Daily CISA KEV Slack Briefing with Gemini & Google Drive (n8n)
Daily CISA KEV Slack Briefing with Gemini & Google Drive (n8n)
Regular price
£67.99
Regular price
£67.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Daily CISA KEV Slack Briefing with Gemini & Google Drive (n8n)
Regular price
£67.99
Regular price
£67.99
Sale price
Unit price
/
per
Get a daily CISA KEV cybersecurity briefing to Slack—enriched with CVSS, exposure context, and Gemini-generated insights
This n8n workflow automatically fetches the latest CISA Known Exploited Vulnerabilities (KEV), enriches each CVE with NVD CVSS data, optionally matches affected versions against your device inventory, and posts a ready-to-read security briefing to Slack—then archives the full payload to Google Drive.
What this workflow does
- Runs daily at 5:30pm (Asia/Bangkok) using a schedule trigger.
- Loads configuration flags and, when enabled, fetches device inventory from your RMM, EDR, and network APIs (or provides a labeled demo fleet / not-configured summary).
- Downloads the CISA KEV JSON feed, keeps the most recent items, and enriches each CVE using the NVD API for CVSS scores and affected version ranges.
- Pulls recent threat context via the Tavily Search API across predefined cybersecurity categories, then normalizes results by recency and relevance.
- Deduplicates CVEs and URLs already reported in the last 30 days, calculates a “top priority” CVE and recurring category trends, and matches KEV affected versions against installed software/firmware on your devices to produce exposure findings.
- Generates a briefing by sending the consolidated KEV, exposure, and news context to Google Gemini to produce a JSON briefing.
- Posts to Slack, including a “Your Exposure” section when matches exist, and archives the JSON payload to Google Drive for audit/history.
Use cases
- Security and IT teams that want an automated CISA KEV Slack briefing every day without manual triage.
- Operators who need KEV-to-asset exposure visibility by correlating NVD version ranges with installed software/firmware.
- Teams that require archived daily security reporting using Google Drive for traceability.
Technical details
- Scheduling: n8n schedule trigger (5:30pm Asia/Bangkok).
- Logic & orchestration: nodes such as if, set, code, merge, and switch.
- Outputs & integrations: Slack for posting, Google Drive for JSON archiving, Google Gemini for briefing generation, and Tavily Search for news context.
- Data sources: CISA KEV JSON feed, NVD API for CVSS and affected version ranges.
