๐ฏ TL;DR
3 Months, 3 Challenges, 1 Vision: From n8n automation winner to Chrome AI cybersecurity pioneer.
This isn't just another hackathon project โ it's solving a $10B industry problem with Virtual CVE Intelligence.
The Journey:
- ๐ August 2025: Won n8n + Bright Data AI Agents Challenge
- ๐ September 2025: Built enterprise SOC dashboard with KendoReact
- ๐ October 2025: Created first Chrome AI security extension with Virtual CVE Intelligence and CISA KEV correlation
Result: Proactive threat detection in 2.3 seconds vs NVDโs 90-day timeline
๐ Chapter 1: The Win (August 2025)
n8n + Bright Data Challenge Victory
Won the Real-Time AI Agents Challenge with SOC-CERT: Automated Threat Intelligence โ an n8n workflow automating CVE correlation and threat detection.
What it did:
- ๐ Real-time NVD + CISA KEV synchronization
- โก Bright Data proxies for reliable threat data scraping
- ๐ฏ AI-powered CVE correlation with 1,400+ known exploited vulnerabilities
- ๐ฑ Telegram alerts in 2 seconds
The Foundation: This winning workflow became the backend intelligence for all future SOC-CERT products.
๐ Chapter 2: The Dashboard (September 2025)
Enterprise Visualization with KendoReact
After winning with automation, SOC teams needed visualization. Built enterprise-grade dashboard with KendoReact.
Features:
- ๐ Real-time threat analytics and trend visualization
- ๐จ Professional enterprise UI components
- โก High-performance data grids for CVE management
- ๐ Advanced filtering and correlation rules
Key Learning: Automation without visualization limits SOC decision-making speed.
๐ Chapter 3: The Innovation (October 2025)
First Chrome AI Cybersecurity Extension
The Problem: Dashboards were reactive โ enterprises wait 30โ90 days for NVD documentation.
The Solution: First Chrome extension combining:
- ๐ง Chrome Built-in AI (Gemini Nano) for local threat analysis
- ๐ CISA KEV Catalog correlation (1,400+ CVEs)
- ๐ฎ Virtual CVE Intelligence โ industry-first system
- โก Proactive browser-level detection
๐ฎ The Game-Changer: Virtual CVE Intelligence
Solving the 90-Day Security Gap
Industry Challenge:
Day 0: Vulnerability discovered
Day 30: Security research completed
Day 60: CVE submitted to MITRE
Day 90: Official CVE published in NVD
โ 90-day exposure window with NO tracking
SOC-CERT Innovation:
Second 0: User visits suspicious URL
Second 2: Gemini Nano detects threat
Second 5: Virtual CVE created (CVE-2026-XXXXX)
Second 10: Alert with recommendations
โ Immediate threat tracking from detection moment
Virtual CVE Structure:
{
"cve_id": "CVE-2026-202745",
"type": "virtual",
"url": "http://example.com/vulnerable.php?id=1'",
"indicators": ["SQL injection", "URL encoding"],
"riskScore": 90,
"confidence": 0.95,
"timestamp": "2025-10-13T10:43:37.556Z",
"aiAnalysis": "Likely vulnerable to SQL injection attacks...",
"recommendations": [
"Implement input validation",
"Use parameterized queries",
"Deploy WAF protection"
]
}
Why This Matters
| Feature | NVD/KEV CVEs | Virtual CVEs |
|---|---|---|
| Detection Time | 60โ90 days | Real-time (2โ3s) |
| Coverage | Known vulnerabilities | Emerging threats |
| Tracking | Post-discovery | From day zero |
| Use Case | Reactive security | Proactive security |
๐ค Chrome Built-in AI Integration
Production Cybersecurity Use Case
Chrome AI Stack:
- ๐ง Prompt API (LanguageModel): Core threat analysis with Gemini Nano
- ๐ Summarizer API: Concise threat alerts for SOC teams
- โ๏ธ Writer API: Detailed security advisories and remediation steps
- ๐ Translator API: Bilingual support (EN, FR) with expansion ready
- โ Proofreader API: Clean, professional security reports
Example Implementation:
// Local threat analysis with Gemini Nano
const session = await ai.languageModel.create({
systemPrompt: "You are a cybersecurity expert analyzing web pages...",
temperature: 0.3,
topK: 3
});
const analysis = await session.prompt(`
Analyze this code for security vulnerabilities:
${codeSnippet}
Return JSON with:
Vulnerability type
Severity (CRITICAL, HIGH, MEDIUM, LOW)
Exploitation potential
Mitigation recommendations
`);
// Concise alert generation
const summarizer = await ai.summarizer.create({
type: 'tldr',
length: 'short'
});
const alert = await summarizer.summarize(analysis);
๐ฏ First CISA KEV Browser Integration
Real-Time Correlation Engine
Industry First: Browser extension with direct CISA KEV correlation.
async function correlateCISAKEV(cveId) {
const kevData = await fetch(`${API}/cisa-kev?cve=${cveId}`);
if (kevData.inKEV) {
return {
priority: 'CRITICAL',
exploited: true,
dueDate: kevData.actionDueDate,
ransomwareUse: kevData.knownRansomware,
mitigation: kevData.requiredAction
};
}
}
Real CVE Example:
Detected: CVE-2020-0618 (SQL Server RCE)
CISA KEV Status: โ
Known Exploited
CVSS Score: 9.8 (Critical)
Action Due Date: 2020-02-14
Ransomware Use: โ
Confirmed
Required Action: Apply security updates immediately
๐๏ธ The Hybrid AI Architecture
Best of Both Worlds
Client-Side (Gemini Nano):
- โก Speed: Instant analysis < 2 seconds
- ๐ Privacy: All sensitive data stays local
- โ Offline: Works without internet connection
- ๐ง AI Reasoning: Pattern detection and risk scoring
Server-Side (n8n + KEV):
- ๐ Intelligence: Real CVE database (1,400+ vulnerabilities)
- ๐ฏ Accuracy: Validated threat data from CISA
- ๐ Enrichment: CVSS scores, mitigation strategies, exploit info
- ๐ Updates: Live threat intelligence feeds
Architecture Flow:
Browser Visit
โ
โก Analysis 1: Gemini Nano (local, <2s)
โ
๐ Instant Results + Risk Score
โ
๐ Analysis 2: n8n Workflow (server-side)
โ
๐ KEV Catalog Query + CVE Correlation
โ
โ
Enriched Results with Real CVE Data
โ
๐ก๏ธ User Alert with Mitigation Steps
๐ Performance & Impact
Speed:
- โก 2.3 seconds average detection time
- ๐ 38,000ร faster than NVDโs 90-day timeline
- ๐ง Local processing (privacy-first architecture)
Coverage:
- ๐ 1,400+ CVEs from CISA KEV Catalog
- ๐ฎ Virtual CVE generation for zero-days
- ๐ 2 languages supported (EN, FR)
Innovation:
- ๐ฅ First Virtual CVE generation system
- ๐ฅ First CISA KEV browser integration
- ๐ฅ First Chrome AI cybersecurity extension
- ๐ฅ First hybrid AI security architecture
Localization Ready: English + French (Spanish, Japanese, Chinese coming soon).
๐ The Complete Ecosystem
Three Months, Three Products, One Vision:
August: n8n Automation (backend intelligence)
โ
September: KendoReact Dashboard (visualization)
โ
October: Chrome AI Extension (proactive detection)
Data Flow:
Browser Extension โ AI Analysis โ Virtual CVE Generation
โ
n8n Enrichment โ CISA KEV Correlation
โ
Dashboard Visualization โ Analytics
โ
Telegram Alerts โ SOC Team
Reusing Winning Architecture:
- โ Same n8n workflows (August challenge)
- โ Same CISA KEV correlation logic
- โ Same Telegram alerting system
- โ Added: Chrome AI for proactive detection
- โ Added: Virtual CVE intelligence system
๐ Lessons Learned
Technical Insights
- โ Gemini Nano is production-ready for security analysis
- โ Hybrid architecture overcomes on-device AI limitations
- โ Local processing enables privacy-first security
- โ Progressive analysis provides optimal UX
Architecture Decisions
- ๐ฏ Reuse proven workflows (n8n from winning project)
- ๐ Build ecosystems, not isolated features
- ๐ Visualize data for faster SOC decisions
- ๐ฎ Innovate on emerging problems (90-day gap)
Strategic Learning
- ๐ Winning once isnโt enough โ keep evolving
- ๐ Build on previous victories โ leverage your wins
- ๐ Embrace new platforms early โ Chrome AI first-mover advantage
- ๐ก Solve real problems โ 90-day gap costs enterprises millions
๐ Whatโs Next
Q4 2025 Roadmap
Immediate:
- ๐ Chrome Web Store publication (after challenge results)
- ๐ SOC team beta program (enterprise pilot)
- ๐ Custom detection rules engine
- ๐ฑ Mobile companion app
2026 Vision:
- ๐ค Multimodal threat analysis (image/audio via Prompt API)
- ๐ SIEM/SOAR platform integrations
- ๐ฅ Team collaboration features
- ๐ Open-source community edition
๐ Try SOC-CERT Guardian
Chrome Extension:
๐ Devpost: https://devpost.com/software/soc-cert-guardian
๐บ Demo Video: https://www.youtube.com/watch?v=jEfFdMXPSn0
๐ GitHub: https://github.com/joupify/soc-cert-guardian-extension
๐
Challenge: https://googlechromeai2025.devpost.com/
n8n Automation (Winner ๐):
๐ Original Article: https://dev.to/joupify/soc-cert-automated-threat-intelligence-system-with-n8n-ai-5722
๐ Challenge: Real-Time AI Agents Challenge (August 2025)
๐ฌ Connect & Contribute
Questions? Ideas? Drop them in the comments!
Want to contribute? Check out the GitHub repository: https://github.com/joupify/soc-cert-guardian-extension
SOC teams interested in beta?
Open to consulting, remote roles, and partnerships.
๐ Acknowledgments
- ๐ n8n + Bright Data for the challenge platform and winning opportunity
- ๐ Progress KendoReact for enterprise UI components
- ๐ค Google Chrome AI for pioneering Built-in AI APIs
- ๐ CISA for the KEV Catalog and public threat intelligence
- ๐ฌ Dev.to community for continuous support and feedback
From n8n automation to Chrome AI innovation: Building the first cybersecurity extension with Virtual CVE Intelligence and real-time CISA KEV correlation.
Series: SOC-CERT Evolution ๐๐๐ค
- โ Part 1: Winning n8n + Bright Data AI Agents Challenge
- โ Part 2: Enterprise Cybersecurity Dashboard with KendoReact
- ๐ข Part 3: Chrome AI Pioneer with Virtual CVE Intelligence (current)
- ๐ Part 4: Open Source Launch & Enterprise Adoption (November 2025)
3 months. 3 challenges. 1 ecosystem. The SOC-CERT evolution continues. ๐
Top comments (0)