AcademyWorkflowsOperations

Suspicious Login Detection

Security and IT operations teams that want a first triage of login alerts with priority levels.

  • Recommendedour rating
  • 6,442views on n8n
Open on n8n.io ↗

Paste it straight onto an n8n canvas with Ctrl+V or Cmd+V.

suspicious-login-detection.json

Loading the file...

What it does

An n8n workflow for reviewing suspicious login events. It runs from a webhook when a login is recorded, or by hand for testing. It checks the IP address with GreyNoise and its location with IP-API, looks up the IP and user agent with Userparser, assigns a High, Medium or Low priority and sends a Slack alert.

Use cases

  1. 01Triaging login alerts by IP reputation
  2. 02Sending login alerts with their priority to Slack
  3. 03Checking the location of an unusual sign-in

Connects

HTTP Request · Postgres · Slack · Gmail · Code · HTML

Questions about
Suspicious Login Detection.

What is Suspicious Login Detection used for?

Security and IT operations teams that want a first triage of login alerts with priority levels. An n8n workflow for reviewing suspicious login events. It runs from a webhook when a login is recorded, or by hand for testing. It checks the IP address with GreyNoise and its location with IP-API, looks up the IP and user agent with Userparser, assigns a High, Medium or Low priority and sends a Slack alert.

How do I import Suspicious Login Detection into n8n?

Copy the workflow JSON from this page and paste it onto the n8n canvas with Ctrl+V or Cmd+V. Then connect your credentials in each node.

Is Suspicious Login Detection safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.