Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)
Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)
Regular price
£13.99
Regular price
£13.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
âš¡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)
Regular price
£13.99
Regular price
£13.99
Sale price
Unit price
/
per
Automatically detect 1Password vault exports and alert your team in TheHive + Slack
This n8n workflow polls the 1Password Events API every 15 minutes to detect vault export activity, then automatically creates an alert in TheHive and posts a detailed Slack notification with a direct link to the incident.
What this workflow does
- Runs on a 15-minute schedule to stay current with recent audit activity.
- Requests the last 24 hours of audit events from the 1Password Events API.
- Filters for vault export events by keeping only items where the object type is vault and the action contains export.
- Extracts key export details, including user, email, vault name/ID, timestamp, source IP, and the event UUID.
- Creates a new TheHive alert with configured severity/TLP/PAP settings, tags, and an export-focused description.
- Posts a Slack message to your selected channel summarizing the incident and linking directly to the created TheHive alert.
Use cases
- Security monitoring: detect and respond quickly when someone exports 1Password vault data.
- Incident response workflows: route vault export activity into TheHive for triage and investigation.
- Operational visibility: notify SOC/IT teams in Slack with context (user, vault, IP, timestamp) and an actionable link.
Technical details
- 1Password Events API via HTTP Request credential (requires access to the auditevents feature).
- n8n nodes: set, http request, filter, split out, sticky note, and slack.
- TheHive integration: add TheHive credentials in n8n, configure the instance URL, and ensure alert creation permissions.
- Link building: update the placeholder TheHive base URL so Slack messages link to the correct TheHive UI.
