Erstellung detaillierter Sicherheits-Tickets basierend auf SentinelOne-Bedrohungen und MITRE-Analysen
Dies ist ein SecOps, Multimodal AI-Bereich Automatisierungsworkflow mit 18 Nodes. Hauptsächlich werden Code, Wait, Webhook, SplitOut, HttpRequest und andere Nodes verwendet. Detaillierte Sicherheits-Tickets auf der Grundlage von SentinelOne-Bedrohungen und MITRE-Analyse erstellen
- •HTTP Webhook-Endpunkt (wird von n8n automatisch generiert)
- •Möglicherweise sind Ziel-API-Anmeldedaten erforderlich
Verwendete Nodes (18)
Kategorie
{
"meta": {
"instanceId": "8d70623c0c9f4448eda9626cd8185192c28447e191325b0c0d94d3f40d23be3a"
},
"nodes": [
{
"id": "b43d41e4-fd97-4a54-93cd-2197da482a76",
"name": "Neue SentinelOne-Bedrohung",
"type": "n8n-nodes-base.webhook",
"position": [
80,
160
],
"webhookId": "3b1d201a-316f-4956-b77a-4d27b268cf1f",
"parameters": {},
"typeVersion": 2
},
{
"id": "3267f360-6fae-43e8-86dc-a0c2e037b590",
"name": "Haftnotiz1",
"type": "n8n-nodes-base.stickyNote",
"position": [
-740,
-140
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "6e7fc0ba-263e-400d-8b22-f502aff3ccf6",
"name": "Haftnotiz",
"type": "n8n-nodes-base.stickyNote",
"position": [
40,
-160
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "497f3698-9fff-4a06-be29-1f3bd8d54553",
"name": "Haftnotiz2",
"type": "n8n-nodes-base.stickyNote",
"position": [
460,
-160
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "b238ff4e-997c-4e64-a848-5490531391be",
"name": "Haftnotiz3",
"type": "n8n-nodes-base.stickyNote",
"position": [
920,
-160
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "d4f07134-ee81-443d-b19a-b2f16266775c",
"name": "Haftnotiz4",
"type": "n8n-nodes-base.stickyNote",
"position": [
2380,
-140
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "3f59c053-ce4c-452c-b6fd-fb7e7874cdd2",
"name": "Haftnotiz6",
"type": "n8n-nodes-base.stickyNote",
"position": [
1480,
420
],
"parameters": {
"content": ""
},
"typeVersion": 1
},
{
"id": "310c22d7-4b8f-459d-8ea2-26b16f8ba3fe",
"name": "Extract Threat Intelligence",
"type": "n8n-nodes-base.code",
"position": [
300,
160
],
"parameters": {},
"typeVersion": 2
},
{
"id": "d9088837-2371-4e06-a71d-93795b94869d",
"name": "Fetch Autotask Users",
"type": "n8n-nodes-base.httpRequest",
"position": [
520,
160
],
"parameters": {},
"typeVersion": 4.2
},
{
"id": "baa5b6d8-7e37-4b6b-81af-6733fc45c61c",
"name": "Load Client Companies",
"type": "n8n-nodes-base.httpRequest",
"position": [
960,
160
],
"parameters": {},
"typeVersion": 4.2
},
{
"id": "332813df-6b24-497d-a53c-eb2544e0c6b7",
"name": "Process Company Data",
"type": "n8n-nodes-base.splitOut",
"position": [
1400,
160
],
"parameters": {},
"typeVersion": 1
},
{
"id": "bb2d1e70-74e1-4f09-af81-af301c852796",
"name": "Retrieve Ticket Fields",
"type": "n8n-nodes-base.httpRequest",
"position": [
1620,
160
],
"parameters": {},
"typeVersion": 4.2
},
{
"id": "d59eff6f-33f6-4c74-93e8-10502ee196bf",
"name": "Parse Field Options",
"type": "n8n-nodes-base.code",
"position": [
1840,
160
],
"parameters": {},
"typeVersion": 2
},
{
"id": "04fb54c0-18c8-47f3-9884-e315451d02f9",
"name": "Map Client Company",
"type": "n8n-nodes-base.code",
"position": [
2280,
160
],
"parameters": {},
"typeVersion": 2
},
{
"id": "cc08de33-66e7-4cba-a4a1-08994fe496f8",
"name": "Create Security Ticket",
"type": "n8n-nodes-base.httpRequest",
"position": [
2500,
160
],
"parameters": {},
"typeVersion": 4.2
},
{
"id": "af7de8b1-c43c-4f9d-bc20-d7f0f63f144c",
"name": "Rate Begrenzen Delay 1",
"type": "n8n-nodes-base.wait",
"position": [
740,
160
],
"webhookId": "9d2aea13-8b41-45f7-a875-4042743815dd",
"parameters": {},
"typeVersion": 1.1
},
{
"id": "f1e2cb40-c74f-4533-a1af-4ee7f24c5045",
"name": "Rate Begrenzen Delay 2",
"type": "n8n-nodes-base.wait",
"position": [
2060,
160
],
"webhookId": "30d29da9-0ce4-4a8a-9b87-a92eee4db5ed",
"parameters": {},
"typeVersion": 1.1
},
{
"id": "47cba939-82b5-4f9c-a59a-4e7f7001dc24",
"name": "Warten",
"type": "n8n-nodes-base.wait",
"position": [
1180,
160
],
"webhookId": "f240fb70-3d06-4faf-a4bc-9b62a699e198",
"parameters": {},
"typeVersion": 1.1
}
],
"pinData": {},
"connections": {
"Wait": {
"main": [
[
{
"node": "332813df-6b24-497d-a53c-eb2544e0c6b7",
"type": "main",
"index": 0
}
]
]
},
"04fb54c0-18c8-47f3-9884-e315451d02f9": {
"main": [
[
{
"node": "cc08de33-66e7-4cba-a4a1-08994fe496f8",
"type": "main",
"index": 0
}
]
]
},
"Rate Limit Delay 1": {
"main": [
[
{
"node": "baa5b6d8-7e37-4b6b-81af-6733fc45c61c",
"type": "main",
"index": 0
}
]
]
},
"Rate Limit Delay 2": {
"main": [
[
{
"node": "04fb54c0-18c8-47f3-9884-e315451d02f9",
"type": "main",
"index": 0
}
]
]
},
"d59eff6f-33f6-4c74-93e8-10502ee196bf": {
"main": [
[
{
"node": "Rate Limit Delay 2",
"type": "main",
"index": 0
}
]
]
},
"d9088837-2371-4e06-a71d-93795b94869d": {
"main": [
[
{
"node": "Rate Limit Delay 1",
"type": "main",
"index": 0
}
]
]
},
"332813df-6b24-497d-a53c-eb2544e0c6b7": {
"main": [
[
{
"node": "bb2d1e70-74e1-4f09-af81-af301c852796",
"type": "main",
"index": 0
}
]
]
},
"baa5b6d8-7e37-4b6b-81af-6733fc45c61c": {
"main": [
[
{
"node": "Wait",
"type": "main",
"index": 0
}
]
]
},
"b43d41e4-fd97-4a54-93cd-2197da482a76": {
"main": [
[
{
"node": "310c22d7-4b8f-459d-8ea2-26b16f8ba3fe",
"type": "main",
"index": 0
}
]
]
},
"bb2d1e70-74e1-4f09-af81-af301c852796": {
"main": [
[
{
"node": "d59eff6f-33f6-4c74-93e8-10502ee196bf",
"type": "main",
"index": 0
}
]
]
},
"310c22d7-4b8f-459d-8ea2-26b16f8ba3fe": {
"main": [
[
{
"node": "d9088837-2371-4e06-a71d-93795b94869d",
"type": "main",
"index": 0
}
]
]
}
}
}Wie verwende ich diesen Workflow?
Kopieren Sie den obigen JSON-Code, erstellen Sie einen neuen Workflow in Ihrer n8n-Instanz und wählen Sie "Aus JSON importieren". Fügen Sie die Konfiguration ein und passen Sie die Anmeldedaten nach Bedarf an.
Für welche Szenarien ist dieser Workflow geeignet?
Experte - Sicherheitsbetrieb, Multimodales KI
Ist es kostenpflichtig?
Dieser Workflow ist völlig kostenlos. Beachten Sie jedoch, dass Drittanbieterdienste (wie OpenAI API), die im Workflow verwendet werden, möglicherweise kostenpflichtig sind.
Verwandte Workflows
Anna Bui
@annabuiplaygroundDiesen Workflow teilen