{"product_id":"detect-1password-vault-exports-thehive-slack-alerts-n8n","title":"Detect 1Password Vault Exports: TheHive \u0026 Slack Alerts (n8n)","description":"\u003ch3\u003eAutomatically detect 1Password vault exports and alert your team in TheHive + Slack\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow polls the \u003cstrong\u003e1Password Events API\u003c\/strong\u003e every 15 minutes to detect \u003cstrong\u003evault export\u003c\/strong\u003e activity, then automatically creates an \u003cstrong\u003ealert in TheHive\u003c\/strong\u003e and posts a detailed \u003cstrong\u003eSlack\u003c\/strong\u003e notification with a direct link to the incident.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns on a 15-minute schedule\u003c\/strong\u003e to stay current with recent audit activity.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRequests the last 24 hours\u003c\/strong\u003e of audit events from the 1Password Events API.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eFilters for vault export events\u003c\/strong\u003e by keeping only items where the object type is \u003cem\u003evault\u003c\/em\u003e and the action contains \u003cem\u003eexport\u003c\/em\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eExtracts key export details\u003c\/strong\u003e, including user, email, vault name\/ID, timestamp, source IP, and the event UUID.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCreates a new TheHive alert\u003c\/strong\u003e with configured severity\/TLP\/PAP settings, tags, and an export-focused description.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePosts a Slack message\u003c\/strong\u003e to your selected channel summarizing the incident and linking directly to the created TheHive alert.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSecurity monitoring:\u003c\/strong\u003e detect and respond quickly when someone exports 1Password vault data.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIncident response workflows:\u003c\/strong\u003e route vault export activity into TheHive for triage and investigation.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOperational visibility:\u003c\/strong\u003e notify SOC\/IT teams in Slack with context (user, vault, IP, timestamp) and an actionable link.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003e1Password Events API\u003c\/strong\u003e via HTTP Request credential (requires access to the \u003cem\u003eauditevents\u003c\/em\u003e feature).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes:\u003c\/strong\u003e \u003cem\u003eset\u003c\/em\u003e, \u003cem\u003ehttp request\u003c\/em\u003e, \u003cem\u003efilter\u003c\/em\u003e, \u003cem\u003esplit out\u003c\/em\u003e, \u003cem\u003esticky note\u003c\/em\u003e, and \u003cem\u003eslack\u003c\/em\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTheHive integration:\u003c\/strong\u003e add TheHive credentials in n8n, configure the instance URL, and ensure alert creation permissions.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eLink building:\u003c\/strong\u003e update the placeholder \u003cem\u003eTheHive base URL\u003c\/em\u003e so Slack messages link to the correct TheHive UI.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46094162526387,"sku":"N8N-19940","price":13.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/GhTSht3VDXasruF-LKWmz_CaIxZ0HK.png?v=1790413771","url":"https:\/\/buyflowscripts.com\/products\/detect-1password-vault-exports-thehive-slack-alerts-n8n","provider":"N8N Commerce","version":"1.0","type":"link"}