Skip to content
FlowHubFluxonLab
A
AI Automationfree

Automate SIEM Alert Enrichment with MITRE ATT&CK, Qdrant & Zendesk in n8n

by Angel Menendezadapted from n8n official workflow galleryUpdated Aug 2026
RequiresAAI AgentDDefault Data LoaderEmbeddings OpenAIEmbeddings OpenAIGoogle DriveGoogle DriveOpenAI Chat ModelOpenAI Chat ModelQdrant Vector StoreQdrant Vector StoreSSimple MemoryStructured Output ParserStructured Output ParserToken SplitterToken SplitterZendeskZendesk
Share Post Share
ChWhen chat message receivedWhen chat messa…AgAI AgentOpenAI Chat ModelOpenAI Chat Mod…SOSplit OutEmbeddings OpenAI1Embeddings Open…DDDefault Data LoaderDefault Data Lo…TSToken Splitter1MBWindow Buffer MemoryWindow Buffer M…Embeddings OpenAI2Embeddings Open…EFExtract from FileExtract from Fi…MaWhen clicking ‘Test workflow’When clicking ‘…AgAI Agent1OpenAI Chat Model1OpenAI Chat Mod…Embeddings OpenAIEmbeddings Open…SILoop Over ItemsOPStructured Output ParserStructured Outp…Pull Mitre Data From GdrivePull Mitre Data…VSEmbed JSON in Qdrant CollectionEmbed JSON in Q…VSQuery Qdrant Vector StoreQuery Qdrant Ve…VSQdrant Vector Store queryQdrant Vector S…Get all Zendesk TicketsGet all Zendesk…Update Zendesk with Mitre DataUpdate Zendesk …NOMove on to next ticketMove on to next…12345
1/5
FLOWS
STEPS · 5
Starts from a chat message

n8n Workflow: Automate SIEM Alert Enrichment with MITRE ATT&CK & Qdrant Who is this for? This workflow is ideal for: Cybersecurity teams & SOC analysts* who want to automate *SIEM alert enrichment**. IT security professionals* looking to integrate *MITRE ATT&CK intelligence** into their ticketing system. Organizations using Zendesk for security incidents* who need enhanced *contextual threat data**. Anyone using n8n and Qdrant* to build *AI-powered security workflows**. What problem does this workflow solve? Security teams receive large volumes of raw SIEM alerts that lack actionable context. Investigating every alert manually is time-consuming and can lead to delayed response times. This workflow solves this problem by: ✔ Automatically enriching SIEM alerts with MITRE ATT&CK TTPs. ✔ Tagging & classifying alerts based on known attack techniques. ✔ Providing remediation steps to guide the response team. ✔ Enhancing security tickets in Zendesk with relevant threat intelligence. What this workflow does 1️⃣ Ingests SIEM alerts (via chatbot or ticketing system like Zendesk). 2️⃣ Queries a Qdrant vector store containing MITRE ATT&CK techniques.

Tags

n8nreference-onlyagentdocument-default-data-loaderembeddings-open-aigoogle-drivelm-chat-open-aimemory-buffer-windowoutput-parser-structuredtext-splitter-token-splittervector-store-qdrantzendesk
Connects
AAI AgentDDefault Data LoaderembeddingsopenaiEmbeddings OpenAIgoogledriveGoogle DriveopenaichatmodelOpenAI Chat ModelqdrantvectorstoreQdrant Vector Store
CategoryAI Automation
Triggermanual
Complexityadvanced
Nodes23
AddedFeb 3, 2025

Related workflows

See all AI Automation
Dgoogledriveopenaichatmodelsummarizationchain
free

Load and summarize Google Drive files with AI

This workflow includes advanced features like text summarization and tokenization, it's ideal for automating document processing tasks that require parsing and summarizing text data from Google Drive. To use this template, you need to be on n8n version 1.19.4 or later.

by n8n Team
AopenaichatmodelserpapigooglesearchS
free

AI agent chat

This workflow employs OpenAI's language models and SerpAPI to create a responsive, intelligent conversational agent. It comes equipped with manual chat triggers and memory buffer capabilities to ensure seamless interactions. To use this template, you need to be on n8n version 1.50.0 or later.

by n8n Team
ACDgmail
free

AI: Summarize podcast episode and enhance using Wikipedia

The workflow automates the process of creating a summarized and enriched podcast digest, which is then sent via email. Note that to use this template, you need to be on n8n version 1.19.4 or later.

by n8n Team