Alfonce27

n8n Agentic AI SOC — AI skill for Claude Code

AI community

Playbook-driven AI SOC for a network.

How to install n8n Agentic AI SOC

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Alfonce27/n8n-Agentic-AI-SOC and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What n8n Agentic AI SOC does

Playbook-driven AI SOC for a network. Kibana detection rules trigger an n8n agent that reads a live Confluence playbook, investigates each UniFi IPS alert with Claude, and posts a verdict to Slack in under 60 seconds.

Alternatives in AI

  • n8n Node Configuration — Node configuration with dependency rules and AI connections 3.6k ★
  • DontFeedTheAI — Transparent anonymization proxy for AI-assisted pentesting 654 ★
  • Upstream Watch — Review pydantic-ai and pydantic-ai-harness releases published since the last watch entry, and record a verdict 361 ★

README

🛡️ AI SOC — Playbook-Driven Alert Triage

An AI-powered Security Operations Center for a home network, built in a single day. Every IPS alert is investigated by an AI agent that reads a **living playbook from Confluence** before it renders a verdict — and the result lands in Slack in under 60 seconds.

![Slack triage report](images/01-slack-alert.jpg)


The idea

Most "AI for security" demos hardcode a prompt and call it a day. This project flips that: the investigation procedure lives in **Confluence**, not in code. The agent fetches the current playbook on every run, so the people who own the process own the agent's behavior.

When the network detects an IPS threat, a Slack notification arrives containing:

  • Verdict — Confirmed Threat / Likely Benign / Needs Investigation
  • Severity with escalation reasoning
  • Plain-English explanation of what happened
  • Recommended response actions
  • Threat intelligence and signature context

Architecture

UniFi → Logstash → Elasticsearch → Kibana Detection Rule → n8n → Elasticsearch Enrichment → Confluence Playbook → Claude AI → Slack
flowchart LR
    A[UniFi Dream Machine
IPS / Syslog CEF] --> B[Logstash] B --> C[(Elasticsearch)] C --> D[Kibana
Detection Rule] D -- Webhook --> E[n8n] E --> F[Enrich alert
from Elasticsearch] F --> G[AI Agent] G <-- fetch on every run --> H[(Confluence
SOC IPS Triage Playbook)] G <--> I[Claude API] G --> J[Slack #alerts]

Pipeline stages

Stage Component Role
1 UniFi Dream Machine SE Threat Management (IPS) generates alerts and ships them via syslog in CEF format
2 Logstash Parses CEF, normalizes fields (src, dst, dpt, UNIFIipSignature, UNIFIrisk, …)
3 Elasticsearch Stores raw events in a unifi-syslog-* index
4 Kibana Detection Rule Matches Threat Detected and Blocked events and fires a webhoo