Analyze phishing emails and alert security team
Workflow Description
Automation that retrieves emails from Outlook, analyzes URLs for phishing threats using Url Scan Io, processes messages in batches, and sends real-time alerts to Slack for security team review and action.
How it works
- 1.Fetch emails from Outlook and extract suspicious links
- 2.Split email batch for parallel processing and threat analysis
- 3.Scan URLs with Url Scan Io and classify risk levels
- 4.Filter dangerous messages and send Slack alerts to security team
Use cases
- Protect employees from phishing and credential theft attacks
- Monitor and detect unauthorized access attempts via email
Requirements
- Connected Outlook account with email read permissions
- Url Scan Io API key for URL threat scanning
- Dedicated Slack channel for security alerts
Service Value
Ready-made workflow template for automation delivery and service execution.
Apps Used
Details
How to Use
- 1.Click "Download Template"
- 2.Open your n8n dashboard
- 3.Go to Workflows > Import from File
- 4.Select downloaded file and configure credentials
Nodes Used (23)
When clicking "Execute Workflow"
Manual Trigger
sends slack message
Slack
Split In Batches
Split In Batches
Mark as read
Microsoft Outlook
VirusTotal: Scan URL
HTTP Request
VirusTotal: Get report
HTTP Request
Schedule Trigger
Schedule Trigger
Find indicators of compromise
Code
URLScan: Get report
Url Scan Io
URLScan: Scan URL
Url Scan Io
Has URL?
If
No error?
If
Not empty?
Filter
Sticky Note
Sticky Note
Sticky Note1
Sticky Note
Sticky Note2
Sticky Note
Sticky Note3
Sticky Note
Wait 1 Minute
Wait
Sticky Note4
Sticky Note
Sticky Note5
Sticky Note
Get all unread messages
Microsoft Outlook
Sticky Note6
Sticky Note
Merge Reports
Merge