{"product_id":"attack-surface-change-monitoring-with-n8n-postgres-openai","title":"Attack Surface Change Monitoring with n8n, Postgres \u0026 OpenAI","description":"\u003ch3\u003eAttack Surface Change Monitoring—Automated in n8n with Postgres \u0026amp; OpenAI\u003c\/h3\u003e\n\u003cp\u003eThis scheduled n8n workflow continuously inventories your external attack surface from three HTTP APIs, diffs it against a Postgres baseline, and uses OpenAI to generate concise risk notes—then sends critical\/high alerts to \u003cstrong\u003eSlack\u003c\/strong\u003e and medium updates by email. When it detects unauthorized cloud footprint, it can also send compliance emails.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns every 6 hours\u003c\/strong\u003e via a schedule trigger to keep monitoring current.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCollects and normalizes assets\u003c\/strong\u003e by querying three external HTTP API sources in parallel (e.g., subdomains, exposed services, and public cloud resources), then merges them into a deduplicated inventory with stable fingerprints.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDiffs against a Postgres baseline\u003c\/strong\u003e by loading the previous inventory from Postgres and comparing it to the current run to identify \u003cstrong\u003enew\u003c\/strong\u003e, \u003cstrong\u003echanged\u003c\/strong\u003e, and \u003cstrong\u003eremoved\u003c\/strong\u003e assets.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eScores and flags risk-relevant changes\u003c\/strong\u003e, including identifying new cloud resources outside allowed provider\/region allowlists.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGenerates risk triage narratives with OpenAI\u003c\/strong\u003e (one to two sentences per change) and attaches them to each change record.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRoutes notifications by severity\u003c\/strong\u003e:\n    \u003cul\u003e\n      \u003cli\u003e\n\u003cstrong\u003eCritical\/High:\u003c\/strong\u003e posts alerts to \u003cstrong\u003eSlack\u003c\/strong\u003e\n\u003c\/li\u003e\n      \u003cli\u003e\n\u003cstrong\u003eMedium:\u003c\/strong\u003e emails security recipients\u003c\/li\u003e\n      \u003cli\u003e\n\u003cstrong\u003eLow\/Removed:\u003c\/strong\u003e logs without notifying\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eUpdates the baseline\u003c\/strong\u003e by upserting the full current inventory into \u003cstrong\u003ePostgres\u003c\/strong\u003e for the next diff.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS security teams need automated \u003cstrong\u003eattack surface monitoring\u003c\/strong\u003e without manual diffing across sources.\u003c\/li\u003e\n  \u003cli\u003eOperators want quick \u003cstrong\u003enew exposure detection\u003c\/strong\u003e with AI-generated triage notes and severity-based routing.\u003c\/li\u003e\n  \u003cli\u003eCompliance-minded teams need \u003cstrong\u003eunauthorized cloud footprint\u003c\/strong\u003e alerts with optional compliance emails.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n scheduled workflow\u003c\/strong\u003e (every 6 hours)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHTTP Request\u003c\/strong\u003e nodes for three authenticated API sources (header-auth or equivalent)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePostgres\u003c\/strong\u003e for storing and loading the baseline inventory (diff + upsert)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOpenAI\u003c\/strong\u003e for generating concise risk triage narratives\u003c\/li\u003e\n  \u003cli\u003eNotification routing via \u003cstrong\u003eSlack\u003c\/strong\u003e and email\u003c\/li\u003e\n  \u003cli\u003eWorkflow logic uses nodes such as \u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003eset\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003eno op\u003c\/strong\u003e, and \u003cstrong\u003emerge\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45862231703731,"sku":"N8N-18339","price":12.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/TvZ_nN3Dl3lwGqpcBk248_eQw50DuR.png?v=1786957265","url":"https:\/\/buyflowscripts.com\/products\/attack-surface-change-monitoring-with-n8n-postgres-openai","provider":"N8N Commerce","version":"1.0","type":"link"}