DaySchedule SSH (key-based auth) BigMailer Universal Summarizer by Kagi

Automated CVE scanning of Bug Bounty programs with Nuclei and Project Discovery

Streamline your vulnerability research by automatically scanning bug bounty scopes against the latest Project Discovery templates. This workflow manages remote Nuclei execution on a VPS and delivers critical findings directly to your inbox, ensuring you're the first to spot new CVEs. It transforms manual reconnaissance into a continuous, hands-off security monitoring engine.

Run this with your team's AI

What This Recipe Does

Managing server security and infrastructure integrity manually is a time-consuming process that often leads to oversight. This Security and Identity Audit automation streamlines your monitoring by performing scheduled, deep-dive checks across your remote server environment. The workflow connects to your systems via secure protocols, gathers raw log data, and processes it to identify critical patterns or anomalies. Instead of requiring a technical expert to manually parse through thousands of lines of system logs, the automation uses intelligent summarization to distill technical data into a clear, high-level overview. Business leaders and security officers receive a concise report via email, highlighting exactly what changed, who accessed the systems, and whether any unauthorized activity was detected. This proactive approach ensures consistent compliance with security policies while freeing your technical team from routine monitoring tasks. By centralizing the reporting of distributed infrastructure, you maintain a robust security posture with minimal manual effort.

What your team gets

Something anyone can use

Forms and dashboards, so it is not a script only one person understands

It keeps running

Runs on your schedule in the cloud, so it does not stop when a laptop closes

Your other tools can call it

Endpoints, so the rest of your stack can trigger the same work

Accounts connected once

DaySchedule, SSH (key-based auth), BigMailer, Universal Summarizer by Kagi connected for the team, not per person

How It Works

  1. 1

    Open the recipe and connect your accounts

    Connect DaySchedule and SSH (key-based auth) once, in your team cloud, and nobody has to do it again on their own machine

  2. 2

    Tell your own agent what is different about your process

    Claude, ChatGPT, Cursor, whichever your team already uses. It adapts the recipe to how you actually work

  3. 3

    Run it, then leave it running

    It lives in your team cloud, so it keeps going after you close the laptop and every teammate's AI can use it

Who Uses This

Frequently Asked Questions

How does the automation access my servers securely?

The workflow uses encrypted SSH connections to communicate with your servers. You provide the necessary credentials or keys within the secure environment to ensure only authorized access is granted.

Can I adjust how often the security checks run?

Yes. The schedule trigger is fully customizable, allowing you to run audits hourly, daily, weekly, or at any specific interval that aligns with your internal security requirements.

What kind of information is included in the final email report?

The report provides a summarized view of system activity, including filtered results for specific events like failed login attempts, critical system updates, or changes to sensitive files.

Do I need to be a developer to understand the output?

No. The automation is designed to summarize complex technical logs into plain language, making it easy for business stakeholders to understand the security status of their infrastructure.

Coming from n8n?

This recipe uses nodes like ScheduleTrigger, HttpRequest, ConvertToFile, Ssh and 8 more. On Runwork, you don't need to learn n8n's workflow syntax. Describe what you want to your own AI agent in plain English.

ScheduleTrigger HttpRequest ConvertToFile Ssh SplitInBatches SplitOut Filter If Set Gmail Summarize StickyNote

Based on n8n community workflow. View original

Related Recipes

GoogleSheets Slack ScheduleTrigger If

Monitor SSL certificate expiry dates with Google Sheets & Slack alerts

Maintaining secure websites is critical for customer trust and search engine rankings, yet many businesses rely on manual checks or memory to renew SSL certificates. This automation eliminates the risk of expired certificates by transforming a simple Google Sheet into a proactive monitoring system. The workflow automatically scans your list of domains on a set schedule, calculates the days remaining until expiry, and triggers instant alerts via Slack when action is needed. By centralizing your domain management, you avoid the chaos of managing multiple vendor portals and prevent costly downtime or security warnings that drive visitors away. This tool ensures your IT or security team has ample lead time to handle renewals, moving your infrastructure management from reactive firefighting to organized, automated oversight.

See the recipe
Cortex

Analyze emails with S1EM

This automation streamlines your security operations by transforming a standard email inbox into a proactive incident response hub. By monitoring incoming messages via IMAP, the system automatically identifies potential threats and converts them into structured cases within TheHive. Instead of requiring security analysts to manually monitor mailboxes for phishing reports or system alerts, this workflow handles the entire intake process. It utilizes Cortex to perform deep analysis on suspicious indicators, such as URLs and file attachments, ensuring that your team has enriched, actionable data the moment they begin an investigation. The workflow includes intelligent logic and waiting periods to ensure all automated background checks are completed before finalizing the report. This approach significantly reduces the mean time to respond (MTTR) to security incidents by eliminating manual data entry and initial triage. By offloading these repetitive tasks to an automated system, your security personnel can focus on high-value remediation and strategic defense rather than administrative overhead. The result is a faster, more accurate security posture that ensures critical alerts are never missed in a crowded inbox.

See the recipe
Http

Generate domain insights with WHOIS lookup and GPT-5-Nano via RapidAPI

This automation serves as a powerful bridge between your front-end applications and external security or identity verification services. By utilizing a webhook-based architecture, it allows your business to securely process incoming data requests, perform complex HTTP lookups, and return immediate, structured responses. This is particularly valuable for organizations that need to validate user credentials, check identity status, or interface with third-party security APIs without building a custom backend from scratch. Instead of manual verification processes or fragmented data handling, this workflow centralizes the logic, ensuring that every request is handled consistently and securely. The result is a more responsive user experience, reduced manual overhead for security teams, and a scalable way to manage identity-related data across multiple platforms. By automating the communication between your app and external data sources, you ensure that critical security information is always accurate and delivered in real-time to the systems that need it most.

See the recipe
Telegram Google Sheets

Protect Telegram groups with math CAPTCHA verification and Google Sheets

The Security and Identity Management automation provides a robust framework for handling sensitive user interactions and data verification directly through Telegram. By integrating messaging capabilities with Google Sheets and custom logic, this workflow transforms a standard chat interface into a secure portal for identity management. It eliminates the need for complex internal portals by allowing administrators or automated systems to process requests, verify information against existing databases, and update records in real-time. The automation ensures that every interaction is logged and validated, reducing the risk of unauthorized access or data entry errors. For businesses handling high volumes of user requests or requiring rapid identity verification, this solution provides a scalable way to maintain security protocols without sacrificing speed. It bridges the gap between communication platforms and core data management, ensuring that your identity workflows are both accessible and highly secure.

See the recipe

Run this with the AI your team already uses

Your agent adapts it, your team cloud keeps it running, and everyone's AI can find it.

Open this recipe in Runwork