The n8n Masterclass
Welcome to The n8n Masterclass. I’m Dylan Watkins.
Each week we break down real business wins using n8n and AI automation. You’ll learn what worked, why it worked, and what broke along the way. Founders, automation experts, and AI agencies share how they use n8n to simplify operations, scale delivery, and move faster without adding more people.
The n8n Masterclass is not about tutorials or tech jargon. It focuses on the real business side of automation, the frameworks, decision patterns, and creative problem solving that turn workflows into results.
You’ll leave every episode with one principle, one pattern, and one action you can apply this week to grow your business, reduce manual work, and unlock the potential of automation.
If you’re building a business that runs on smart systems, AI, and no-code tools, this is your playbook for scaling with n8n. Follow The n8n Masterclass and start using automation as your competitive edge.
The n8n Masterclass
I Automated My Home Security With n8n (Free Workflows Inside)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
If you want this home security setup, go here: https://go.n8n.io/buddy
You get the free step-by-step guide and Buddy's self-hosted cyber lab.
Your home network is being probed right now, and most people have no idea. Buddy, a cybersecurity professional and solutions engineer at n8n, built two automation workflows that change that.
In this episode, Buddy walks through how to use n8n to automatically scan incoming Gmail for phishing links using VirusTotal, and how to monitor your firewall for blocked threats, enriching each alert with VirusTotal, URLScan, and MISP in under 10 seconds.
These workflows work for homeowners with a smart device setup and for small businesses protecting employee inboxes alike. Buddy covers phishing detection, firewall threat enrichment, lateral movement, ransomware, prompt injection risks, and personal data exposure from breaches like National Public Data.
The conversation ends with a practical cybersecurity checklist: password managers, app-based two-factor authentication, social media verification, and keeping software updated. Links to the workflows, the GitHub repo, a setup guide, and a hardware recommendation are all below.
🎙 Chapters:
00:00 - Intro: What This Episode Covers
01:48 - Phishing Email Workflow Demo
05:50 - What Is VirusTotal?
07:00 - Auto-Tagging Confirmed Phishing in Gmail
09:27 - Real-World Phishing Attack Stories
14:00 - Lateral Movement and Ransomware Explained
16:08 - Firewall Monitoring Workflow and Ubiquiti Setup
20:00 - Geo-Blocking and Incoming Connection Threats
21:44 - URLScan, MISP, and Threat Enrichment
27:53 - Full Workflow Walkthrough: Soup to Nuts
37:07 - Dark Web Data Exposure and Identity Theft
43:41 - Why Use n8n for Cybersecurity Automation
46:23 - AI Agents, Prompt Injection, and Future Threats
48:47 - Personal Security Checklist and Best Practices
52:11 - Closing Thoughts and Next Steps
Get 30% Off n8n Cloud Starter or Pro Plans!
Want to get started with n8n? Visit n8n.io/pricing and use code 2025-N8N-PODCAST-729C416E at checkout for 30% off your first month or year.
You have Debbie from accounting who is not up to speed on phishing emails. And Debbie clicks a link that is suspicious. She clicks, you know, Adobe PDF.exe. Debbie's machine gets infected. The bad actors then are able to steal all the credentials from her machine, get access to your your QuickBook and your Stripe account and start exfiltrating your customers' data. This source was China and the destination was my home. So this is where someone in China tried to Telnet to my house. And this was blocked. We started off with just what is your name and what is your work email. And in 99.95% of cases, we were able to then take those details, determine what was their personal email, where did they live, who were their family, because what passwords did they have.
SPEAKER_01There are people trying to get into your network right now. Whether you run a business or just a house full of smart devices, buddy spent years in cybersecurity before joining Inate Inn. In this episode, he turns Inate Inn into a real Cybersecurity tool that you can run at your home or your business. He built two workflows. The first watches are Gmail, it pulls every link of every suspicious email, then runs it through Firus Total, and then tags it to confirm 50 or false positive on its own. The second watches your firewall, the moment something gets blocked, it enriches that threat with virus total and URL scan and MISP and hands you a full port in seconds. After we recorded, Buddy gave me his GitHub repo. So I rebuilt the whole thing on my own home network. I picked up an enterprise security router, ran his workflow, and went through the setup myself. I then wrote a step-by-step guide so you can do the exact same thing at your home or in your business. The link to the files and the guides are down below. Buddy, welcome to Showbrother. So glad to have you be here. What did we learn today?
SPEAKER_00Thanks for having me, uh Dylan. So today we're going to learn a couple different use cases that someone could use in AidN in their personal and professional life to automate different cybersecurity concerns that they may have. Fantastic.
SPEAKER_01I would love for you to share your screen and show us the workflows that you've been building out. And also, we will be covering some of these very uh amazing and also terrifying situations that people are mostly unaware of. Uh things that I wasn't aware of and some things that uh Buddy has recently brought to my attention that now makes me want to reflect on my own personal cybersecurity I have going on in my house.
SPEAKER_00So here we go. So the the first one here, before I even dive into the workflow, let me let me walk you through a real life scenario. So you have Debbie from accounting who is not up to stuff, up to speed on phishing emails. And Debbie clicks a link that is suspicious. She clicks, you know, Adobe PDF.exe uh that's attached to her email that's that's an invoice from a vendor. Debbie's machine gets infected. They the bad actors then are able to steal all the credentials from her machine, get access to your your QuickBooks, your accounting, to your Stripe account, and start exfiltrating your customers' data and start making unauthorized charges. With this workflow that I'm getting ready to show you, um, it is narrowly scoped to things that are reported phishing, but this can easily be adapted to every incoming email to your Gmail, run it through this flow and auto-tag for you. So, with that said, this workflow here um will automatically grab any emails that said in Gmail that have a label of reported phishing. And I'm actually going to run this on a phishing email that I personally received. Um, images are already taken down now, so boo. Uh, but this did look did have uh an Apple logo. Um, as you can see there, it says iCloud. And this little link at the bottom, you notice at the very bottom of my screen, right? It says let's let's go momo.us.com. But I received this email to my personal um email and I've just forwarded it over to my N email and I replied a label. Let me let me let me look reload this. This should have a label on it. It does not let me apply label of reported phishing. Apply. Ah, there's what I forgot to click earlier. Perfect. So now that I click that, if I turn this workflow on every 10 minutes, this will check my Gmail account to look for any emails that are tagged that. But again, this can easily be changed to where the trigger is every email that comes into your Gmail. But what this is going to do is any items that are tagged for me, recorded phishing, it's gonna pull all those emails into this particular workflow. It is then going to get the exact message. And in my case, since I forwarded the email over, I have a full email um headers and everything else. I do need to recompose the message itself so that I retain that. As someone who is well versed in cyber, what us guys care about is are the email headers. And I don't know why Google's being funky. Um, it needs to be able to let me see see this within the message itself. But anyhow, since the email is as an attachment, I go through this workflow and these first two steps here are recomposing the email back into a format that N8N can read. So if I were to pull this open here, right, we can see the to, the from, subject, etc. Whereas before it's just this big binary blob, blob blob, binary blob of data that is not parsable, not easy to read. This code here uh again translates it over to something the NADN can parse and utilize. From there, we extract out every one of the links go that are contained in the email. We then send that over to VirusTotal where we prepare the request for VirusTotal. In that request, we also then check to see does VirusTotal already know about this thing? If so, we're just gonna pull those results.
SPEAKER_01If I think just real quick, just so we know, what is VirusTotal?
SPEAKER_00Sure. So VirusTotal is a place that you could go and input um file hashes, URLs that tell you what the analysis is of a particular website. I'll pull that up and show you as well here once I run the workflow so you can see what that would look like. One of the really, really useful things about it is they provide the analysis of any type of malware of how many antiviruses have detected a particular piece of malware or if a website is already known to be bad. Got it. Got it. In this workflow, if virus total didn't know about it, had never seen it, we're gonna submit that. Uh this triage score here then lets us know how many detections have already been found um or are known of or reported from this particular URL to determine a criticality rating. So how critical is this? How how do you need to react? If it meets the criteria here to be malicious or suspicious, it's then going to add a label for me of confirmed phishing. It's also if it's not, sorry, if it's clean, it's going to add a false positive tag onto it. If it is confirmed phishing, it's also gonna tag it as analysis completed so that I know for sure that my workflow has ran and fully progressed through there. And it's also gonna remove this reported phishing tag that we put on there earlier. So let me move this out of the way, and I'm just gonna execute the workflow here real quick and we'll see it run through, grab the email. Perfect. Awesome. It's already ran, and just to show you for buyers total since you asked about it, let me go to let me go to this bar total URL right here. Oh no, my API key is missing out of N itin. No way no. Oh, because I'll try to get the API URL. No wonder. Alright, uh, one second. If I manually were to go and input the URL in the virus total, we'll actually see what it looks like. We can edit that out. Let me copy this item. Let me just go to virus total right here. So within VirusTotal again, you can put in any um file hash. Uh typically this is going to be what's called an MD5, SHA1, or SHA Q56. Those are just different algorithms that will compute a file to a new variable to reference and identify that particular file. In my case, I want to give it a URL. So that's not what I copied. Terrible demos. Uh by the way, in in life, as uh someone who's on solutions engineering, there's two things that will make a liar out of you, and that is kids and live demos.
SPEAKER_01Yeah, yeah. I always call it uh uh uh curse of the live demo. You know, you always you always have those uh live demo demons that are always plaguing you inside of here. But as you get this pulled up though, I do think it's important to talk about the fact that like the cybersecurity thing is that maybe you might be younger and hip to it, and you understand that if you see something from from Gmail or from Google or YouTube and you you understand not to click it, but a lot of people don't, right? And so it just takes any person in your company at all that is just not paying attention or unaware that that message that they got isn't actually from the government or the IRS or name name whatever respectable body of uh you know monitoring services. And so this is really important for you know, deploying this across all of your employees to make sure that it detects any of these phishing use cases.
SPEAKER_00Absolutely. And and one thing I do want to note, um something that I've observed in prior companies, uh given that I worked in cybersecurity, is that a lot of the newer ones, they may not have a link for you to click. But what they will do is send you a fake email that says that your invoice is due, say through PayPal or any other payment provider, and then they'll put in their phone number uh for you to call and interact with them, which if you were to do that, they use tactics that stress a level and sense of urgency for you to then say, well, don't worry, I'm here to help you. Let's let me get connected to your machine via Team Viewer or you know, VNC application um or um any desk is another fairly common vector. And once they're attached to the machine, they'll then say, Oh, well, let's look at your bank, let's look at the statements to see if the charge is there. And then what they'll do is they'll lock your screen so you can't put any input in and they'll start transferring money out of your account.
SPEAKER_01Uh, awesome. Good to know. Yeah, yeah, yeah. There's there's a lot of different ways that people have. And I know you actually have some some funny stories that we'll have you get into at another point, uh, being in the cybersecurity space of ways that you've demoed to people that thought that they were safe, that they weren't safe, but we're gonna save that for a hot second. Let's talk about what's on the screen and then we'll get we're gonna get to that.
SPEAKER_00For sure. So here's where I just manually queried buyer total for that same URL that was in that phishing email. And we can see that these six companies flag this as malicious. All right. So without me even having to do any further thing, I know that this is a bad website. Do not go to this website, which is the intent behind this workflow, is to do that categorization lookup for me instantaneously. So again, it can be modified instead of every 10 minutes and instead of those that are tagged, just to run on every email coming in, just check every link that's in all the emails. And if any of them are suspicious, fly the email. You can have it, you know, auto-archived so you don't see it, and you can tag it the the world you oyster really, uh, with what you can do with it once you have this analysis available to you.
SPEAKER_01Fantastic. Yeah, and I can absolutely see that the value of this system and getting it deployed across um, you know, all of you know, all of your employees, or even yourself, or even having on your own computer. Um, I I've known several friends uh that have been hit from with phishing uh issues. And so yeah. One of the things I know is um well, actually let's talk about this. Like as you're as you're looking this up right now, um, you know, what are some stories that you know of personally of people that have have had um it could be fishing attacks or other types of cybersecurity things where they they slipped up and they did a thing that they weren't supposed to, and because of that they they ended up exposing themselves and and it could be financial issues or uh ransoms or whatever might have popped up.
SPEAKER_00Sure. So all of those apply. I've I've I've seen it happen to where the the vector, once they're in a typical TTP or tool tastics procedure for any bad actors, once they're in a network, they'll then do lateral movement. So they'll try to infect a secondary machine before they try to do any attacks. The reason being, right, if Debbie's a machine, if Debbie goes to IT and it's like, hey, I was compromised 10 minutes ago, within that 10 minutes, they're already on another machine. So hard to be clean, but they're somewhere else in the network as well.
SPEAKER_01So it's really important for the speed to be notified that if you do get compromised, how quickly it is, because in the cybersecurity world, it's like minutes or days and days or you know, years.
SPEAKER_00Correct, correct. Uh that's it is there's some bad actors who stay in networks for months before they get um detected, which is isn't good because they're they'll exfiltrate a ton, ton of data. Uh I was reading a report yesterday on a company that they were compromised back in like November of last year and didn't get caught up until April of this year. And it was a pharmaceutical company, and they exfiltrated uh like four and a half terabytes worth of data um from the company and then put them they didn't ransom their data, but they then threatened to post all of that pharmaceutical data to the web if they weren't paid uh some hush money.
SPEAKER_01Sure. That's a that's pretty much a ransom.
SPEAKER_00Yes, yes. So well, I I don't use the term ransomware for that because of a ransomware would encrypt all the files and then it'd be posted on the dark web with a thread of that, which is the uh another common one that you'll see as well.
SPEAKER_01True, yeah, that's true. The difference between ransom and ransomware for sure.
SPEAKER_00Yes.
SPEAKER_01Okay, so so this is it right here. We have got a we got a great workflow that sh show anybody can use to get up and running. And um ideally we can make this available in some way capacity that people could be able to have access to that. Is this correct?
SPEAKER_00Correct, correct. So I intend today is uh 15th of May. Um I intend by next next Friday to have this publicly available as well as a loom recording, or we can send them this video um on this workflow so others can begin to utilize and implement it.
SPEAKER_01Fantastic. And um do we have any other workflows you'd like to get into to show off today?
SPEAKER_00Yeah, yeah, absolutely. I've I've got quite a few here. Let me let me just close these out real quick. And I do want to show here that um I took it a minute, I had to refresh Google a couple times for it to actually pick up where those tags were applied to where this is confirmed phishing and analysis has been completed to show that the workflow did run through um end to end for me.
SPEAKER_01Great, yeah.
SPEAKER_00Oh, and one more thing. The the reason that I use that tag um is because we're using Gmail, but in most organizations in Outlook, there's a report phishing button which sends the email to a particular dedicated mailbox. So me putting the tag on it for us since we're using Gmail allows me to simulate or replicate that same type of setup.
SPEAKER_01For sure, yeah. And with the tags, you can trigger not another automation inside of Gmail.
SPEAKER_00Correct. Correct. So the um next workflow here that I can show you is uh if you get a firewall alert. So say Debbie does click that link, and that link is on a known bad list that you're looking at with your firewall. Like me personally, um here at home, I use Ubiquity, and Ubiquity has a block list that can be can be implemented. And I'm gonna have to log in. Uh well, I can just get logging into my Ubiquity. Uh but it has a as a black list that can be implemented so it can be there for alerting and monitoring. And in that scenario, you could have N8N be a receiver of those logs.
SPEAKER_01So what is can you can you explain what Ubiquity is again?
SPEAKER_00Yeah, yeah. So Ubiquity makes prosumer hardware. Uh it's called ProSumer because it's for professionals for businesses, but you can absolutely use them at home. They're much better than your Netgear, your Linksys, uh, your typical hardware that that most people would run at home because of the granularity, access controls, et cetera, that they provide, such as the unified threat management of pulling in those those block lists. Like if people are familiar with like ad block, ublock, you can get the same type of thing, but at the firewall level. So for example, my iPhone, right? There's no ad block Safari has an ad blocker built in, but it's nowhere near the extent that u block, adblock can do. Um, or you know, a switch, or even if you have a smart TV that has ads on it, right? You can block those at the firewall level using Ubiquity so that there's not a dedicated app for the device, but you're blocking it before it even egresses or leaves your network.
SPEAKER_01Amazing. So just if you hate ads, this would be this would serve you.
SPEAKER_00Yes, yes, yes, yes.
SPEAKER_01Okay, great. So so this is a hardware device that that at the firewall level allows you to to block any types of links or IP addresses or anything else. So it gives you a lot more control um at that level, which then you're using that in conjunction with this workflow, correct?
SPEAKER_00Correct, correct. Um, so on this one, I'm simulating the call, um, just for the purposes of this demonstration, but it that is absolutely possible. And let me give me just a moment here. I'll actually log into my Ubiquity to show you what that would look like um in an actual practice here.
SPEAKER_01I'm logging in off screen, so give me just a moment. Come on, put your email credentials inside the screen. Totally fine. No one's watching.
SPEAKER_00Yeah, we're only recording, no big deal. Um one moment. Insights. Okay. So this is my um ubiquity setup. So we can see here just from the logs, right, that I already have threats that are being blocked and log. Some of these are just ads, but some of them are also country filters. Like there's no, there's no reason why anything at my home should be reaching out to China, for example. So I geo block any requests to China. I can set up ubiquity to then, if there's anything that triggers any of these, send them to this webhook that's within N8N and do analysis for me, which is what I'm going to demonstrate in this workflow. Got it. So you can also see over here the the ad blocking.
SPEAKER_01And just to uh just so I understand it for clarity's sake, for me and maybe anybody else that also is unclear, uh, this is essentially a a more or less like a like a modem or a router of some kind that would sit there, or does it sit in between like I'm trying to understand? Like if I have an ATT router, for example, right? Would that would this be in front of that or how would this work?
SPEAKER_00So um it depends upon your network provider, but it would either be in front of that or right behind it. Um for me, for example, I've got fiber internet coming in through Winstream, and then I can show you my network topology here so that you can see, right? So here's my internet connection coming in through Winstream, and then I have a UDM SE, which is the name of the name of the name of the device um that I have that actually looks like this. You don't have to get uh this one, they have a more consumer version. It's just I I like this one in particular so I can handle all the load of of my network. Um, as you see, my network scales out fairly large, so there's a ton of devices on my network with my kids and their iPhones, iPads, smart TVs that are hooked up, so on and and so forth. Um, but you can see here I also got several access points, switches, and everything else set up. I'm in um pretty deep in the Ubiquity stack, but you don't have to go that deep. If you have just that front layer uh coming in, like I have the UDMSE here, it will provide you these features because it's the internet, that, and then everything else is behind it. So it will be central to doing all of these functions.
SPEAKER_01Got it. Okay, cool. So you put that as a frontline defense, and then that frontline defense right now you're simulating, then you can put like geoblack, like like, yeah, why why ever would my device be reaching out to China, for example?
SPEAKER_00Correct. I mean, you you could have an affected device. Um, it it it could be an ad from a website as well that's hosted in China. There's an umpting number of right umteing number of reasons, and then in this case, this UC source was China and the destination was my home. So this is where someone in China tried to tailnet to my house, and this was blocked. Oh so that's an incoming connection, not an egress connection. Yeah, yeah. Geo blocking still blocks that based upon where it's coming from.
SPEAKER_01Got it. Okay, so that's okay, so that's that gets my attention. I'm paying attention for the this coming through. Um, so okay, so you put this in place. Please go to the workflow. Uh, show us the workflow, and then if anything needs to run and there's downtime, we'll talk about some some other uh situations.
SPEAKER_00Yeah, sure. So this workflow, similar to the other one, I'm using virus total again as well to check the the incoming URL um for this example. Then also I'm using another third party service called URL scan, which is very, very useful. Because with URL scan, let me actually um pull this one up here for visual demonstration. URL scan will actually go to that website and pull down a screenshot of what the website currently looks like. And then in my case, where I was talking about at the beginning, right, there's IOCs or indicators or indicators of compromise that can be used. It gives me all of those. It lets me know any requests that website is also trying to make in tandem. Any redirects, any links on the page. So very, very useful things for anyone who's in cyber or wants to do a more in-depth investigation. And especially you said this, this web page here. Like this is literally what the web page has on it that says that it's suspicious phishing and has a cloud player um button on it. A lot of times a new vector that you'll see as well is you'll see these fake captchas where they'll have people download and run a PowerShell command on Windows or in a terminal command on the Mac, which is then the initial vector that a bad actor would get on their machine. Got it.
SPEAKER_01Yeah. And it's also one of the things to be very aware of, especially with this whole like OpenClaw craze in people that are, you know, downloading OpenClaw onto their computer. And then there's all these uh marketplaces that would have open claw, you know, add-ons and everything else. And then all of a sudden you're running all these terminal commands, or you're having the AI run the terminal commands, or there's something stuffed inside a markdown file. Incredibly easy with all of these terminal-level CLI commands being flung around for a bad actor to get access to your system.
SPEAKER_00Absolutely. Um prompt injection is a real a real thing, a real big risk that is presented when you're using any autonomous AI agent. Although I will say if you're using um Claude Opus, it's pretty good at detecting those, but it's not always guaranteed. Like it's one of the things that is an inherent risk when using an LLM. I was reading another story yesterday where somebody was using um either Chat GPT or Claude and having it do some market research for them. And the AI actually returned back, hey, FYI, this page had a prompt injection trying to alter the results that were returned to show that they're more magitimate and that they should be preferred or be any other source that was retrieved as part of the context for here. Wow.
unknownWow.
SPEAKER_00So it's not always for which is for infecting your machine, but it could be used, said in in that case to sway an AI um any recommendations that it gives.
SPEAKER_01For sure. Okay, that's good to know. Um, so just beware that that, yeah, it it comes in all flavors.
SPEAKER_00Absolutely, absolutely. So this workflow, like I said, uh I've I got a uh sample uh URL here, a source machine, um any other machine as well on the network that may have visited a request that is then I said as a report, send over which we buyers total, sent to URL scan. I merge those results, and in my case for N8N, I'm also sending this over to MISP. MISP is a malware information sharing platform. It's something that's small business, medium-sized businesses could be running, but you as well can run at home. It is free and open source. I'm personally currently running this in Docker for this example as well.
SPEAKER_01And what is it, what does it do? What does MISP do?
SPEAKER_00Yeah, sure. I'm glad that you asked. So this is actually going to create an event in MISP. So I have all the surrounding details of this is the URL that was visited. This was the machine, this was the destination. And then MISP is also going to hold this data from virus total and URL scan in one place for me. As someone that's in cyber and an analyst would then use that to say, okay, we need to distribute these to our firewall, we need to distribute these to this other place, or we need to create a report based upon this because we had a machine reached out to here that maybe send that to the internal IT to go investigate the machine as an example.
SPEAKER_01Got it. Okay. So it's yeah, so it's it's it's gathered and holding on to any of these um malicious sources to then be distributed.
SPEAKER_00Correct. And MISP also allows you to do correlation as well. So there are different um open source threat intelligence feeds that are available. MISP comes with quite a few um as a default, which is what you're gonna see, which whenever you're creating an event, MISP allows you to correlate upon any indicators that it already has or knows. So you can get further context and enrichment and more data from a singular event, putting it inside of that type of platform rather than saving it to say Google Doc, right? Because you're not gonna be able to pivot and get more and more contextual data or information that way.
SPEAKER_01Okay, it's a it's a malicious enrichment source.
SPEAKER_00Yeah.
SPEAKER_01Yeah, nothing.
SPEAKER_00In labor terms, yes.
SPEAKER_01I'm just translating it into my own brain so I can understand the terminology. All right, this is great.
SPEAKER_00I'm gonna let this run real quick. Um again, noting that that URL that I submitted in right is point urbanridge.ru service verification.google. And now if I come over here to MISP, let me zoom out. And let me reload. Let me get this Google tab over here out of my way. Here's the event that was just created. And we see it says firewall URL and enrichment for this particular URL. There are automatically tags applied to this for me, letting me know that if you were to visit this page, it downloads malware, right? Root red alert, that's that's a big problem, right? A machine on my network has visited this and I know it downloads malware before I've even clicked in, before I've done anything else. It got this from both virus total and URL scan, the data that's available from both of those. And I also tag it in MISP with workflow automated enrichment so that I know that this is where this came from and that it's already been um enriched again. Knowing that a workflow is executed is something that I'm very, very big on. So I have some type of visual indicator to reference back.
SPEAKER_01Sure. Been processed.
SPEAKER_00Yes.
SPEAKER_01Yes.
SPEAKER_00So now when I open this up, right, I can see at the very top um what we talked about a moment ago, that the the name of the event over here to the far right. There's where I ran an event before, but we can see, right, these other threat feeds that are native default provided from MISP are showing me this URL is known to be in these particular threat feeds and when they were published.
unknownRight.
SPEAKER_00So this one is fairly interesting because there's probably more surrounding context and details for this one. Oh wow. So that one page has led me now to a bunch of indicators, a bunch of different things that someone who's in Threat Intel would want to make sure not only am I blocking that, but I need to be aware of these as well and look for any of these if I'm not already blocking them. But going back over to this event to make it simpler because I know that's a lot that is just uh toss at you. With this event, when I scroll down, there's the link for virus total. So if I wanted to manually go look at the event in Virus Total, I could easily click it and go look, and it it's it's like a Dagon Christmas tree here, right? There's a bunch of red, bunch of you know, red flags going on with this. That hey, this is really a malicious website, no one should be going to this.
SPEAKER_01For sure.
SPEAKER_00Additionally, I condensed down those results to make it very easy to read and understand. So I don't have to click it over. I got the uh the results here available for me. So there's the URL scan verdict, here's the virus total verdict, which both of these are where um from the virus total details is where I was able to flag it that hey, this downloads malware, right? Because they're telling me here this downloads malware. Also log just the base domain so I can make sure I'm not blocking just the path, but the domain as well. Because if that website is hosting a malicious URL, the website itself is likely also malicious too. And then of course I have my IP source, so my machine that initiated the alert, and then I also have the destination, which wasn't already included from the power details. So a bunch of details here that I can use to block, enrich, and enact from as someone who's interested in cyber.
SPEAKER_01And I just want to note that if you didn't have this system in place, you would never know that any of this would be happening. You wouldn't know that anybody would be trying to connect to your your network through China. Uh, you would never know that uh there'd be downloading malware and spyware, and this this would just be you'd just be thinking that your system's completely secure.
SPEAKER_00You'd be none the wiser. None the wiser.
SPEAKER_01Everything seems fine. Everything seems fine.
SPEAKER_00But and I mean if you if you have uh antivirus on your machine, it may catch it. So if you if you had any of the um antiviruses that are listed up here, they would catch it. But that is the other anomaly, right? There's only 18 of 95 known antiviruses that captured this and flagged it. So there's this other chunk. So if I'm running uh, let's see if what other one here's a well-known one, probably that didn't catch it. So XeroFox, right? XeroFox is a known threat intelligence vendor. They didn't flag it. Yeah.
SPEAKER_01So wow. Okay, yeah. So you're so yeah, so it's cross-referenced across all of the all of the um threat detection services and saying, okay, well, this, you know, one caught it or eight caught it, or and you can see if you have one, you feel like you're completely secure, but this is really shows you that you're not.
SPEAKER_00Correct. And so in my case, um the results there are vendors who do cybersecurity and not the malware scanners because I didn't use a hash. But give me just a moment here. I'll actually I'm trying to find one real quick to um to demonstrate, to demonstrate what that would look like because it's one real, real useful thing with this is with the file hash, it does check. It does check against known antiviruses to say these are the ones we're actually detecting detecting this or not. Um, I think I actually have a file hash um in here in the event.
SPEAKER_01Well, actually, and after that, let's go back to the workflow because I do want to work for want to go through the workflow to understand the whole soup to nuts of what you have in place here.
SPEAKER_00Yeah, sure. Uh let me grab this file hash right here, just as an example. So if I go back over to virus total, we can place the URL with the file hash, right? That was detected quite a bit, but there's just an example. There's still nine antivirus vendors that didn't catch this one, whereas the other ones did. So if you happen to be unluckily running any of these, they said that this this is good. The hacker got hacked. Yeah, this is great. Yeah, this particular hash has been known since 2018. That's the one I grabbed from 2018, right? So there's still some that don't flag it. So you could be none the wiser. And in this case, I used an old hash, but if that's a brand new piece of malware that's never been seen before, your antivirus isn't guaranteed to catch it. You literally could be none the wiser for who knows how long until it does get detected and until your antivirus does run, you know, a scan.
SPEAKER_01Yeah, and this is evolving so quickly because, like, I mean, with the whole thing of like mythos coming out and the the all these different exploits that are that are happening inside of cybersecurity world, the more people are becoming empowered with AI and automation, the more that bad actors have more power and capabilities, uh, the the more uh intent and onus it is on the user, the consumer to protect themselves. Because you, you know, we all see these cold emails that go out to us. It's very obvious, well, for most people, it's very obvious that you see these cold emails go out, you're like spam. And spam has, you know, multiplied a hundred X in the last five years, a thousand X in the last five years. I'm sure the same is happening with cybersecurity. We just can't see it. You can see a bad email come in, and Google's doing what they can to block it, or Microsoft or whoever your ISP is. But this is something that is un an unseen danger. And I'm not here to like put the fear of God into anybody of like, you know, oh, be terrified, but it's just mostly be educated. And this is actually this is very educational for me. Like, I'm I want to go and get this type of system and put it on my own uh you know, home lab infrastructure that I have, and and just out of curiosity to see what pops up, what detections happen. So um this is great. Could you just run me through the the workflow here, stupid nuts on the kind of what it is and how it works? That we kind of got into the mist and we kind of popped in and out of it. So I do kind of want to take like a 50,000 foot view of the system, and then and then we can uh just so I can wrap my head around the whole thing.
SPEAKER_00Sure. So to to review it here, right? So the alert comes in through the through the webhook. So my ubiquity catches that firewall block, sends it over, triggers this workflow. This then goes through virus total and URL scan. This merges those results. So I have a single result set that I'm analyzing together rather than one at a time. I then compose what MISP would need in their in their format to ingest that data. I then create the attributes and the events. Sorry, create the event in MISP, and then I add the different attributes to there. And the attributes are the other items, so all the other different indicators for it as the initial create just creates the event that says, hey, here's the URL, here's the um analysis for the header that you've seen within MISP, but it doesn't include any of those other details.
SPEAKER_01Got it.
SPEAKER_00And then from there, this just loops through adding all those attributes because the way that MISP is encoded, you have to submit each attribute individually. And the same thing for tags, you have to submit each tag one at a time. So this loops through all of the different attributes, all the different tags, and composes that entire event for you. But the beauty of it was this ran in eight seconds to do all of that. Whereas if you were manually looking at a firewall, manually looking at a virus total, that's a ton of copy pasting, right? You're spending 30 minutes just looking at it, understanding it before you decide what you're gonna copy paste, what's important, what's not. Whereas that in an automated way, you would have those continually available for you in eight seconds with all the data there um available to you.
SPEAKER_01And so this is being okay. So here's what I'm here's my big takeaway with this. So essentially, this is monitoring any of your traffic going in and out of whatever facility you have, whether it's a home or a business that's going on. It's able to monitor and cross-reference any of this traffic to see is this malicious, is there anything about it that's suspicious? And then taking that and uh enriching it with additional data sources and then reporting back on that and and running through this process that then allows you to know within eight seconds, is this something that should be flagged, or should you know, should it something that we should be blocked, or you know what should we be what we should be aware of? And then in terms of the notification, like so, like if I want to get notified, if something like this is a red alert and I should pay attention and you know, you know, take bolt cutters to my Wi-Fi. Uh no, what should what like how do I get notified? What what would you do here for this?
SPEAKER_00Yeah, sure. So um once if this runs through to this node, that means there's something to look at. So here I'm done, I put no operation, but you could easily replace this with Gmail, with Slack, Telegram, uh, any of the other integrations that that we have or offer for whatever medium it is that you would like to receive that notification on.
SPEAKER_01Yeah. It's really interesting. It's really interesting to me because also I'm I'm thinking about doing that, but I'm also one of the other things coming up to me is like also maybe running some sort of like, and I don't know if you've ever done this for like like uh whether it's a home system, home lab, or a business, like having AI look at this and you know, having tickets created saying, hey, these are some of the issues that we recommend blocking. Should we take this action across your network or some sort of like AI that could then process this information? Because obviously if you go to sleep and you're asleep for eight hours and this happens in eight seconds while you're sleeping, is there something that you would recommend? Because I do think human in the loop is going to be critical and important to get notified. But there are any thoughts around implementing some sort of AI system that could help handle maybe some of the low-level stuff or some sort of like triage the wound while you're sleeping?
SPEAKER_00Sure. So in those in those events, in those cases, right, I would I would enhance this workflow to have the AI agent here when the workflow is done. And then to have it pull back any of those other related events. So what other details, what maybe am I missing, and then have those then sent over to my firewall to block to further refine the attack surface that I'm that I may not be looking for that may be missed. Um, because there's you know, there's other file hashes that are in there, other URLs, domains that aren't in the initial report because it doesn't know about them. But using MISP, it has the additional context that you can then pivot off of, pull those back down, ensure those are blocked as well.
SPEAKER_01Got it. And let's talk about this real quick. Um actually, uh one thing I want to I want to note, I do want to talk about a thing. I'm gonna put a pin on it, but I want to get to it, is um, you had a thing with your previous company where people think that they're secure, and then you'd have a meeting to let them know that they're not secure. Can you just tell me a little bit about what that thing was, what happened? Uh so anybody here who thinks that they are secure, uh, how what what would you do?
SPEAKER_00Sure. So at a prior company, we did protection for individuals, not for businesses. We started off with just what is your name, first and last name, and what is your work email? And in 99.95% of cases, we were able to then take those details, determine what was their personal emails, where did they live, who were their family. More more importantly, for cybersecurity side, is what passwords did they have as well. So the the tool that we had developed looked up several different sources, it checked the dark web, would pull in those breaches, it would deduplicate it and compile for us an easy digest to digest and understand report um with every one of those details. So it could be passwords, it could be phone numbers, it could be your your home address that's contained in there, it could be your social security number, um, can be on the dark web um as well. If you remember last year before last, there was a big um data broker that was breached. Give me just a second here, let me actually um pull it off. Um that that was breached and like literally like most of the US population was contained in it. Uh national public data, that's who it was. So let me pull that up real quick. Here we go. Good old Wikipedia here, right? So national public data was breached and they leaked um 2.9 billion records, and that had people's names, addresses, special security numbers. You were able to then pivot based upon the address that was contained in there to who else has lived there, right? And if I and someone else had the same last name, you can easily conclude that there's some familial familial representation that's within there, right? That could be my parent, could be my child, could be my sister, uncle, etc. But you had everything that you need in there to commit identity theft. You had their first name, their last name, middle name, social security number, addresses, previous people they've lived with. All those can be used easily to commit identity theft because what questions are asked, you know, when you go sign up for a credit report, right? They'll they'll say, Well, where'd you live before? Right? It had your past addresses on it. It makes it so easy for for those things to occur. A lot of people don't realize the that that data is even out there and that it's a risk.
SPEAKER_01So you would do this for people, you get their name and email, work email, and then you would then compile this information, uh, all of their personal information, and then you would show up to a meeting with them.
SPEAKER_00Yes. So we didn't give them the stuff.
SPEAKER_01We we we verbally delivered that um to the here's your social, here's your passwords, here's what's going on. And so it's one of those things that, yeah, you think if you're you know, I'm I'm being safe, there's other information that's going out that may not have that. And so the more you can protect yourself, the better. Now, let's talk about I wanted to address that just so people know that the the the power, someone who actually understands how to use this not obviously you you are ideally a good actor, that far as I know. I am, I am. And thankfully, and thankfully we have people like you who actually understand this who can communicate this stuff. Now, what why inAiden? Why should people use this system? Why should people use NAIDN? Why should people you know use NADN for their cybersecurity needs?
SPEAKER_00Sure. Uh one, you can run it at home. Uh, you know, we do we are source available for you to run and use at home to automate these types of things. Two, the the time saving 100. Because it's an automation, uh, but it saves you a ton of time so that you're not manually triaging the alerts or manually looking at your firewall, you know, because who has the time to sit there and look at all the alerts that came in, right? As I showed earlier, there's a ton just from my own firewall. So you can have those coming in automatically, programmatically to disqualify or to qualify. Should this be something that you need to be concerned about? Is this something that is actionable? Using automation, you can definitely process that much faster, except in eight seconds, versus manually looking up those different sources to go and retrieve the retrieve that data. Outside of there, right, if you're a large enterprise, you may already have some type of security automations and response platform, which is great, but those are typically geared towards just security alone. Using N8N, right, it can do a lot more than just these specific use cases. I personally also use N8N for some of my uh social media automations that I that I have, right? So there there are uses outside of just cyber, outside of just business. There's lots of different things. The world the world is your oyster in regards to what you can do with N8N.
SPEAKER_01So I think this is great. And I mean specifically around cybersecurity, and I the NAN is great for a lot of different AI and automations, but talking about the fact that you this is extendable, you can extend the cybersecurity abilities for the detections. I mean, we just looked at the ability to cross-reference it across uh several systems for threat detection and to then be able to enrich that uh information source and then to be able to then notify you, you know, through the power of using NADN and AI and automation. What I think is great about this is what I think would be really valuable is we talked in the very beginning about this, but I do want to I want to uh collaborate with you uh to put together a little kit for somebody on like, you know, what they could buy in terms of the hardware, uh these workflows that you've shown so far, um, and then you know, any kind of like really light information on kind of how to get started with this. So if somebody wants to set this up, um, you know, so you know, whether you are uh you know you're have a house that you want to protect uh SMB or you're you're an enterprise business and you want to you want to see what this would look like and how to set this up. Or maybe you you work at an enterprise and you want this at your house. Uh so buddy, I'd love to work with you to get something to put together a nice little uh safety care package for people so that anybody that's watching this could click the link down below and get started on this. Does that sound good?
SPEAKER_00Can we Yeah, yeah, yeah, for sure. But just uh to show you here, right? This is this would be the consumer equivalent to the device that I have. So for you, Dylan, as an example, you could put this right behind your router in in in line. So instead of you directly checking to the router with your switch and everything else you have router, this, then your switch. Then you can also then have the same type of protection that I have on on your level without you having to have said the equipment that I have, because I do have a um a literally a rack mount um switch um from them. Like this, this is the one that I have, and you don't need this one. You can definitely go get this one, which offers the same thing at the consumer level.
SPEAKER_01Got it. So yeah, so it's quite affordable. And if you understand, like, you know, yeah, it's a couple hundred bucks for this. In itin, I mean, depending on your level, is is free to nominal. If you're if you're using it in a big business, it's it's gonna be well worth it. Because again, these bad actors, it only takes one time. I mean, I I I got, you know, I'm I I've been hacked on social media. I've been banned out of my Facebook account that I had to think like I knew people at at Facebook so I could get my account back. But I had people asking, pretending to be me, asking for money. I've had people impersonate my account on TikTok asking for money. So these things happen all the time, all the time. And I think until you get burned, you don't realize the the uh ounce of prevention for a pound of pain, you know. So yes, I think this is really important stuff. And so, yes, I think it's amazing. Thank you for showing that on screen so anybody can get started. I want to put this all condensed, the the workflows, the links, and everything else. So someone doesn't need to, you don't have to think about anything. Just to say, you know, click this, go here, follow steps. So um incredible. Um, buddy, I know we have more to cover, but I think we might do a part two on this because we've got so deep into the weeds. And so I want to come back to this and do another one. I think there's a lot for people to process to get into. And I think just getting started with this, putting this in place, putting getting your email protection set up and and protecting your firewalls, if it if people just did this, they would be incredible, they would be much safer than just not doing anything.
SPEAKER_00Sure, sure. Well, while we're on that topic, though, just some other things that folks can do outside of N, outside of replacing any any hardware, something that doesn't cost any money. Yeah, if if they are concerned about securing their accounts, as a general best practice, one use unique passwords on every website to that effect. Use the password manager, it makes it a lot easier for you. And I would take that a step further and say, don't use the ones built into ILS, don't use the one built into Chrome. There's uh I want to that's a bigger topic we'll talk about later, but just don't use those. Um, use an external one. So I personally prefer use one password, you don't have to use that one. That's just what I use. Bitboard is another acceptable option as well.
SPEAKER_01I use dash lanes.
SPEAKER_00Dash lane is is a good one as well. Um use so use a password manager so that you're generating unique passwords for every website. Enable two-factor authentication on every website where applicable and and where available. When you're enabling two-factor, don't use your phone for two-factor. Right? Phones can be sim slot. That's that's a whole nother can of worms. I don't want to get into it. Another longer discussion that we can have on that, but use an app-based two-factor authentication that generates the code that rotates every 30 seconds as the best preventative measure instead of two-factor via text that is weak. On social media, sign up for any verification program. So, like on Meta, Facebook, Instagram, if you get a verified account that gets you guaranteed support, a support person that you can talk to rather than a generic email. They can also help you take down any fictitious accounts for you on there as well, if any pop up that are intimid or impersonating you on Facebook or Instagram.
SPEAKER_01Amazing advice. We are gonna include all of this in a checklist uh uh together. So have this at the very end. And we can put this all together at the end. So people can get this and download this and they can just go through and go, okay, how do I make my social media secure? What can I do? What are best practices and how do I get started? Because I think this security checklist will be an incredible uh useful tool for anybody that wants to just uh sleep safely at night, sleep soundly, I should say, you know. Um, so so buddy, uh uh with that being said, uh, is there anything else you'd like to let people know about um before we conclude the podcast? Normally I'd say how to get a hold of you, but you know, you work at N It N. So I don't know if we want necessarily people uh uh ringing your doorbell. Uh before you give away any of your personal identified information, is there anything you'd like to let people know about?
SPEAKER_00Sure. Just you know, again, stay safe if you're unsure of something. If you get an email that you don't expect and it's urging you to do something, those typically are the indicators, right? You get a you get a big unexpected email that says you owe this money to the RS or to PayPal or to this company, right? That's usually one of the indicating signals. Stop, pause, reflect, check the number that's in the email. Again, that's one of the common vectors that we've already talked about. Uh, and check the links before you click them. Don't click them and then go and then like, oops, easy check that you can do there with N8N um using this to ensure that that is not a vector. And keep your software up to date. That'd be the other the other the other easy one. Uh, I know it's annoying having to constantly update your phone or or update Chrome, but they really do patch bugs and no normal abilities. So definitely keep things up to date. Fantastic.
SPEAKER_01Buddy, thank you so much, my friend. It's been a honor, a pleasure, and slightly terrifying. I appreciate your time. Have a blessed day, my friend. I'll see you on the other side. I'll see you. All right, take care now. Bye.