top of page

Suspicious Login Detection Workflow

An n8n workflow for detecting suspicious logins using GreyNoise API for IP threat intelligence, IP-API for geolocation, UserParser for user agent analysis, and Postgres for login history. It prioritizes alerts and notifies via Slack and email for security response.

bottom of page