Automated Threat Hunting for Wazuh - n8n AI Agent
automation · $49.99
Automated Threat Hunting for Wazuh
Threat hunting keeps losing to the alert queue. Not because it's difficult, but because it requires a senior analyst and a free afternoon and that afternoon never comes.
This n8n workflow automates the process.
Every week it searches your Wazuh environment for signs of credential theft, lateral movement, web shells, ransomware staging, persistence, and dozens of other attacker techniques. Findings are automatically enriched with VirusTotal, AlienVault OTX, and AbuseIPDB, analyzed by a local AI model (optional), and delivered as a single analyst-ready report.
Unlike static dashboards or manual hunting, this workflow continuously executes 59 MITRE ATT&CK-mapped threat hunting hypotheses, so your team spends minutes reviewing results instead of hours writing and running queries.
At a glance
✅ 59 MITRE ATT&CK-mapped threat hunts
✅ Automated weekly execution
✅ Rotating hunt schedule or full library execution
✅ VirusTotal, AlienVault OTX & AbuseIPDB enrichment
✅ Optional local AI-powered triage (Ollama)
✅ Analyst-ready HTML email reports
✅ Fully customizable hunt library
✅ Runs entirely on your infrastructure
✅ Around 15-minute setup
How it works
Every Monday the workflow automatically runs a rotating set of threat hunts against your Wazuh Indexer. Over the course of a month, all 59 hunt hypotheses are executed without overwhelming your team with unnecessary noise.
Prefer to hunt on demand? Run the complete library in a single execution (around 20 seconds), focus on specific hunt groups, or customize the schedule to fit your environment.
Each finding is automatically enriched with threat intelligence, analyzed, prioritized, and included in a clean HTML report so analysts can immediately focus on what matters.
Everything is configurable from a single node, including schedules, recipients, branding, whitelists, reporting options, and hunt settings.
Most importantly, your data never leaves your infrastructure.
Perfect for
MSSPs delivering managed detection services
Internal SOC teams using Wazuh
Security consultants
Security operations homelabs
Organizations that want continuous threat hunting without additional tooling
Requirements
n8n
Wazuh 4.x with a reachable Indexer
SMTP mail credentials Or use Gmail
Optional:
Ollama for local AI analysis
VirusTotal, AlienVault OTX, and AbuseIPDB API keys
The workflow continues to operate even if the AI model or threat intelligence services are unavailable.
7-day guarantee
If it doesn't work as described, or it isn't what you needed, contact us within 7 days of purchase and we'll refund you in full. If you'd rather have it working, say so and we'll help you get it running. Your call. Full terms.