Erstellung detaillierter Sicherheits-Tickets basierend auf SentinelOne-Bedrohungen und MITRE-Analysen

Experte

Dies ist ein SecOps, Multimodal AI-Bereich Automatisierungsworkflow mit 18 Nodes. Hauptsächlich werden Code, Wait, Webhook, SplitOut, HttpRequest und andere Nodes verwendet. Detaillierte Sicherheits-Tickets auf der Grundlage von SentinelOne-Bedrohungen und MITRE-Analyse erstellen

Voraussetzungen
  • HTTP Webhook-Endpunkt (wird von n8n automatisch generiert)
  • Möglicherweise sind Ziel-API-Anmeldedaten erforderlich
Workflow-Vorschau
Visualisierung der Node-Verbindungen, mit Zoom und Pan
Workflow exportieren
Kopieren Sie die folgende JSON-Konfiguration und importieren Sie sie in n8n
{
  "meta": {
    "instanceId": "8d70623c0c9f4448eda9626cd8185192c28447e191325b0c0d94d3f40d23be3a"
  },
  "nodes": [
    {
      "id": "b43d41e4-fd97-4a54-93cd-2197da482a76",
      "name": "Neue SentinelOne-Bedrohung",
      "type": "n8n-nodes-base.webhook",
      "position": [
        80,
        160
      ],
      "webhookId": "3b1d201a-316f-4956-b77a-4d27b268cf1f",
      "parameters": {},
      "typeVersion": 2
    },
    {
      "id": "3267f360-6fae-43e8-86dc-a0c2e037b590",
      "name": "Haftnotiz1",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        -740,
        -140
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "6e7fc0ba-263e-400d-8b22-f502aff3ccf6",
      "name": "Haftnotiz",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        40,
        -160
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "497f3698-9fff-4a06-be29-1f3bd8d54553",
      "name": "Haftnotiz2",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        460,
        -160
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "b238ff4e-997c-4e64-a848-5490531391be",
      "name": "Haftnotiz3",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        920,
        -160
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "d4f07134-ee81-443d-b19a-b2f16266775c",
      "name": "Haftnotiz4",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        2380,
        -140
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "3f59c053-ce4c-452c-b6fd-fb7e7874cdd2",
      "name": "Haftnotiz6",
      "type": "n8n-nodes-base.stickyNote",
      "position": [
        1480,
        420
      ],
      "parameters": {
        "content": ""
      },
      "typeVersion": 1
    },
    {
      "id": "310c22d7-4b8f-459d-8ea2-26b16f8ba3fe",
      "name": "Extract Threat Intelligence",
      "type": "n8n-nodes-base.code",
      "position": [
        300,
        160
      ],
      "parameters": {},
      "typeVersion": 2
    },
    {
      "id": "d9088837-2371-4e06-a71d-93795b94869d",
      "name": "Fetch Autotask Users",
      "type": "n8n-nodes-base.httpRequest",
      "position": [
        520,
        160
      ],
      "parameters": {},
      "typeVersion": 4.2
    },
    {
      "id": "baa5b6d8-7e37-4b6b-81af-6733fc45c61c",
      "name": "Load Client Companies",
      "type": "n8n-nodes-base.httpRequest",
      "position": [
        960,
        160
      ],
      "parameters": {},
      "typeVersion": 4.2
    },
    {
      "id": "332813df-6b24-497d-a53c-eb2544e0c6b7",
      "name": "Process Company Data",
      "type": "n8n-nodes-base.splitOut",
      "position": [
        1400,
        160
      ],
      "parameters": {},
      "typeVersion": 1
    },
    {
      "id": "bb2d1e70-74e1-4f09-af81-af301c852796",
      "name": "Retrieve Ticket Fields",
      "type": "n8n-nodes-base.httpRequest",
      "position": [
        1620,
        160
      ],
      "parameters": {},
      "typeVersion": 4.2
    },
    {
      "id": "d59eff6f-33f6-4c74-93e8-10502ee196bf",
      "name": "Parse Field Options",
      "type": "n8n-nodes-base.code",
      "position": [
        1840,
        160
      ],
      "parameters": {},
      "typeVersion": 2
    },
    {
      "id": "04fb54c0-18c8-47f3-9884-e315451d02f9",
      "name": "Map Client Company",
      "type": "n8n-nodes-base.code",
      "position": [
        2280,
        160
      ],
      "parameters": {},
      "typeVersion": 2
    },
    {
      "id": "cc08de33-66e7-4cba-a4a1-08994fe496f8",
      "name": "Create Security Ticket",
      "type": "n8n-nodes-base.httpRequest",
      "position": [
        2500,
        160
      ],
      "parameters": {},
      "typeVersion": 4.2
    },
    {
      "id": "af7de8b1-c43c-4f9d-bc20-d7f0f63f144c",
      "name": "Rate Begrenzen Delay 1",
      "type": "n8n-nodes-base.wait",
      "position": [
        740,
        160
      ],
      "webhookId": "9d2aea13-8b41-45f7-a875-4042743815dd",
      "parameters": {},
      "typeVersion": 1.1
    },
    {
      "id": "f1e2cb40-c74f-4533-a1af-4ee7f24c5045",
      "name": "Rate Begrenzen Delay 2",
      "type": "n8n-nodes-base.wait",
      "position": [
        2060,
        160
      ],
      "webhookId": "30d29da9-0ce4-4a8a-9b87-a92eee4db5ed",
      "parameters": {},
      "typeVersion": 1.1
    },
    {
      "id": "47cba939-82b5-4f9c-a59a-4e7f7001dc24",
      "name": "Warten",
      "type": "n8n-nodes-base.wait",
      "position": [
        1180,
        160
      ],
      "webhookId": "f240fb70-3d06-4faf-a4bc-9b62a699e198",
      "parameters": {},
      "typeVersion": 1.1
    }
  ],
  "pinData": {},
  "connections": {
    "Wait": {
      "main": [
        [
          {
            "node": "332813df-6b24-497d-a53c-eb2544e0c6b7",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "04fb54c0-18c8-47f3-9884-e315451d02f9": {
      "main": [
        [
          {
            "node": "cc08de33-66e7-4cba-a4a1-08994fe496f8",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "Rate Limit Delay 1": {
      "main": [
        [
          {
            "node": "baa5b6d8-7e37-4b6b-81af-6733fc45c61c",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "Rate Limit Delay 2": {
      "main": [
        [
          {
            "node": "04fb54c0-18c8-47f3-9884-e315451d02f9",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "d59eff6f-33f6-4c74-93e8-10502ee196bf": {
      "main": [
        [
          {
            "node": "Rate Limit Delay 2",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "d9088837-2371-4e06-a71d-93795b94869d": {
      "main": [
        [
          {
            "node": "Rate Limit Delay 1",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "332813df-6b24-497d-a53c-eb2544e0c6b7": {
      "main": [
        [
          {
            "node": "bb2d1e70-74e1-4f09-af81-af301c852796",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "baa5b6d8-7e37-4b6b-81af-6733fc45c61c": {
      "main": [
        [
          {
            "node": "Wait",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "b43d41e4-fd97-4a54-93cd-2197da482a76": {
      "main": [
        [
          {
            "node": "310c22d7-4b8f-459d-8ea2-26b16f8ba3fe",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "bb2d1e70-74e1-4f09-af81-af301c852796": {
      "main": [
        [
          {
            "node": "d59eff6f-33f6-4c74-93e8-10502ee196bf",
            "type": "main",
            "index": 0
          }
        ]
      ]
    },
    "310c22d7-4b8f-459d-8ea2-26b16f8ba3fe": {
      "main": [
        [
          {
            "node": "d9088837-2371-4e06-a71d-93795b94869d",
            "type": "main",
            "index": 0
          }
        ]
      ]
    }
  }
}
Häufig gestellte Fragen

Wie verwende ich diesen Workflow?

Kopieren Sie den obigen JSON-Code, erstellen Sie einen neuen Workflow in Ihrer n8n-Instanz und wählen Sie "Aus JSON importieren". Fügen Sie die Konfiguration ein und passen Sie die Anmeldedaten nach Bedarf an.

Für welche Szenarien ist dieser Workflow geeignet?

Experte - Sicherheitsbetrieb, Multimodales KI

Ist es kostenpflichtig?

Dieser Workflow ist völlig kostenlos. Beachten Sie jedoch, dass Drittanbieterdienste (wie OpenAI API), die im Workflow verwendet werden, möglicherweise kostenpflichtig sind.

Verwandte Workflows

Workflow-Informationen
Schwierigkeitsgrad
Experte
Anzahl der Nodes18
Kategorie2
Node-Typen6
Schwierigkeitsbeschreibung

Für fortgeschrittene Benutzer, komplexe Workflows mit 16+ Nodes

Externe Links
Auf n8n.io ansehen

Diesen Workflow teilen

Kategorien

Kategorien: 34