Skip to content

Threat intelligence API / integrations

n8n

A community node for n8n that puts ThreatCluster in your workflows: incident clusters, CVEs with exploitation signals, validated indicators, entity profiles and ransomware leak-site activity, plus a polling trigger that fires on new incidents, new leak-site victims and newly exploited CVEs. Works on n8n Cloud and self-hosted.

Packagenpm: n8n-nodes-threatclusterSource on GitHubMIT

Prerequisites

  1. A ThreatCluster API key. Every plan, including Free, has one: sign in, open Settings → API and select Generate API Key. Free keys get 100 credits a day and read the last seven days.
  2. n8n Cloud, or a self-hosted n8n where community nodes are enabled (they are by default; the owner account installs them under Settings → Community Nodes).

Setup

  1. Install the node. In the n8n UI: Settings → Community Nodes → Install, enter n8n-nodes-threatcluster and confirm. Self-hosted without the UI:
    cd ~/.n8n/nodes
    npm install n8n-nodes-threatcluster
    Restart n8n after a manual install.
  2. Add the credential. Credentials → New → ThreatCluster API, paste the key, select Test. The test calls GET /me, which costs zero credits, so testing never spends your budget.
  3. Drop a ThreatCluster node or a ThreatCluster Trigger into a workflow and pick the credential.

The action node

Seven resources, fifteen operations. List responses come back as one item per row, which is what the nodes downstream expect, and every item carries a _meta object with what the call cost and how many credits remain today.

  1. Threat Incident: Get Many, Get, Get IOCs, Get STIX, Search.
  2. Vulnerability: Get Many with KEV, public-exploit and severity filters, Get.
  3. Dark Web: Get Victims, Get Groups.
  4. Entity: Search, Get.
  5. IOC: Get Feed.
  6. Ask AI: Ask the Corpus, Ask About an Incident. Paid plans only.
  7. Account: Get Credits. Free to call.

The trigger

Three events: New Threat Incident, New Leak-Site Victim and New Exploited CVE, each with the filters the matching endpoint accepts, for example a sector on victims or a severity on CVEs.

Deduplication is handled for you, and it matters, because duplicate alerts are the usual way a polling integration goes wrong. The trigger passes the API's since parameter so a poll returns only what is newer than the last run, and keeps a set of seen ids to catch rows that share a timestamp or arrive out of order. The first poll primes that state and emits a single sample rather than flooding the workflow with a whole window of history. A 429 from a spent daily budget is treated as "try again next interval", so a busy day never disables the workflow.

Worked example: ransomware watch for your sector

  1. ThreatCluster Trigger, event New Leak-Site Victim, sector Healthcare, poll every 30 minutes.
  2. Slack node, message from the item fields. A listing arrives with the group, the victim name, the country, the sector and the date it was posted:
    New leak-site listing: {{ $json.name }}
    Group: {{ $json.group }}  ·  Sector: {{ $json.sector }}  ·  {{ $json.country }}
    Posted {{ $json.discovered_at }}
    {{ $json.url }}

Keep the wording "listing" or "claim". A group naming an organisation means the group says it attacked them; it is not a confirmed breach.

Two more patterns

  1. Exploited CVE triage: Trigger (New Exploited CVE) → Filter (severity is CRITICAL) → Jira or ServiceNow. One ticket per CVE that gained a public exploit.
  2. Enrich an alert: your SIEM's webhook → ThreatCluster (Entity: Get) → post the actor profile back into the case.

What it costs

Most calls cost 1 credit; Search costs 5; STIX and the IOC feed cost 3; Ask AI costs 25 to 50 and needs a paid plan. Get Credits is free. A free key has 100 credits a day, which covers a trigger polling every 30 minutes plus a handful of lookups. The node turns the three errors you will actually meet into plain English: 401 the key was rejected, 403 your plan does not allow it, 429 the daily budget is spent and refills at 00:00 UTC.

Prefer a plain HTTP Request node? The curl guide has every endpoint and header, and a ready-made "IOC feed to Slack" workflow template is in the repository.