{"product_id":"n8n-threat-intel-workflow-url-ip-lookup-via-greynoise-vt","title":"n8n Threat Intel Workflow: URL \u0026 IP Lookup via Greynoise\/VT","description":"\u003ch3\u003eThreat Intel in Minutes: URL \u0026amp; IP Lookup with GreyNoise + VirusTotal (n8n Workflow)\u003c\/h3\u003e\n\u003cp\u003eThis n8n threat intelligence workflow automatically enriches \u003cstrong\u003eURLs and IP addresses\u003c\/strong\u003e using \u003cstrong\u003eGreyNoise\u003c\/strong\u003e and \u003cstrong\u003eVirusTotal\u003c\/strong\u003e. Feed it a URL or IP via a form submission or webhook trigger, and it returns a consolidated reputation and malware assessment—including classification, location, tags, and trust signals.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eStarts from a form submission or webhook trigger\u003c\/strong\u003e and accepts input that may be a URL or an IP.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSplits logic based on input type\u003c\/strong\u003e (IP vs. URL).\u003c\/li\u003e\n  \u003cli\u003eIf the input is an \u003cstrong\u003eIP\u003c\/strong\u003e, it sets an \u003cstrong\u003eip\u003c\/strong\u003e variable to that value.\u003c\/li\u003e\n  \u003cli\u003eIf the input is a \u003cstrong\u003eURL\u003c\/strong\u003e, it performs a \u003cstrong\u003eDNS lookup using Google Public DNS\u003c\/strong\u003e and sets \u003cstrong\u003eip\u003c\/strong\u003e from the lookup results.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEnriches the IP with GreyNoise in two parallel branches\u003c\/strong\u003e:\n    \u003cul\u003e\n      \u003cli\u003e\n\u003cstrong\u003eGreyNoise RIOT IP Lookup\u003c\/strong\u003e for reputation\/benign association.\u003c\/li\u003e\n      \u003cli\u003e\n\u003cstrong\u003eGreyNoise IP Context\u003c\/strong\u003e to evaluate potential threats.\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eMerges\u003c\/strong\u003e GreyNoise results to produce a comprehensive analysis (IP, classification such as benign\/malicious\/unknown, location, tags, category, and trust level).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eInitiates a VirusTotal scan\u003c\/strong\u003e for the URL\/IP, waits \u003cstrong\u003e5 seconds\u003c\/strong\u003e, then \u003cstrong\u003epolls\u003c\/strong\u003e for scan completion.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSummarizes results\u003c\/strong\u003e, including overall vendor analysis outcomes, blockList analysis, OpenPhish analysis, plus the analyzed URL and IP.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSecurity teams enriching indicators from ticketing workflows or webhook feeds.\u003c\/li\u003e\n  \u003cli\u003eSaaS operators checking customer-submitted URLs\/IPs for suspicious activity.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers building an on-demand “threat intel lookup” endpoint inside n8n.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWorkflow control:\u003c\/strong\u003e if, set, code, wait, merge\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations\/automation nodes mentioned:\u003c\/strong\u003e gmail (node included in the workflow), plus threat intel steps for \u003cstrong\u003eGreyNoise\u003c\/strong\u003e (RIOT IP Lookup, IP Context) and \u003cstrong\u003eVirusTotal\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45756679717043,"sku":"N8N-1971","price":5.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/1c2-cTaahzN7B4qHUGwFu_3JZc75k5.png?v=1785748543","url":"https:\/\/buyflowscripts.com\/products\/n8n-threat-intel-workflow-url-ip-lookup-via-greynoise-vt","provider":"N8N Commerce","version":"1.0","type":"link"}