ztsprofessionalaiid7-alt

Cybersecurity Automation Portfolio 30 n8n Workflows — Security skill for Claude Code

Security community

30 ready-to-import n8n workflows for security operations across three tiers (Basic, Mid, Advanced).

How to install Cybersecurity Automation Portfolio 30 n8n Workflows

This entry records only its repository, not the path inside it, so there is no exact command to give. Open ztsprofessionalaiid7-alt/Cybersecurity-Automation-Portfolio-30-n8n-Workflows and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Cybersecurity Automation Portfolio 30 n8n Workflows does

30 ready-to-import n8n workflows for security operations across three tiers (Basic, Mid, Advanced). They cover SOC triage, phishing remediation, incident response, compliance auditing, DLP and vendor risk, using AI agents (Claude, Gemini, GPT), RAG, and human-in-the-loop approvals.

Alternatives in Security

  • Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
  • Mcpick — Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across eve 94 ★
  • AegisGate — Open-source security gateway for LLM APIs — prompt injection detection, PII redaction, dangerous response sani 62 ★

README

Cybersecurity Automation Portfolio — Mid Level (10)

This repository brings together ten n8n workflows from the **Mid-Level Cybersecurity Automation** portfolio. Each workflow automates a specific security operation — SOC ticketing, phishing remediation, incident response, login-anomaly detection, dark-web monitoring, compliance auditing, vulnerability triage, data-loss prevention, and a central security-operations dashboard — combining AI agents, Slack/Discord/Twilio notifications, Postgres logging, and Jira/ServiceNow ticketing.

📑 Table of Contents

  1. Security Incident Ticketing & SOC Automation System
  2. Phishing Email Triage & Auto-Remediation Pipeline
  3. Cybersecurity Incident Response Automation
  4. Brute-Force / Anomalous Login Detection & Auto-Response
  5. Dark Web Monitor & Identity Protection
  6. Continuous Compliance Audit Automation (SOC2/ISO27001)
  7. Autonomous Vulnerability Scan Triage & Remediation
  8. Behavioral Data Loss Prevention (DLP) System
  9. VIP & Sensitive Data Loss Prevention (DLP) Alert
  10. AI Security Operations Dashboard

📌 Introduction

Together, these ten automations form a **mid-level security operations stack** — more complex than basic-tier monitoring/alerting automations, since they incorporate AI-agent-driven decision-making (triage, risk scoring, classification), multi-branch routing across systems, and human-in-the-loop verification (Slack approvals, wait steps) — while not yet reaching the complexity of a fully autono