AcademyWorkflowsOperations

CrowdStrike Detections to VirusTotal, Jira and Slack

Security and IT operations teams that triage endpoint detections and track them as tickets.

  • Recommendedour rating
  • 4,201views on n8n
Open on n8n.io ↗

Paste it straight onto an n8n canvas with Ctrl+V or Cmd+V.

analyze-crowdstrike-detections-search-for-iocs-in-virustotal-create-a-ticket-in.json

Loading the file...

What it does

Runs daily at midnight and fetches recent CrowdStrike detections. Each one is enriched with detail from the CrowdStrike API and checked in VirusTotal by file hash and indicator values. The workflow then creates a Jira issue with the combined details and posts a message in Slack.

Use cases

  1. 01Create a Jira ticket for each new CrowdStrike detection
  2. 02Add VirusTotal context to a detection before triage
  3. 03Notify the security channel in Slack about new detections

Connects

HTTP Request · Slack · Jira Software

Questions about
CrowdStrike Detections to VirusTotal, Jira and Slack.

What is CrowdStrike Detections to VirusTotal, Jira and Slack used for?

Security and IT operations teams that triage endpoint detections and track them as tickets. Runs daily at midnight and fetches recent CrowdStrike detections. Each one is enriched with detail from the CrowdStrike API and checked in VirusTotal by file hash and indicator values. The workflow then creates a Jira issue with the combined details and posts a message in Slack.

How do I import CrowdStrike Detections to VirusTotal, Jira and Slack into n8n?

Copy the workflow JSON from this page and paste it onto the n8n canvas with Ctrl+V or Cmd+V. Then connect your credentials in each node.

Is CrowdStrike Detections to VirusTotal, Jira and Slack safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.