NeetroX - n8n Cybersecurity Workflows & AI SOC Automation
Practitioner-built n8n cybersecurity workflows, AI SOC analyst templates, and threat intel automation for blue teams. The lightweight SOAR alternative.
Products
- Phishing Email Analyzer — Instant Report Edition · $49.99 [automation] · Turn “Is this email phishing?” into a clear analyst report in under a minute. Stop spending 20 minutes manually checking email headers, suspicious links, attachments, and sender d…
- Wazuh Rule Tuning Automation - Approval-Gated, 81 Nodes · $89.99 [automation] · Automatically tune your noisiest Wazuh rules without letting a script touch your ruleset on its own. One n8n workflow. It profiles your alert noise every night, asks a local LLM h…
- SOC Analyst L1 for Wazuh - Rule-Based, No AI · $49.99 [automation] · An n8n workflow that turns raw Wazuh alerts into finished incident reports verdict, false-positive call, severity, MITRE technique, and a response playbook without a single line g…
- Wazuh UEBA Automation - 30-Day Baselines and Anomaly Reports · $49.99 [automation] · Your SIEM is very good at catching what someone wrote a rule for. It is blind to everything else. It will not tell you that svc-backup has never logged in from that country before…
- Automated Threat Hunting for Wazuh - n8n AI Agent · $49.99 [automation] · Automated Threat Hunting for Wazuh Threat hunting keeps losing to the alert queue. Not because it's difficult, but because it requires a senior analyst and a free afternoon and th…
- Wazuh Multi-Tenant Client Dashboard · $149.99 [tools] · Give every client their own SOC dashboard from the Wazuh you already run Running Wazuh for multiple clients? Then you know the dilemma: the built-in dashboard shows everything to …
- Wazuh Vulnerability Reports - Enriched, Not a Spreadsheet · $39.99 [automation] · Stop copying CVEs into spreadsheets every Monday. Turn your Wazuh vulnerability data into a prioritized patch plan and client-ready report automatically every week. What it does P…
- Monthly Wazuh Reports - Technical and Management PDFs · $39.99 [automation] · Stop spending hours turning Wazuh data into client-ready reports. Automatically turn a full month of Wazuh data into two polished PDF reports — one for security teams and one for …
- AI Chatbot Security Testing Agent - Jailbreaks and Leaks · $29.99 [automation] · Find out how your AI chatbot holds up before attackers do. Run 49 structured attack tests across 16 categories against your chatbot and get a clear, OWASP-mapped security report s…
- AI SOC Analyst L1 for Wazuh - Triage and Incident Reports · $49.99 [automation] · Your Wazuh alerts get investigated and written up before you open your laptop One n8n workflow does the tier-1 job for you: it pulls the context from your Indexer, checks the IP a…
- Vendor Radar - Security Background Check for Any SaaS · $29.99 [automation] · Know the security risk before you trust a new SaaS vendor. Stop relying on a vendor's homepage or a SOC 2 badge alone. Vendor Radar turns a company's domain into a structured secu…
- CVE Explainer and PoC Fetcher - One Lookup, Not Four · $29.99 [automation] · You search the same CVE in four different places. Every time. You get a CVE ID - from a scanner, a Slack alert, a vendor advisory, whatever. Then the tab-hopping starts. NVD for t…
- AI Cybersecurity News Digest - 9 Feeds, One Daily Brief · $29.99 [automation] · You follow 9 security news sites. You read none of them. This workflow reads them all and tells you the one thing that matters today You know the feeling. Ten browser tabs open. T…
- CVE Stack Monitor - CVE Alerts for Your Actual Stack · $29.99 [automation] · CVE Stack Monitor - Know Exactly Which CVEs Are Attacking Your Infrastructure Automatically. Enterprise CVE intelligence platforms cost $200–$2,000/month. This workflow does the s…
- CTI AI Agent - IOC Enrichment with STIX and MITRE Mapping · $49.99 [automation] · Send one indicator. Get a cited verdict, a STIX bundle, and MITRE mapping back in under a minute. The CTI AI Agent enriches any IP, domain, URL, hash, or CVE across six intelligen…
- AI SOC Analyst for Wazuh - Multi-Host Log Pull over SSH · $49.99 [automation] · Your Wazuh alert arrives with the actual log lines already pulled off the server One n8n workflow does the tier-1 job for you. It works out which OS the host runs, logs in over SS…
Latest from the blog
- What Automation Actually Does to a SOC Team [Impact] · 2026-09-01 · About a quarter of security alerts are never investigated, and 60% of teams have had one of those turn into a real incident. Here is what changes when you automate the work, with real numbers.
- n8n Cybersecurity Automation That Does Not Die in Six Months [Insights] · 2026-08-29 · We build security automation for any SIEM, then keep it alive for you
- CTI AI Agent Update: The Before/After of Improving an n8n Workflow for Production [Threat intelligence] · 2026-08-18 · 10 concrete changes, keys out of code, one agent for every IOC type, and the two n8n traps that fail silently.
- Wazuh Rule Tuning Automation Approval-Gated n8n Workflow, 81 Nodes [Rule Tuning] · 2026-08-13 · I let an AI tune my Wazuh rules but only if it asks permission first
- I Automated Threat Hunting on Wazuh with n8n - Here's the Workflow, Node by Node [Threat Hunting] · 2026-07-28 · 31 nodes that run 59 MITRE-mapped hunts every Monday, triage the hits with a local AI, and email one report that opens with the verdict.
- One Wazuh, Many Clients: Why I Built a Multi-Tenant Wazuh Dashboard [Tool] · 2026-07-21 · Wazuh has no clean way to give each client their own view. Here's how I built a multi-tenant Wazuh dashboard with white-label logins without touching the SIEM.
- The Practical Guide to Cybersecurity Automation with Local AI Models [Guide] · 2026-06-30 · After Reading this guide you will understand why local AI matters for security, which models to run, how to run them, how to wire them into n8n, and exactly how to tune them.
- How to Automate a Wazuh Monthly Report (Technical + Management PDFs, Zero Manual Work) [Reporting] · 2026-06-20 · Build an automated Wazuh monthly report in n8n - technical + management PDFs, real charts, MITRE mapping, emailed every month with zero hardcoded data
- AI SOC Agent Pro Edition - Stop Triaging SIEM Alerts Manually [Detection] · 2026-06-17 · I built a 73-node n8n workflow that turns Wazuh alerts into AI-generated incident reports. It runs 100% locally with Ollama
- Deploy Wazuh SIEM at Enterprise Level: Multi-Node Architecture on Ubuntu [Detection] · 2026-06-15 · Build a scalable, enterprise-grade Wazuh deployment with dedicated Indexer, Manager, and Dashboard nodes - the same architecture used to monitor 850+ endpoints in production
- I Spent Days Trying to Break AI Chatbots. Then I Built a Tool That Does It in 5 Minutes. [Pentesting] · 2026-06-05 · Meet the AI Chatbot Security Testing Tool - the fastest way to find out if your assistant is leaking secrets
- I Built an AI SOC Analyst in n8n That Triages Wazuh Alerts For Me - Here’s Every Node, Explained [AI Agent] · 2026-05-31 · How a webhook, a local LLM, and a healthy fear of auto-blocking my own servers turned into a 24/7 tier-1 analyst.
- Automatically Detect New Cyber Threats Before Your Team Reads the News [News] · 2026-05-18 · Stop Scrolling Cybersecurity News: Let This AI Send You Only the Threats That Matter
- Integrating FortiGate Logs with Wazuh [Detection] · 2026-05-05 · Complete Security Monitoring Setup
- AI CTI Agent: Delivers Report & STIX 2.1 Bundles [Automation] · 2026-05-04 · Most CTI workflows are a mess. You get an alert. You copy an IP. You paste it into VirusTotal. You open another tab for AbuseIPDB. You manually check OTX. You try to remember the MITRE technique from…