Automate SIEM Alert Enrichment with MITRE ATT&CK, Qdrant & Zendesk in n8n — n8n Workflow

High complexity Trigger23 nodes AI👁 12,446 viewsby Angel Menendez

Overview

n8n Workflow: Automate SIEM Alert Enrichment with MITRE ATT&CK & Qdrant

Who is this for?
This workflow is ideal for:
Cybersecurity teams & SOC analysts* who want to automate SIEM alert enrichment*.
IT security professionals* looking to integrate MITRE ATT&CK intelligence* into their ticketing system.
Organizations using Zendesk for security incidents* who need enhanced contextual threat data*.
Anyone using n8n and Qdrant* to build AI-powered security workflows*.

What prob

Nodes used

Google DriveZendeskAI AgentEmbeddings OpenAIOpenAI Chat ModelSimple MemoryStructured Output ParserToken SplitterDefault Data LoaderQdrant Vector Store

Workflow Preview

!n8n
Embed your Vector Store
To provide data for your Vector store, you need to pass
!n8n
Talk to your Vector Store
Now that your vector store has been updated with the em
you can use the n8n chat interface to talk to your da
!Servicenow
Deploy your Vector Store
This flow adds contextual information to your tickets u
embedmodelembedembedmodeldocmemoryparsertooltool
W
When chat message received
AI Agent
OpenAI Chat Model
S
Split Out
Embeddings OpenAI1
Default Data Loader
Token Splitter1
Window Buffer Memory
Embeddings OpenAI2
E
Extract from File
W
When clicking ‘Test work…
AI Agent1
OpenAI Chat Model1
Embeddings OpenAI
L
Loop Over Items
Structured Output Parser
Pull Mitre Data From Gdr…
Embed JSON in Qdrant Col…
Query Qdrant Vector Store
Qdrant Vector Store query
Get all Zendesk Tickets
Update Zendesk with Mitr…
M
Move on to next ticket
23 nodes21 edges

How it Works

  1. 1

    Trigger

    The workflow starts with a trigger trigger.

  2. 2

    Process

    Data flows through 23 nodes, connecting agent, chattrigger, documentdefaultdataloader.

  3. 3

    Output

    The workflow completes its automation and delivers the result to the configured destination.

Node Details (23)

GO

Google Drive

googleDrive

#1
ZE

Zendesk

zendesk

#2
AI

AI Agent

n8n-nodes-langchain.agent

#3
EM

Embeddings OpenAI

n8n-nodes-langchain.embeddingsOpenAi

#4
OP

OpenAI Chat Model

n8n-nodes-langchain.lmChatOpenAi

#5
SI

Simple Memory

n8n-nodes-langchain.memoryBufferWindow

#6
ST

Structured Output Parser

n8n-nodes-langchain.outputParserStructured

#7
TO

Token Splitter

n8n-nodes-langchain.textSplitterTokenSplitter

#8
DE

Default Data Loader

n8n-nodes-langchain.documentDefaultDataLoader

#9
QD

Qdrant Vector Store

n8n-nodes-langchain.vectorStoreQdrant

#10

How to Import This Workflow

  1. 1Click Download JSON button on the right to save the workflow file.
  2. 2Open your n8n instance. Go to Workflows → New → Import from file.
  3. 3Select the downloaded automate-siem-alert-enrichment-with-mitre-attck-qdrant-zendesk-in-n8n file and click Import.
  4. 4Set up credentials for each service node (API keys, OAuth, etc.).
  5. 5Click Test Workflow to verify everything works, then activate it.

Or paste directly in n8n → Import from JSON:

{ "name": "Automate SIEM Alert Enrichment with MITRE ATT&CK, Qdrant & Zendesk in n8n", "nodes": [...], ...}

Integrations

agentchattriggerdocumentdefaultdataloaderembeddingsopenaiextractfromfilegoogledrivelmchatopenaimanualtriggermemorybufferwindowoutputparserstructuredsplitinbatchessplitouttextsplittertokensplittervectorstoreqdrantzendesk

Get This Workflow

Download and import in one click

Download JSONView on n8n.io
Nodes23
Complexityhigh
Triggertrigger
Views12,446
CategoryAI

Created by

Angel Menendez

Angel Menendez

@djangelic

Tags

agentchattriggerdocumentdefaultdataloaderembeddingsopenaiextractfromfilegoogledrivelmchatopenaimanualtriggermemorybufferwindowoutputparserstructured

New to n8n?

n8n is a free, open-source workflow automation tool. Self-host it or use the cloud version.

Get n8n Free →

Related AI Workflows

AGCOFIGM+10
high

Automate Digital Product Delivery: Stripe to Gmail via n8n

Transform your post-purchase operations with this high-performance n8n workflow designed for digital creators and SaaS founders. Instead of manual fulfillment, this automation acts as a 24/7 digital concierge. It begins by scanning Stripe for successful transactions, cross-referencing buyer data against a centralized Google Sheets inventory to identify the correct digital asset. Utilizing advanced AI via GPT-4o, the system then drafts a personalized onboarding email, including secure access credentials and custom instructions, ensuring a premium customer experience without manual intervention. This flow eliminates the 'human-in-the-middle' delay, significantly reducing support tickets related to missing downloads. By integrating an AI agent, the workflow can intelligently parse complex product variations, making it far more robust than standard linear automations. Whether you are selling automation templates, software licenses, or protected PDF guides, this system provides a scalable infrastructure that grows with your sales volume while maintaining a personal touch through LLM-generated content. **Common Use Cases:** - Scaling a niche digital marketplace for selling specialized code snippets or design assets. - Automating the distribution of unique software license keys and documentation after a SaaS subscription purchase. - Delivering personalized AI-generated consulting reports or audit results based on customer input data.

Scheduled·25 nodes
AGCHCOEX+10
high

Automated AI Resume Parser & JD Matcher via n8n & GPT-4

Transform your recruitment funnel with this advanced AI-driven candidate evaluation engine. This n8n workflow eliminates manual screening fatigue by autonomously analyzing batches of resumes against specific job descriptions. Using GPT-4 and LangChain's structured output parsers, the system extracts key qualifications, scores them against your criteria, and generates objective alignment reports. The process begins with a custom n8n form for document upload, followed by intelligent text extraction from PDFs. The data is then processed through an LLM chain to ensure unbiased scoring. Results are synchronized directly to Google Sheets for centralized tracking, while high-match alerts are dispatched via Slack and SendGrid to keep hiring managers informed in real-time. This workflow is essential for high-volume recruitment agencies and scaling startups that need to maintain a rigorous, auditable, and data-backed shortlisting process without increasing headcount or sacrificing quality of hire. **Common Use Cases:** - High-volume university recruitment and internship screening - Technical talent sourcing for niche engineering roles - Internal mobility matching for large corporate restructuring

Trigger·21 nodes
AGCHGMGM+5
medium

AI Gmail Auto-Labeler: Smart Inbox Sorting with GPT-4 & n8n

Stop drowning in a cluttered inbox and regain control of your digital communication. This advanced n8n automation leverages GPT-4's natural language processing to intelligently analyze, categorize, and label incoming Gmail messages in real-time. Unlike basic filter rules that rely on rigid keywords, this workflow understands the context and sentiment of every email, ensuring high-precision organization. The process begins with a Gmail Trigger that captures new messages. It then passes the content through a LangChain LLM chain where OpenAI evaluates the intent—distinguishing between urgent client requests, internal project updates, or low-priority newsletters. Using structured output parsing, the workflow extracts key metadata and applies the appropriate Gmail labels automatically. This eliminates the manual cognitive load of triaging emails, allowing your team to focus on high-value tasks rather than administrative upkeep. Whether you are managing high-volume support tickets or complex sales inquiries, this workflow ensures that critical messages are highlighted and organized without human intervention. **Common Use Cases:** - Automated Customer Support Triage: Instantly tag emails as 'Urgent Support', 'Feature Request', or 'Billing' to speed up response times. - Sales Lead Prioritization: Automatically identify high-intent inquiries and label them for immediate follow-up by account executives. - Project Management Sync: Categorize incoming vendor updates and stakeholder feedback by project name or department for better visibility.

Trigger·11 nodes
AGGMGOLM+3
medium

AI Dental Lead Follow-up: n8n, OpenAI & Google Sheets Sync

Stop losing high-value patients to delayed responses. This advanced n8n workflow bridges the gap between lead capture and appointment booking by deploying an AI-driven engagement layer. When a prospect submits a query via your website or landing page, the automation immediately triggers, logging the data into Google Sheets for centralized tracking. Instead of sending a generic auto-reply, the integrated LangChain agent utilizes GPT-4/3.5 to analyze the specific treatment interest—be it Invisalign, dental implants, or routine cleaning—and crafts a personalized, empathetic response delivered via Gmail. The workflow includes a strategic 'Wait' node to mimic natural human timing and a 'Memory Buffer' to maintain context if the lead replies. This system is essential for clinics looking to scale their patient acquisition without increasing administrative headcount, ensuring every inquiry is nurtured instantly with professional, clinical-grade communication. By automating the initial touchpoint, your front-desk team can focus on confirmed arrivals rather than chasing cold leads. **Common Use Cases:** - Automated Patient Triage: Categorizing and responding to specific dental treatment inquiries based on urgency and procedure type. - Medical Spa Lead Nurturing: Instantly engaging prospects interested in high-ticket aesthetic treatments to increase conversion rates. - Multi-Location Clinic Sync: Centralizing lead data from various web forms into a single Google Sheet while maintaining personalized local email follow-ups.

Trigger·8 nodes
AGCOGOHT+8
high

Automate AI UGC Video Production with Google Sheets & Veo

Transform your digital marketing strategy by automating the production of high-converting User-Generated Content (UGC) at scale. This sophisticated n8n workflow eliminates the logistical bottleneck of traditional content creation by orchestrating a seamless pipeline between Google Sheets and advanced AI video models. By leveraging NanoBanana Pro for precise image synthesis and Veo 3.1 for fluid motion, the system takes three distinct visual inputs—your product, a chosen persona, and a target environment—and blends them into hyper-realistic, selfie-style video assets. The automation begins by monitoring a Google Sheet for new campaign parameters, triggers an intelligent AI agent to handle complex image processing, and manages asynchronous API calls to ensure high-fidelity video rendering. This is an enterprise-grade solution for performance marketers who need to refresh creative assets daily without manual intervention. It effectively handles the heavy lifting of prompt engineering and file management, allowing you to focus on strategy while the workflow generates 8-second, platform-ready clips optimized for the TikTok and Instagram algorithms. **Common Use Cases:** - Scaling creative testing for TikTok and Meta Ads by generating hundreds of product variants - Automating personalized influencer-style shoutouts for e-commerce loyalty programs - Rapid prototyping of social media video content for global brand localization

Scheduled·24 nodes
@BAGCOIF+7
high

Automate AI Twitter Threads via Telegram & n8n (No-Code)

Streamline your social media presence with this enterprise-grade n8n automation that bridges the gap between raw inspiration and professional X (Twitter) publishing. By integrating Telegram as a mobile command center, this workflow allows you to dictate or type thread ideas on the go. The system leverages OpenAI’s LLMs and LangChain agents to draft high-engagement thread structures, which are then sent back to your private Telegram chat for review. Unlike basic automation, this setup features a sophisticated 'human-in-the-loop' approval system. You can interactively refine the AI-generated content, request edits, or finalize the draft. Once you provide the 'Okay' confirmation, the workflow automatically formats and publishes the entire thread to X via the Blotato integration. This eliminates the friction of manual drafting and copy-pasting, ensuring your brand stays active without the constant overhead of social media management. It is the perfect solution for creators and businesses looking to maintain a high-quality digital presence using a voice-to-thread mobile pipeline. **Common Use Cases:** - Thought Leadership: Convert spontaneous voice memos into structured educational threads while commuting. - Event Live-Tweeting: Rapidly draft and approve professional event summaries from a mobile device without opening the X app. - Content Repurposing: Send links or snippets of long-form articles to Telegram to generate 'tweetable' summaries for social distribution.

Trigger·19 nodes