Automated Threat Hunting for Wazuh - n8n AI Agent

automation · $49.99

Automated Threat Hunting for Wazuh

Threat hunting keeps losing to the alert queue. Not because it's difficult, but because it requires a senior analyst and a free afternoon and that afternoon never comes.

This n8n workflow automates the process.

Every week it searches your Wazuh environment for signs of credential theft, lateral movement, web shells, ransomware staging, persistence, and dozens of other attacker techniques. Findings are automatically enriched with VirusTotal, AlienVault OTX, and AbuseIPDB, analyzed by a local AI model (optional), and delivered as a single analyst-ready report.

Unlike static dashboards or manual hunting, this workflow continuously executes 59 MITRE ATT&CK-mapped threat hunting hypotheses, so your team spends minutes reviewing results instead of hours writing and running queries.

The scheduled threat hunting workflow in n8n, running from a weekly schedule and hunt library through hunt selection and execution, IOC extraction, VirusTotal, OTX and AbuseIPDB lookups, an Ollama triage agent, and a dry-run gate ahead of Gmail, Slack, Discord and Telegram delivery

At a glance

  • ✅ 59 MITRE ATT&CK-mapped threat hunts

  • ✅ Automated weekly execution

  • ✅ Rotating hunt schedule or full library execution

  • ✅ VirusTotal, AlienVault OTX & AbuseIPDB enrichment

  • ✅ Optional local AI-powered triage (Ollama)

  • ✅ Analyst-ready HTML email reports

  • ✅ Fully customizable hunt library

  • ✅ Runs entirely on your infrastructure

  • ✅ Around 15-minute setup

How it works

Every Monday the workflow automatically runs a rotating set of threat hunts against your Wazuh Indexer. Over the course of a month, all 59 hunt hypotheses are executed without overwhelming your team with unnecessary noise.

Prefer to hunt on demand? Run the complete library in a single execution (around 20 seconds), focus on specific hunt groups, or customize the schedule to fit your environment.

Each finding is automatically enriched with threat intelligence, analyzed, prioritized, and included in a clean HTML report so analysts can immediately focus on what matters.

Everything is configurable from a single node, including schedules, recipients, branding, whitelists, reporting options, and hunt settings.

Most importantly, your data never leaves your infrastructure.

Perfect for

  • MSSPs delivering managed detection services

  • Internal SOC teams using Wazuh

  • Security consultants

  • Security operations homelabs

  • Organizations that want continuous threat hunting without additional tooling

Requirements

  • n8n

  • Wazuh 4.x with a reachable Indexer

  • SMTP mail credentials Or use Gmail

Optional:

  • Ollama for local AI analysis

  • VirusTotal, AlienVault OTX, and AbuseIPDB API keys

The workflow continues to operate even if the AI model or threat intelligence services are unavailable.

7-day guarantee

If it doesn't work as described, or it isn't what you needed, contact us within 7 days of purchase and we'll refund you in full. If you'd rather have it working, say so and we'll help you get it running. Your call. Full terms.

← Browse all products