Detect 1Password vault exports with TheHive and Slack alerts
Quick Overview
Description
Quick Overview This workflow polls the 1Password Events API every 15 minutes for recent audit events, detects vault export activity, creates an alert in TheHive, and posts a notification to a Slack channel with the export details and a link to the alert. How it works Runs every 15 minutes on a schedule. Requests the last 24 hours of audit events from the 1Password Events API. Splits the returned events into individual items and keeps only events where the object type is vault and the action contains export. Extracts key details (user, email, vault name/ID, timestamp, source IP, and event UUID) and prepares a TheHive base URL for link building. Creates a new TheHive alert with severity/TLP/PAP settings, tags, and a description containing the vault export context. Posts a Slack message to the selected channel summarizing the incident and linking directly to the created TheHive alert. Setup Create and configure a 1Password Events API token with access to the auditevents feature and add it as an HTTP request credential used by the workflow. Add TheHive credentials in n8n and set the correct TheHive instance URL, then ensure alert creation permissions are granted. Add Slack OAuth2 credentials and select the destination Slack channel for the notification. Replace the placeholder value for the TheHive base URL in the export-details step so the Slack alert link points to your TheHive UI. An n8n automation workflow template by Muhammad Bin Zohaib.
Community Metrics
Author
Muhammad Bin Zohaib
Platform
web
Pricing model
free
Categories
- Automation
Tags
- n8n
- workflow
- http-request
- slack
- thehive-5
Capabilities
- 3 nodes