that lets you create Voice Agents that handle voice calls simply, based on a prompt or using a conversational flow builder. Who is it for For builders of Retell's Voice Agents who want to make their a

Free

Reviews

No reviews yet

Be the first to buy and share your experience.

Leave a review

Sign in to share your experience with this workflow.

Log in to review
Free
No ratings yet

Create a free account to purchase workflows.

  • JSON blueprint — instant download
  • Setup guide PDF included
  • 5 downloads · valid 30 days
  • Works with n8n

Need help setting this up?

Book a 3-hour live setup session with an Agility consultant.

₹2,499/ session
3 hrs · video call
  • Configure live on Google Meet / Zoom
  • Free follow-up if workflow has defects
  • Platform expert assigned to you
Book installation session
Free