CTI AI Agent - IOC Enrichment with STIX and MITRE Mapping

automation · $49.99

Send one indicator. Get a cited verdict, a STIX bundle, and MITRE mapping back in under a minute.

The CTI AI Agent enriches any IP, domain, URL, hash, or CVE across six intelligence sources, has a local AI write the verdict from the evidence, and delivers a branded report plus a ready-to-ingest STIX 2.1 bundle, to Slack, Telegram, email, or your API.

The CTI agent workflow in n8n: webhook, Slack and Telegram entry points into artifact detection and a results cache, then parallel lookups to VirusTotal, AbuseIPDB, GreyNoise, URLhaus, Shodan and AlienVault OTX, an Ollama agent writing the verdict, and a STIX 2.1 bundle before the outputs

The 30-minute tab ritual, in 30 seconds

Alert fires. You copy an IP. Open VirusTotal, then AbuseIPDB, then OTX, then GreyNoise, then Shodan. Try to recall the MITRE technique. Hand-write a STIX bundle. Half an hour gone per indicator.

Or send it here and read the verdict before your coffee cools.

What's included

- The complete n8n workflow

- Webhook API that accepts a structured list or free text, plus Telegram and Slack triggers

- Six-source parallel enrichment across every IOC type: IPv4, IPv6, domain, URL, MD5, SHA1, SHA256, CVE

- Auto-generated STIX 2.1 bundle on every run

- Five-level verdict system with confidence scoring and cited evidence

- MITRE technique IDs and Sigma/YARA/KQL rule ideas in every report

- Branded HTML report that carries your company name, plus three swappable themes (dark SOC, executive-light, MSP-blue)

- Optional smart cache for sub-second repeat lookups

- Batch support up to 100 indicators, one consolidated report

- TLP marking on every output (WHITE / GREEN / AMBER / RED)

- Safe by default, builds and previews the full report inside n8n, sends nothing until you flip one switch

- Step-by-step setup guide and a detailed run guide with curl / PowerShell / Python examples

What every submission returns

  • A three-layer report - Technical (related IOCs + Block/Hunt/Quarantine/Patch), Tactical (MITRE technique IDs + Sigma/YARA/KQL rule ideas), Strategic (actor attribution, victimology, executive brief).

  • A STIX 2.1 bundle - linked indicators, vulnerabilities, actors, and attack-patterns. Drops straight into MISP, OpenCTI, Anomali, Sentinel, Splunk ES, or TheHive.

Every verdict cites its evidence "VT 12/89, AbuseIPDB 87/100, OTX 3 pulses" with a confidence level. The AI only summarizes what the sources returned; thin evidence means Unknown, never a guess.

🔴 Malicious · 🟠 Suspicious · 🟡 Mixed · 🟢 Benign · ⚪ Unknown

Three ways in - including plain English

  • POST a list - {"artifacts": ["45.9.148.108", "evil.com"]} for SIEM/SOAR.

  • POST a sentence - {"text": "beaconing to 185.220.101.1 and hxxp://evil[.]com"} and it finds the indicators itself.

  • Message a bot - Telegram or Slack; the verdict replies in the same chat.

Forward a raw Wazuh alert as-is. One indicator or a batch of 100 - one consolidated report.

Built to fit

Six sources in parallel (VirusTotal, AbuseIPDB, OTX, GreyNoise, URLhaus, Shodan), each queried only when it can answer. Any Ollama-compatible LLM, local or cloud. Every API key in n8n's credential vault, never in the workflow. Safe by default, previews the full report inside n8n and sends nothing until you flip one switch. Imports and activates with zero credentials configured.

Who it's for

CTI analysts cutting 30 minutes per indicator to 30 seconds.

SOC teams mid-incident the optional cache means ten analysts on the same IP cost one lookup.

Detection engineers who want MITRE IDs and rule ideas for free.

MSSPs shipping TLP-marked client reports without the formatting hours.

7-day guarantee

If it doesn't work as described, or it isn't what you needed, contact us within 7 days of purchase and we'll refund you in full. If you'd rather have it working, say so and we'll help you get it running. Your call. Full terms.

← Browse all products