Keyflow

Search Keyflow

Find a shortcut, workflow, MCP server or skill

Suspicious Login Detection

n8n template #1993
This n8n workflow is designed for security monitoring and incident response when suspicious login events are detected. It can be initiated either manually from within the n8n UI for testing or automatically triggered by a webhook when a new login event occurs. The workflow first extracts relevant data from the incoming webhook payload, including the IP address, user agent, timestamp, URL, and user ID. It then splits into three parallel processing paths. In the first path, it queries GreyNoise's Community API to retrieve information about the investigated IP address. Depending on the classification and trust level received from GreyNoise, the alert is given a High, Medium, or Low priority. Th

Hand off to your agent

Prompt

Help me set up the n8n workflow "Suspicious Login Detection" (https://n8n.io/workflows/1993). It uses: HTTP Request, Postgres, Slack, Gmail, Code, HTML. Import the template JSON into my n8n instance, list every credential I need to create, and walk me through testing it.

Paste into Claude Code and it will do the rest.

Apps and nodes

Similar workflows

NameViews
  1. Advanced AI Demo (Presented at AI Developers #14 meetup)24K
  2. Daily Podcast Summary15K
  3. 🤖 Advanced Slackbot with n8n9,377
  4. Realtime Notion Todoist 2-way sync with Redis8,614
  5. URL and IP lookups through Greynoise and VirusTotal8,572
  6. Explore n8n Nodes in a Visual Reference Library5,197
  7. Create LinkedIn Contributions with AI and Notify Users On Slack5,090
  8. 🗞️ AI-powered sustainability newsletter for marketing with Gmail, GPT-4o3,565
Buy me a coffee