AutomationMart
Home/Browse/Automated GitHub scanner for exposed AWS IAM keys
n8n

Automated GitHub scanner for exposed AWS IAM keys

n8nn8n16 modulesv1.0
SlackGitHub

Automated GitHub Scanner for Exposed AWS IAM Keys Overview This n8n workflow automatically scans GitHub for exposed AWS IAM access keys associated with your AWS account, helping security teams quickly identify and respond to potential security breaches. When compromised keys are found, the workflow generates detailed security reports and sends Slack notifications with actionable remediation steps. ๐Ÿ”‘ Key Features - Automated AWS IAM Key Scanning: Regularly checks for exposed AWS access keys on Gi

At a glance

Automated GitHub scanner for exposed AWS IAM keys is a ready-made n8n workflow you import as a workflow JSON file โ€” no build required. It connects Slack, GitHub. It's free to download. Follow the 5-step import below to go live in minutes.

Platform
n8n
Connects
Slack, GitHub
Modules
16
Price
Free
Version
v1.0
Automated GitHub scanner for exposed AWS IAM keys workflow diagram

About this workflow

Automated GitHub Scanner for Exposed AWS IAM Keys Overview This n8n workflow automatically scans GitHub for exposed AWS IAM access keys associated with your AWS account, helping security teams quickly identify and respond to potential security breaches. When compromised keys are found, the workflow generates detailed security reports and sends Slack notifications with actionable remediation steps. ๐Ÿ”‘ Key Features - Automated AWS IAM Key Scanning: Regularly checks for exposed AWS access keys on GitHub - Real-time Security Alerts: Sends immediate Slack notifications when compromised keys are detected - Comprehensive Security Reports: Generates detailed reports with exposure information and risk assessment - Actionable Remediation Steps: Provides clear instructions for securing compromised credentials - Continuous Monitoring: Maintains ongoing surveillance of your AWS environment ๐Ÿ“‹ Workflow Steps 1. List AWS Users: Retrieves all users from your AWS account 2. Split Users for Processing: Processes each user individually 3. Get User Access Keys: Retrieves access keys for each user 4. Filter Active Keys Only: Focuses only on currently active access keys 5. Search GitHub for Exposed Keys: Scans GitHub repositories for exposed access keys 6. Aggregate Search Results: Consolidates and deduplicates search findings 7. Check For Compromised Keys: Determines if any keys have been exposed 8. Generate Security Report: Creates detailed security reports for compromised keys 9. Extract AWS Usernames: Extracts usernames from AWS response for notification 10. Format Slack Alert: Prepares comprehensive Slack notifications 11. Send Slack Notification: Delivers alerts with actionable information 12. Continue Scanning: Maintains continuous monitoring cycle ๐Ÿ› ๏ธ Setup Requirements Prerequisites - Active n8n instance - AWS account with IAM permissions - GitHub account/token for searching repositories - Slack workspace for notifications Required Credentials 1. AWS Credentials: - IAM user with permissions to list users and access keys - Access Key ID and Secret Access Key 2. GitHub Credentials: - Personal Access Token with search permissions 3. Slack Credentials: - Webhook URL for your notification channel โš™๏ธ Configuration 1. AWS Configuration: - Configure the "List AWS Users" node with your AWS credentials - Ensure proper IAM permissions for listing users and access keys 2. GitHub Configuration: - Set up the "Search GitHub for Exposed Keys" node with your GitHub token - Adjust search parameters if needed 3. Slack Configuration: - Configure the Slack node with your webhook URL - Customize notification format if desired ๐Ÿš€ Usage Running the Workflow 1. Manual Execution: Click "Execute Workflow" to run an immediate scan 2. Scheduled Execution: Set up a schedule to run periodic scans (recommended daily or weekly) Repository Compatibility This workflow is compatible with both public and private GitHub repositories to which you have access. It will scan all repositories you have permission to view based on your GitHub credentials. Handling Alerts When a compromised key is detected: 1. Review the Slack notification for details about the exposure 2. Follow the recommended remediation steps: - Deactivate the compromised key immediately - Create a new key if needed - Investigate the exposure source - Update any services using the compromised key โš ๏ธ Disclaimer This workflow template is provided for reference purposes only to demonstrate how to automate AWS IAM key exposure scanning. Please note: - The scanning process may produce false positives as it only matches potential AWS access key patterns - Always verify any reported exposures manually before taking action - Disabling or deleting access keys without proper verification could have significant negative impacts on your environment - Understand which systems and applications rely on identified access keys before deactivating them - This template should be customized to fit your specific environment and security policies IMPORTANT: Use this workflow with caution and only after thoroughly understanding your AWS environment. The authors of this template are not responsible for any disruptions or damages resulting from its use. ๐Ÿ”’ Security Considerations - This workflow requires access to sensitive AWS credentials - Store all credentials securely within n8n - Review and rotate access keys regularly ๐Ÿ“ Customization Options - Adjust GitHub search parameters for more targeted scanning - Customize Slack notification format and content - Modify security report generation for your specific needs - Integrate with additional notification channels (email, MS Teams, etc.) Optional: Enabling Interactive Slack Buttons The Slack Block Kit notification format supports interactive buttons that can be implemented if you want to perform actions directly from Slack: 1. Disable Key: This button can be configured to automatically disable the compromised AWS IAM access key 2. View Details: This button can be set up to show additional information about the exposure 3. Acknowledge: This button can be used to mark the alert as acknowledged To make these buttons functional: 1. Set up a Slack Socket Mode App: - Create a Slack app in the Slack API Console - Enable Socket Mode and Interactive Components - Subscribe to the blockactions event to capture button clicks 2. Create an n8n Webhook Endpoint: - Add a new webhook node to receive Slack button click events - Create separate workflows for each button action 3. Implement AWS Key Disabling: - For the "Disable Key" button, create a workflow that uses the n8n HTTP Request node to call the AWS IAM UpdateAccessKey API - Example HTTP request that can be implemented in n8n: 4. Update the Slack Message Format: - Modify the Format Slack Alert node to include your webhook URL in the button action values - Add callbackid and actionid values to identify which button was clicked This implementation allows for immediate response to security incidents directly from the Slack interface, reducing response time and improving security posture.

n8n

How to import this n8n workflow

  1. 1

    Download the workflow JSON file after purchase.

  2. 2

    Open n8n โ†’ click the menu โ†’ Import from File.

  3. 3

    Select the downloaded JSON and import.

  4. 4

    Set up credentials for each node that requires them.

  5. 5

    Click Execute Workflow to test, then activate.

Setup guide

Setup guide included

Purchase to unlock the full step-by-step guide

Related N8n workflows

Create Slack messages for new offline messages in HappyFox Chat

Every time an offline message is received in your HappyFox Chat, Make will create a message in your Slack.

Free

Create Slack messages for new Bigin by Zoho CRM deals

Every time a deal in your Bigin by Zoho CRM is added, Make will create a message in your Slack.

Free

Add Project Tasks to Google Sheets with GPT-4.1-mini Chat Assistant

Let your team create, track, and manage project tasks through natural conversation. This workflow uses an AI Project Manager Agent that chats with users, gathers the task details it needs, and automatically adds them to a Google Sheet. --- โœ… What this template does - Lets you chat naturally with an AI to add new project tasks - Automatically detects if the user wants to create or update an item (updates coming soon) - Collects Task, Description, and Status fields

Free

Classify and summarize WeChat articles with GPT-4 Nano to Google Sheets and Notion

Whoโ€™s it for ๐Ÿ‘ฅ This template is perfect for content creators, marketers, and researchers managing WeChat public account articles! ๐Ÿš€ Itโ€™s ideal for n8n newcomers or anyone wanting to save time on manual content analysis, especially if you use Google Sheets for tracking. ๐Ÿ“Š Whether youโ€™re into AI, ๆฌง้˜ณ่‰ฏๅฎœ, or automation, this is for you! ๐Ÿ˜„ How it works / What it does ๐Ÿ”ง This workflow automates the retrieval, filtering, classification, and summarization of WeChat articles. ๐ŸŒ It reads RSS feed lin

Free

Get Slack notifications about new proposals completed in Bidsketch

Every time a new proposal is accepted or declined in Bidsketch, Make will automatically send a notification message to a specified channel/chat in Slack.

Free

Send a Slack message from a new Uniqode QR code scan

Every time a new Uniqode QR code scan happens, Make will automatically send a Slack message.

Free

Source top GitHub talent by language & location with Gemini AI and BrowserAct

AI-Powered Top GitHub Talent Sourcing (by Language & Location) to Google Sheet This n8n template is a powerful talent sourcing engine that finds, analyzes, and scores GitHub contributors using a custom AI formula. This workflow is ideal for technical recruiters, hiring managers, and team leads who want to build a pipeline of qualified candidates based on specific technical skills and location. --- Self-Hosted Only This Workflow uses a community contribution and is designed and tested for self-h

Free

Extract Website URLs from Sitemap.XML for SEO Analysis

Overview This n8n workflow automates the process of crawling a website's sitemap to extract URLs, which is particularly useful for SEO analysis, website auditing, or content monitoring. By leveraging n8n's nodes, the workflow fetches the sitemap from a specified URL, processes the XML data, and extracts individual URLs, which can then be converted into a downloadable file or integrated with tools like Google Sheets. How It Works The workflow operates in a sequential manner, utilizing a se

Free

Reviews

No reviews yet

Be the first to buy and share your experience.

Leave a review

Sign in to share your experience with this workflow.

Log in to review
Free
No ratings yet

Create a free account to purchase workflows.

  • JSON blueprint โ€” instant download
  • Setup guide PDF included
  • 5 downloads ยท valid 30 days
  • Works with n8n

Need help setting this up?

Book a 3-hour live setup session with an Agility consultant.

โ‚น2,499/ session
3 hrs ยท video call
  • Configure live on Google Meet / Zoom
  • Free follow-up if workflow has defects
  • Platform expert assigned to you
Book installation session
Free