Automated CVE scanning of Bug Bounty programs with Nuclei and Project Discovery
Streamline your vulnerability research by automatically scanning bug bounty scopes against the latest Project Discovery templates. This workflow manages remote Nuclei execution on a VPS and delivers critical findings directly to your inbox, ensuring you're the first to spot new CVEs. It transforms manual reconnaissance into a continuous, hands-off security monitoring engine.
Run this with your team's AIWhat This Recipe Does
Managing server security and infrastructure integrity manually is a time-consuming process that often leads to oversight. This Security and Identity Audit automation streamlines your monitoring by performing scheduled, deep-dive checks across your remote server environment. The workflow connects to your systems via secure protocols, gathers raw log data, and processes it to identify critical patterns or anomalies. Instead of requiring a technical expert to manually parse through thousands of lines of system logs, the automation uses intelligent summarization to distill technical data into a clear, high-level overview. Business leaders and security officers receive a concise report via email, highlighting exactly what changed, who accessed the systems, and whether any unauthorized activity was detected. This proactive approach ensures consistent compliance with security policies while freeing your technical team from routine monitoring tasks. By centralizing the reporting of distributed infrastructure, you maintain a robust security posture with minimal manual effort.
What your team gets
Forms and dashboards, so it is not a script only one person understands
Runs on your schedule in the cloud, so it does not stop when a laptop closes
Endpoints, so the rest of your stack can trigger the same work
DaySchedule, SSH (key-based auth), BigMailer, Universal Summarizer by Kagi connected for the team, not per person
How It Works
- 1
Open the recipe and connect your accounts
Connect DaySchedule and SSH (key-based auth) once, in your team cloud, and nobody has to do it again on their own machine
- 2
Tell your own agent what is different about your process
Claude, ChatGPT, Cursor, whichever your team already uses. It adapts the recipe to how you actually work
- 3
Run it, then leave it running
It lives in your team cloud, so it keeps going after you close the laptop and every teammate's AI can use it
Who Uses This
- IT Managers who need weekly compliance reports on server access and system health without manual data collection.
- Security Officers who require automated monitoring for unauthorized system changes or suspicious login patterns across cloud infrastructure.
- System Administrators who want to receive summarized daily digests of server logs to identify and address potential vulnerabilities before they escalate.
Frequently Asked Questions
How does the automation access my servers securely?
The workflow uses encrypted SSH connections to communicate with your servers. You provide the necessary credentials or keys within the secure environment to ensure only authorized access is granted.
Can I adjust how often the security checks run?
Yes. The schedule trigger is fully customizable, allowing you to run audits hourly, daily, weekly, or at any specific interval that aligns with your internal security requirements.
What kind of information is included in the final email report?
The report provides a summarized view of system activity, including filtered results for specific events like failed login attempts, critical system updates, or changes to sensitive files.
Do I need to be a developer to understand the output?
No. The automation is designed to summarize complex technical logs into plain language, making it easy for business stakeholders to understand the security status of their infrastructure.
Coming from n8n?
This recipe uses nodes like ScheduleTrigger, HttpRequest, ConvertToFile, Ssh and 8 more. On Runwork, you don't need to learn n8n's workflow syntax. Describe what you want to your own AI agent in plain English.
Based on n8n community workflow. View original
Related Recipes
Monitor SSL certificate expiry dates with Google Sheets & Slack alerts
Maintaining secure websites is critical for customer trust and search engine rankings, yet many businesses rely on manual checks or memory to renew SSL certificates. This automation eliminates the risk of expired certificates by transforming a simple Google Sheet into a proactive monitoring system. The workflow automatically scans your list of domains on a set schedule, calculates the days remaining until expiry, and triggers instant alerts via Slack when action is needed. By centralizing your domain management, you avoid the chaos of managing multiple vendor portals and prevent costly downtime or security warnings that drive visitors away. This tool ensures your IT or security team has ample lead time to handle renewals, moving your infrastructure management from reactive firefighting to organized, automated oversight.
Analyze emails with S1EM
This automation streamlines your security operations by transforming a standard email inbox into a proactive incident response hub. By monitoring incoming messages via IMAP, the system automatically identifies potential threats and converts them into structured cases within TheHive. Instead of requiring security analysts to manually monitor mailboxes for phishing reports or system alerts, this workflow handles the entire intake process. It utilizes Cortex to perform deep analysis on suspicious indicators, such as URLs and file attachments, ensuring that your team has enriched, actionable data the moment they begin an investigation. The workflow includes intelligent logic and waiting periods to ensure all automated background checks are completed before finalizing the report. This approach significantly reduces the mean time to respond (MTTR) to security incidents by eliminating manual data entry and initial triage. By offloading these repetitive tasks to an automated system, your security personnel can focus on high-value remediation and strategic defense rather than administrative overhead. The result is a faster, more accurate security posture that ensures critical alerts are never missed in a crowded inbox.
Generate domain insights with WHOIS lookup and GPT-5-Nano via RapidAPI
This automation serves as a powerful bridge between your front-end applications and external security or identity verification services. By utilizing a webhook-based architecture, it allows your business to securely process incoming data requests, perform complex HTTP lookups, and return immediate, structured responses. This is particularly valuable for organizations that need to validate user credentials, check identity status, or interface with third-party security APIs without building a custom backend from scratch. Instead of manual verification processes or fragmented data handling, this workflow centralizes the logic, ensuring that every request is handled consistently and securely. The result is a more responsive user experience, reduced manual overhead for security teams, and a scalable way to manage identity-related data across multiple platforms. By automating the communication between your app and external data sources, you ensure that critical security information is always accurate and delivered in real-time to the systems that need it most.
Protect Telegram groups with math CAPTCHA verification and Google Sheets
The Security and Identity Management automation provides a robust framework for handling sensitive user interactions and data verification directly through Telegram. By integrating messaging capabilities with Google Sheets and custom logic, this workflow transforms a standard chat interface into a secure portal for identity management. It eliminates the need for complex internal portals by allowing administrators or automated systems to process requests, verify information against existing databases, and update records in real-time. The automation ensures that every interaction is logged and validated, reducing the risk of unauthorized access or data entry errors. For businesses handling high volumes of user requests or requiring rapid identity verification, this solution provides a scalable way to maintain security protocols without sacrificing speed. It bridges the gap between communication platforms and core data management, ensuring that your identity workflows are both accessible and highly secure.
Run this with the AI your team already uses
Your agent adapts it, your team cloud keeps it running, and everyone's AI can find it.
Open this recipe in Runwork