CTI AI Agent + Guide
Send one indicator. Get a cited verdict, a STIX bundle, and MITRE mapping back in under a minute.
The CTI AI Agent enriches any IP, domain, URL, hash, or CVE across six intelligence sources, has a local AI write the verdict from the evidence, and delivers a branded report plus a ready-to-ingest STIX 2.1 bundle, to Slack, Telegram, email, or your API.
The 30-minute tab ritual, in 30 seconds
Alert fires. You copy an IP. Open VirusTotal, then AbuseIPDB, then OTX, then GreyNoise, then Shodan. Try to recall the MITRE technique. Hand-write a STIX bundle. Half an hour gone per indicator.
Or send it here and read the verdict before your coffee cools.
What's included
- The complete n8n workflow
- Webhook API that accepts a structured list or free text, plus Telegram and Slack triggers
- Six-source parallel enrichment across every IOC type: IPv4, IPv6, domain, URL, MD5, SHA1, SHA256, CVE
- Auto-generated STIX 2.1 bundle on every run
- Five-level verdict system with confidence scoring and cited evidence
- MITRE technique IDs and Sigma/YARA/KQL rule ideas in every report
- Branded HTML report that carries your company name, plus three swappable themes (dark SOC, executive-light, MSP-blue)
- Optional smart cache for sub-second repeat lookups
- Batch support up to 100 indicators, one consolidated report
- TLP marking on every output (WHITE / GREEN / AMBER / RED)
- Safe by default, builds and previews the full report inside n8n, sends nothing until you flip one switch
- Step-by-step setup guide and a detailed run guide with curl / PowerShell / Python examples
What every submission returns
- A three-layer report โ Technical (related IOCs + Block/Hunt/Quarantine/Patch), Tactical (MITRE technique IDs + Sigma/YARA/KQL rule ideas), Strategic (actor attribution, victimology, executive brief).
- A STIX 2.1 bundle โ linked indicators, vulnerabilities, actors, and attack-patterns. Drops straight into MISP, OpenCTI, Anomali, Sentinel, Splunk ES, or TheHive.
Every verdict cites its evidence "VT 12/89, AbuseIPDB 87/100, OTX 3 pulses" with a confidence level. The AI only summarizes what the sources returned; thin evidence means Unknown, never a guess.
๐ด Malicious ยท ๐ Suspicious ยท ๐ก Mixed ยท ๐ข Benign ยท โช Unknown
Three ways in โ including plain English
- POST a list โ {"artifacts": ["45.9.148.108", "evil.com"]} for SIEM/SOAR.
- POST a sentence โ {"text": "beaconing to 185.220.101.1 and hxxp://evil[.]com"} and it finds the indicators itself.
- Message a bot โ Telegram or Slack; the verdict replies in the same chat.
Forward a raw Wazuh alert as-is. One indicator or a batch of 100 โ one consolidated report.
Built to fit
Six sources in parallel (VirusTotal, AbuseIPDB, OTX, GreyNoise, URLhaus, Shodan), each queried only when it can answer. Any Ollama-compatible LLM, local or cloud. Every API key in n8n's credential vault, never in the workflow. Safe by default, previews the full report inside n8n and sends nothing until you flip one switch. Imports and activates with zero credentials configured.
Who it's for
CTI analysts cutting 30 minutes per indicator to 30 seconds.
SOC teams mid-incident the optional cache means ten analysts on the same IP cost one lookup.
Detection engineers who want MITRE IDs and rule ideas for free.
MSSPs shipping TLP-marked client reports without the formatting hours.
30-day guarantee
If it doesn't run in your setup, I'll help you troubleshoot. If we can't get it working, full refund. No questions.