n8n Agentic AI SOC — AI skill for Claude Code
Playbook-driven AI SOC for a network.
How to install n8n Agentic AI SOC
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Alfonce27/n8n-Agentic-AI-SOC and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What n8n Agentic AI SOC does
Playbook-driven AI SOC for a network. Kibana detection rules trigger an n8n agent that reads a live Confluence playbook, investigates each UniFi IPS alert with Claude, and posts a verdict to Slack in under 60 seconds.
Alternatives in AI
- n8n Node Configuration — Node configuration with dependency rules and AI connections 3.6k ★
- DontFeedTheAI — Transparent anonymization proxy for AI-assisted pentesting 654 ★
- Upstream Watch — Review pydantic-ai and pydantic-ai-harness releases published since the last watch entry, and record a verdict 361 ★
README
🛡️ AI SOC — Playbook-Driven Alert Triage
An AI-powered Security Operations Center for a home network, built in a single day. Every IPS alert is investigated by an AI agent that reads a **living playbook from Confluence** before it renders a verdict — and the result lands in Slack in under 60 seconds.

The idea
Most "AI for security" demos hardcode a prompt and call it a day. This project flips that: the investigation procedure lives in **Confluence**, not in code. The agent fetches the current playbook on every run, so the people who own the process own the agent's behavior.
When the network detects an IPS threat, a Slack notification arrives containing:
- Verdict —
Confirmed Threat/Likely Benign/Needs Investigation - Severity with escalation reasoning
- Plain-English explanation of what happened
- Recommended response actions
- Threat intelligence and signature context
Architecture
UniFi → Logstash → Elasticsearch → Kibana Detection Rule → n8n → Elasticsearch Enrichment → Confluence Playbook → Claude AI → Slack
flowchart LR
A[UniFi Dream Machine
IPS / Syslog CEF] --> B[Logstash]
B --> C[(Elasticsearch)]
C --> D[Kibana
Detection Rule]
D -- Webhook --> E[n8n]
E --> F[Enrich alert
from Elasticsearch]
F --> G[AI Agent]
G <-- fetch on every run --> H[(Confluence
SOC IPS Triage Playbook)]
G <--> I[Claude API]
G --> J[Slack #alerts]
Pipeline stages
| Stage | Component | Role |
|---|---|---|
| 1 | UniFi Dream Machine SE | Threat Management (IPS) generates alerts and ships them via syslog in CEF format |
| 2 | Logstash | Parses CEF, normalizes fields (src, dst, dpt, UNIFIipSignature, UNIFIrisk, …) |
| 3 | Elasticsearch | Stores raw events in a unifi-syslog-* index |
| 4 | Kibana Detection Rule | Matches Threat Detected and Blocked events and fires a webhoo |
Related Skills
AI Weekly Update
Claude Code skill: fill your individual row on a Confluence AI-usage weekly report. Researches Jira, Slack, Ou
MCP Unifi Applications
UniFi MCP server that makes the official UniFi API documentation (Network, Protect, Site Manager, InnerSpace)
Claude Skills Governance Risk And Compliance
Claude Skills for Governance, Risk & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2,
Onchain Narrative Research Skill
AI coding agent skill for crypto onchain research: verify wallets, trace narratives, and design alert rules
Warpalert
Wmux — Warp alert: native toasts when your AI agent (Claude, Codex, OpenCode, Gemini) finishes a turn.
Reins
The control layer for autonomous AI agents. Budget governor, policy engine, hash chained ledger and an evidenc
Related Agents
Worker Publisher
Execute publishing operations — Slack, Confluence, Notion, webhooks. Receives final content and posts it.
Scope Investigate
SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — st
Threat Detection Engineer
Principal Threat Detection Engineer with VETO authority over detection-as-code coverage, false-positive-rate d