What it does
An n8n workflow for reviewing suspicious login events. It runs from a webhook when a login is recorded, or by hand for testing. It checks the IP address with GreyNoise and its location with IP-API, looks up the IP and user agent with Userparser, assigns a High, Medium or Low priority and sends a Slack alert.
Use cases
- 01Triaging login alerts by IP reputation
- 02Sending login alerts with their priority to Slack
- 03Checking the location of an unusual sign-in
Connects
HTTP Request · Postgres · Slack · Gmail · Code · HTML