Skip to product information

Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)

Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)

 (200+Reviews)
Regular price £13.99
Regular price £13.99 Sale price
SAVE Sold out
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
🔥
128+ Sold
Popular with n8n builders
âš¡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)

Detect 1Password Vault Exports: TheHive & Slack Alerts (n8n)

Regular price £13.99
Regular price £13.99 Sale price
SAVE Sold out

Automatically detect 1Password vault exports and alert your team in TheHive + Slack

This n8n workflow polls the 1Password Events API every 15 minutes to detect vault export activity, then automatically creates an alert in TheHive and posts a detailed Slack notification with a direct link to the incident.

What this workflow does

  • Runs on a 15-minute schedule to stay current with recent audit activity.
  • Requests the last 24 hours of audit events from the 1Password Events API.
  • Filters for vault export events by keeping only items where the object type is vault and the action contains export.
  • Extracts key export details, including user, email, vault name/ID, timestamp, source IP, and the event UUID.
  • Creates a new TheHive alert with configured severity/TLP/PAP settings, tags, and an export-focused description.
  • Posts a Slack message to your selected channel summarizing the incident and linking directly to the created TheHive alert.

Use cases

  • Security monitoring: detect and respond quickly when someone exports 1Password vault data.
  • Incident response workflows: route vault export activity into TheHive for triage and investigation.
  • Operational visibility: notify SOC/IT teams in Slack with context (user, vault, IP, timestamp) and an actionable link.

Technical details

  • 1Password Events API via HTTP Request credential (requires access to the auditevents feature).
  • n8n nodes: set, http request, filter, split out, sticky note, and slack.
  • TheHive integration: add TheHive credentials in n8n, configure the instance URL, and ensure alert creation permissions.
  • Link building: update the placeholder TheHive base URL so Slack messages link to the correct TheHive UI.
View full details