DEV Community

Cover image for From n8n Winner to Chrome AI Pioneer: Building SOC-CERT Guardian extension with Virtual CVE Intelligence ๐Ÿš€
Malika
Malika Subscriber

Posted on

From n8n Winner to Chrome AI Pioneer: Building SOC-CERT Guardian extension with Virtual CVE Intelligence ๐Ÿš€

๐ŸŽฏ TL;DR

3 Months, 3 Challenges, 1 Vision: From n8n automation winner to Chrome AI cybersecurity pioneer.

This isn't just another hackathon project โ€” it's solving a $10B industry problem with Virtual CVE Intelligence.

The Journey:

  • ๐Ÿ† August 2025: Won n8n + Bright Data AI Agents Challenge
  • ๐Ÿ“Š September 2025: Built enterprise SOC dashboard with KendoReact
  • ๐Ÿš€ October 2025: Created first Chrome AI security extension with Virtual CVE Intelligence and CISA KEV correlation

Result: Proactive threat detection in 2.3 seconds vs NVDโ€™s 90-day timeline


๐Ÿ† Chapter 1: The Win (August 2025)

n8n + Bright Data Challenge Victory

Won the Real-Time AI Agents Challenge with SOC-CERT: Automated Threat Intelligence โ€” an n8n workflow automating CVE correlation and threat detection.

What it did:

  • ๐Ÿ”„ Real-time NVD + CISA KEV synchronization
  • โšก Bright Data proxies for reliable threat data scraping
  • ๐ŸŽฏ AI-powered CVE correlation with 1,400+ known exploited vulnerabilities
  • ๐Ÿ“ฑ Telegram alerts in 2 seconds

The Foundation: This winning workflow became the backend intelligence for all future SOC-CERT products.


๐Ÿ“Š Chapter 2: The Dashboard (September 2025)

Enterprise Visualization with KendoReact

After winning with automation, SOC teams needed visualization. Built enterprise-grade dashboard with KendoReact.

Features:

  • ๐Ÿ“ˆ Real-time threat analytics and trend visualization
  • ๐ŸŽจ Professional enterprise UI components
  • โšก High-performance data grids for CVE management
  • ๐Ÿ” Advanced filtering and correlation rules

Key Learning: Automation without visualization limits SOC decision-making speed.


๐Ÿš€ Chapter 3: The Innovation (October 2025)

First Chrome AI Cybersecurity Extension

The Problem: Dashboards were reactive โ€” enterprises wait 30โ€“90 days for NVD documentation.

The Solution: First Chrome extension combining:

  • ๐Ÿง  Chrome Built-in AI (Gemini Nano) for local threat analysis
  • ๐Ÿ” CISA KEV Catalog correlation (1,400+ CVEs)
  • ๐Ÿ”ฎ Virtual CVE Intelligence โ€” industry-first system
  • โšก Proactive browser-level detection

๐Ÿ”ฎ The Game-Changer: Virtual CVE Intelligence

Solving the 90-Day Security Gap

Industry Challenge:

Day 0: Vulnerability discovered
Day 30: Security research completed
Day 60: CVE submitted to MITRE
Day 90: Official CVE published in NVD
โ†’ 90-day exposure window with NO tracking
Enter fullscreen mode Exit fullscreen mode

SOC-CERT Innovation:

Second 0: User visits suspicious URL
Second 2: Gemini Nano detects threat
Second 5: Virtual CVE created (CVE-2026-XXXXX)
Second 10: Alert with recommendations
โ†’ Immediate threat tracking from detection moment
Enter fullscreen mode Exit fullscreen mode

Virtual CVE Structure:

{
  "cve_id": "CVE-2026-202745",
  "type": "virtual",
  "url": "http://example.com/vulnerable.php?id=1'",
  "indicators": ["SQL injection", "URL encoding"],
  "riskScore": 90,
  "confidence": 0.95,
  "timestamp": "2025-10-13T10:43:37.556Z",
  "aiAnalysis": "Likely vulnerable to SQL injection attacks...",
  "recommendations": [
    "Implement input validation",
    "Use parameterized queries",
    "Deploy WAF protection"
  ]
}
Enter fullscreen mode Exit fullscreen mode

Why This Matters

Feature NVD/KEV CVEs Virtual CVEs
Detection Time 60โ€“90 days Real-time (2โ€“3s)
Coverage Known vulnerabilities Emerging threats
Tracking Post-discovery From day zero
Use Case Reactive security Proactive security

๐Ÿค– Chrome Built-in AI Integration

Production Cybersecurity Use Case

Chrome AI Stack:

  • ๐Ÿง  Prompt API (LanguageModel): Core threat analysis with Gemini Nano
  • ๐Ÿ“ Summarizer API: Concise threat alerts for SOC teams
  • โœ๏ธ Writer API: Detailed security advisories and remediation steps
  • ๐ŸŒ Translator API: Bilingual support (EN, FR) with expansion ready
  • โœ… Proofreader API: Clean, professional security reports

Example Implementation:

// Local threat analysis with Gemini Nano
const session = await ai.languageModel.create({
  systemPrompt: "You are a cybersecurity expert analyzing web pages...",
  temperature: 0.3,
  topK: 3
});

const analysis = await session.prompt(`
Analyze this code for security vulnerabilities:
${codeSnippet}
Return JSON with:
Vulnerability type
Severity (CRITICAL, HIGH, MEDIUM, LOW)
Exploitation potential
Mitigation recommendations
`);

// Concise alert generation
const summarizer = await ai.summarizer.create({
  type: 'tldr',
  length: 'short'
});
const alert = await summarizer.summarize(analysis);
Enter fullscreen mode Exit fullscreen mode

๐ŸŽฏ First CISA KEV Browser Integration

Real-Time Correlation Engine

Industry First: Browser extension with direct CISA KEV correlation.

async function correlateCISAKEV(cveId) {
  const kevData = await fetch(`${API}/cisa-kev?cve=${cveId}`);
  if (kevData.inKEV) {
    return {
      priority: 'CRITICAL',
      exploited: true,
      dueDate: kevData.actionDueDate,
      ransomwareUse: kevData.knownRansomware,
      mitigation: kevData.requiredAction
    };
  }
}
Enter fullscreen mode Exit fullscreen mode

Real CVE Example:

Detected: CVE-2020-0618 (SQL Server RCE)
CISA KEV Status: โœ… Known Exploited
CVSS Score: 9.8 (Critical)
Action Due Date: 2020-02-14
Ransomware Use: โœ… Confirmed
Required Action: Apply security updates immediately
Enter fullscreen mode Exit fullscreen mode

๐Ÿ—๏ธ The Hybrid AI Architecture

Best of Both Worlds

Client-Side (Gemini Nano):

  • โšก Speed: Instant analysis < 2 seconds
  • ๐Ÿ”’ Privacy: All sensitive data stays local
  • โœ… Offline: Works without internet connection
  • ๐Ÿง  AI Reasoning: Pattern detection and risk scoring

Server-Side (n8n + KEV):

  • ๐Ÿ“š Intelligence: Real CVE database (1,400+ vulnerabilities)
  • ๐ŸŽฏ Accuracy: Validated threat data from CISA
  • ๐Ÿ“Š Enrichment: CVSS scores, mitigation strategies, exploit info
  • ๐Ÿ”„ Updates: Live threat intelligence feeds

Architecture Flow:

Browser Visit
โ†“
โšก Analysis 1: Gemini Nano (local, <2s)
โ†“
๐Ÿ“Š Instant Results + Risk Score
โ†“
๐Ÿ”„ Analysis 2: n8n Workflow (server-side)
โ†“
๐Ÿ“š KEV Catalog Query + CVE Correlation
โ†“
โœ… Enriched Results with Real CVE Data
โ†“
๐Ÿ›ก๏ธ User Alert with Mitigation Steps
Enter fullscreen mode Exit fullscreen mode

๐Ÿ“Š Performance & Impact

Speed:

  • โšก 2.3 seconds average detection time
  • ๐Ÿš€ 38,000ร— faster than NVDโ€™s 90-day timeline
  • ๐Ÿง  Local processing (privacy-first architecture)

Coverage:

  • ๐Ÿ“‹ 1,400+ CVEs from CISA KEV Catalog
  • ๐Ÿ”ฎ Virtual CVE generation for zero-days
  • ๐ŸŒ 2 languages supported (EN, FR)

Innovation:

  • ๐Ÿฅ‡ First Virtual CVE generation system
  • ๐Ÿฅ‡ First CISA KEV browser integration
  • ๐Ÿฅ‡ First Chrome AI cybersecurity extension
  • ๐Ÿฅ‡ First hybrid AI security architecture

Localization Ready: English + French (Spanish, Japanese, Chinese coming soon).


๐Ÿ”— The Complete Ecosystem

Three Months, Three Products, One Vision:

August: n8n Automation (backend intelligence)
โ†“
September: KendoReact Dashboard (visualization)
โ†“
October: Chrome AI Extension (proactive detection)
Enter fullscreen mode Exit fullscreen mode

Data Flow:

Browser Extension โ†’ AI Analysis โ†’ Virtual CVE Generation
โ†“
n8n Enrichment โ†’ CISA KEV Correlation
โ†“
Dashboard Visualization โ†’ Analytics
โ†“
Telegram Alerts โ†’ SOC Team
Enter fullscreen mode Exit fullscreen mode

Reusing Winning Architecture:

  • โœ… Same n8n workflows (August challenge)
  • โœ… Same CISA KEV correlation logic
  • โœ… Same Telegram alerting system
  • โœ… Added: Chrome AI for proactive detection
  • โœ… Added: Virtual CVE intelligence system

๐ŸŽ“ Lessons Learned

Technical Insights

  • โœ… Gemini Nano is production-ready for security analysis
  • โœ… Hybrid architecture overcomes on-device AI limitations
  • โœ… Local processing enables privacy-first security
  • โœ… Progressive analysis provides optimal UX

Architecture Decisions

  • ๐ŸŽฏ Reuse proven workflows (n8n from winning project)
  • ๐Ÿ”„ Build ecosystems, not isolated features
  • ๐Ÿ“Š Visualize data for faster SOC decisions
  • ๐Ÿ”ฎ Innovate on emerging problems (90-day gap)

Strategic Learning

  • ๐Ÿ† Winning once isnโ€™t enough โ€” keep evolving
  • ๐Ÿ“ˆ Build on previous victories โ€” leverage your wins
  • ๐Ÿš€ Embrace new platforms early โ€” Chrome AI first-mover advantage
  • ๐Ÿ’ก Solve real problems โ€” 90-day gap costs enterprises millions

๐Ÿš€ Whatโ€™s Next

Q4 2025 Roadmap

Immediate:

  • ๐ŸŒ Chrome Web Store publication (after challenge results)
  • ๐Ÿ“Š SOC team beta program (enterprise pilot)
  • ๐Ÿ”„ Custom detection rules engine
  • ๐Ÿ“ฑ Mobile companion app

2026 Vision:

  • ๐Ÿค– Multimodal threat analysis (image/audio via Prompt API)
  • ๐Ÿ”— SIEM/SOAR platform integrations
  • ๐Ÿ‘ฅ Team collaboration features
  • ๐ŸŒ Open-source community edition

๐Ÿ† Try SOC-CERT Guardian

Chrome Extension:

๐Ÿ“‹ Devpost: https://devpost.com/software/soc-cert-guardian
๐Ÿ“บ Demo Video: https://www.youtube.com/watch?v=jEfFdMXPSn0
๐Ÿ”— GitHub: https://github.com/joupify/soc-cert-guardian-extension
๐Ÿ… Challenge: https://googlechromeai2025.devpost.com/

n8n Automation (Winner ๐Ÿ†):

๐Ÿ“– Original Article: https://dev.to/joupify/soc-cert-automated-threat-intelligence-system-with-n8n-ai-5722

๐Ÿ† Challenge: Real-Time AI Agents Challenge (August 2025)


๐Ÿ’ฌ Connect & Contribute

Questions? Ideas? Drop them in the comments!
Want to contribute? Check out the GitHub repository: https://github.com/joupify/soc-cert-guardian-extension
SOC teams interested in beta?
Open to consulting, remote roles, and partnerships.


๐Ÿ™ Acknowledgments

  • ๐Ÿ† n8n + Bright Data for the challenge platform and winning opportunity
  • ๐Ÿ“Š Progress KendoReact for enterprise UI components
  • ๐Ÿค– Google Chrome AI for pioneering Built-in AI APIs
  • ๐Ÿ” CISA for the KEV Catalog and public threat intelligence
  • ๐Ÿ’ฌ Dev.to community for continuous support and feedback

From n8n automation to Chrome AI innovation: Building the first cybersecurity extension with Virtual CVE Intelligence and real-time CISA KEV correlation.

Series: SOC-CERT Evolution ๐Ÿš€๐Ÿ“ˆ๐Ÿค–

3 months. 3 challenges. 1 ecosystem. The SOC-CERT evolution continues. ๐Ÿš€

Top comments (0)