๐ฏ TL;DR
3 Months, 3 Challenges, 1 Vision: From n8n automation winner to Chrome AI cybersecurity pioneer.
This isn't just another hackathon project โ it's solving a $10B industry problem with Virtual CVE Intelligence.
The Journey:
- ๐ August 2025: Won n8n + Bright Data AI Agents Challenge
- ๐ September 2025: Built enterprise SOC dashboard with KendoReact
- ๐ October 2025: Created first Chrome AI security extension with Virtual CVE Intelligence and CISA KEV correlation
Result: Proactive threat detection in 2.3 seconds vs NVDโs 90-day timeline
๐ Chapter 1: The Win (August 2025)
n8n + Bright Data Challenge Victory
Won the Real-Time AI Agents Challenge with SOC-CERT: Automated Threat Intelligence โ an n8n workflow automating CVE correlation and threat detection.
What it did:
- ๐ Real-time NVD + CISA KEV synchronization
- โก Bright Data proxies for reliable threat data scraping
- ๐ฏ AI-powered CVE correlation with 1,400+ known exploited vulnerabilities
- ๐ฑ Telegram alerts in 2 seconds
The Foundation: This winning workflow became the backend intelligence for all future SOC-CERT products.
๐ Chapter 2: The Dashboard (September 2025)
Enterprise Visualization with KendoReact
After winning with automation, SOC teams needed visualization. Built enterprise-grade dashboard with KendoReact.
Features:
- ๐ Real-time threat analytics and trend visualization
- ๐จ Professional enterprise UI components
- โก High-performance data grids for CVE management
- ๐ Advanced filtering and correlation rules
Key Learning: Automation without visualization limits SOC decision-making speed.
๐ Chapter 3: The Innovation (October 2025)
First Chrome AI Cybersecurity Extension
The Problem: Dashboards were reactive โ enterprises wait 30โ90 days for NVD documentation.
The Solution: First Chrome extension combining:
- ๐ง Chrome Built-in AI (Gemini Nano) for local threat analysis
- ๐ CISA KEV Catalog correlation (1,400+ CVEs)
- ๐ฎ Virtual CVE Intelligence โ industry-first system
- โก Proactive browser-level detection
๐ฎ The Game-Changer: Virtual CVE Intelligence
Solving the 90-Day Security Gap
Industry Challenge:
Day 0: Vulnerability discovered Day 30: Security research completed Day 60: CVE submitted to MITRE Day 90: Official CVE published in NVD โ 90-day exposure window with NO tracking SOC-CERT Innovation:
Second 0: User visits suspicious URL Second 2: Gemini Nano detects threat Second 5: Virtual CVE created (CVE-2026-XXXXX) Second 10: Alert with recommendations โ Immediate threat tracking from detection moment Virtual CVE Structure:
{ "cve_id": "CVE-2026-202745", "type": "virtual", "url": "http://example.com/vulnerable.php?id=1'", "indicators": ["SQL injection", "URL encoding"], "riskScore": 90, "confidence": 0.95, "timestamp": "2025-10-13T10:43:37.556Z", "aiAnalysis": "Likely vulnerable to SQL injection attacks...", "recommendations": [ "Implement input validation", "Use parameterized queries", "Deploy WAF protection" ] } Why This Matters
| Feature | NVD/KEV CVEs | Virtual CVEs |
|---|---|---|
| Detection Time | 60โ90 days | Real-time (2โ3s) |
| Coverage | Known vulnerabilities | Emerging threats |
| Tracking | Post-discovery | From day zero |
| Use Case | Reactive security | Proactive security |
๐ค Chrome Built-in AI Integration
Production Cybersecurity Use Case
Chrome AI Stack:
- ๐ง Prompt API (LanguageModel): Core threat analysis with Gemini Nano
- ๐ Summarizer API: Concise threat alerts for SOC teams
- โ๏ธ Writer API: Detailed security advisories and remediation steps
- ๐ Translator API: Bilingual support (EN, FR) with expansion ready
- โ Proofreader API: Clean, professional security reports
Example Implementation:
// Local threat analysis with Gemini Nano const session = await ai.languageModel.create({ systemPrompt: "You are a cybersecurity expert analyzing web pages...", temperature: 0.3, topK: 3 }); const analysis = await session.prompt(` Analyze this code for security vulnerabilities: ${codeSnippet} Return JSON with: Vulnerability type Severity (CRITICAL, HIGH, MEDIUM, LOW) Exploitation potential Mitigation recommendations `); // Concise alert generation const summarizer = await ai.summarizer.create({ type: 'tldr', length: 'short' }); const alert = await summarizer.summarize(analysis); ๐ฏ First CISA KEV Browser Integration
Real-Time Correlation Engine
Industry First: Browser extension with direct CISA KEV correlation.
async function correlateCISAKEV(cveId) { const kevData = await fetch(`${API}/cisa-kev?cve=${cveId}`); if (kevData.inKEV) { return { priority: 'CRITICAL', exploited: true, dueDate: kevData.actionDueDate, ransomwareUse: kevData.knownRansomware, mitigation: kevData.requiredAction }; } } Real CVE Example:
Detected: CVE-2020-0618 (SQL Server RCE) CISA KEV Status: โ
Known Exploited CVSS Score: 9.8 (Critical) Action Due Date: 2020-02-14 Ransomware Use: โ
Confirmed Required Action: Apply security updates immediately ๐๏ธ The Hybrid AI Architecture
Best of Both Worlds
Client-Side (Gemini Nano):
- โก Speed: Instant analysis < 2 seconds
- ๐ Privacy: All sensitive data stays local
- โ Offline: Works without internet connection
- ๐ง AI Reasoning: Pattern detection and risk scoring
Server-Side (n8n + KEV):
- ๐ Intelligence: Real CVE database (1,400+ vulnerabilities)
- ๐ฏ Accuracy: Validated threat data from CISA
- ๐ Enrichment: CVSS scores, mitigation strategies, exploit info
- ๐ Updates: Live threat intelligence feeds
Architecture Flow:
Browser Visit โ โก Analysis 1: Gemini Nano (local, <2s) โ ๐ Instant Results + Risk Score โ ๐ Analysis 2: n8n Workflow (server-side) โ ๐ KEV Catalog Query + CVE Correlation โ โ
Enriched Results with Real CVE Data โ ๐ก๏ธ User Alert with Mitigation Steps ๐ Performance & Impact
Speed:
- โก 2.3 seconds average detection time
- ๐ 38,000ร faster than NVDโs 90-day timeline
- ๐ง Local processing (privacy-first architecture)
Coverage:
- ๐ 1,400+ CVEs from CISA KEV Catalog
- ๐ฎ Virtual CVE generation for zero-days
- ๐ 2 languages supported (EN, FR)
Innovation:
- ๐ฅ First Virtual CVE generation system
- ๐ฅ First CISA KEV browser integration
- ๐ฅ First Chrome AI cybersecurity extension
- ๐ฅ First hybrid AI security architecture
Localization Ready: English + French (Spanish, Japanese, Chinese coming soon).
๐ The Complete Ecosystem
Three Months, Three Products, One Vision:
August: n8n Automation (backend intelligence) โ September: KendoReact Dashboard (visualization) โ October: Chrome AI Extension (proactive detection) Data Flow:
Browser Extension โ AI Analysis โ Virtual CVE Generation โ n8n Enrichment โ CISA KEV Correlation โ Dashboard Visualization โ Analytics โ Telegram Alerts โ SOC Team Reusing Winning Architecture:
- โ Same n8n workflows (August challenge)
- โ Same CISA KEV correlation logic
- โ Same Telegram alerting system
- โ Added: Chrome AI for proactive detection
- โ Added: Virtual CVE intelligence system
๐ Lessons Learned
Technical Insights
- โ Gemini Nano is production-ready for security analysis
- โ Hybrid architecture overcomes on-device AI limitations
- โ Local processing enables privacy-first security
- โ Progressive analysis provides optimal UX
Architecture Decisions
- ๐ฏ Reuse proven workflows (n8n from winning project)
- ๐ Build ecosystems, not isolated features
- ๐ Visualize data for faster SOC decisions
- ๐ฎ Innovate on emerging problems (90-day gap)
Strategic Learning
- ๐ Winning once isnโt enough โ keep evolving
- ๐ Build on previous victories โ leverage your wins
- ๐ Embrace new platforms early โ Chrome AI first-mover advantage
- ๐ก Solve real problems โ 90-day gap costs enterprises millions
๐ Whatโs Next
Q4 2025 Roadmap
Immediate:
- ๐ Chrome Web Store publication (after challenge results)
- ๐ SOC team beta program (enterprise pilot)
- ๐ Custom detection rules engine
- ๐ฑ Mobile companion app
2026 Vision:
- ๐ค Multimodal threat analysis (image/audio via Prompt API)
- ๐ SIEM/SOAR platform integrations
- ๐ฅ Team collaboration features
- ๐ Open-source community edition
๐ Try SOC-CERT Guardian
Chrome Extension:
๐ Devpost: https://devpost.com/software/soc-cert-guardian
๐บ Demo Video: https://www.youtube.com/watch?v=jEfFdMXPSn0
๐ GitHub: https://github.com/joupify/soc-cert-guardian-extension
๐
Challenge: https://googlechromeai2025.devpost.com/
n8n Automation (Winner ๐):
๐ Original Article: https://dev.to/joupify/soc-cert-automated-threat-intelligence-system-with-n8n-ai-5722
๐ Challenge: Real-Time AI Agents Challenge (August 2025)
๐ฌ Connect & Contribute
Questions? Ideas? Drop them in the comments!
Want to contribute? Check out the GitHub repository: https://github.com/joupify/soc-cert-guardian-extension
SOC teams interested in beta?
Open to consulting, remote roles, and partnerships.
๐ Acknowledgments
- ๐ n8n + Bright Data for the challenge platform and winning opportunity
- ๐ Progress KendoReact for enterprise UI components
- ๐ค Google Chrome AI for pioneering Built-in AI APIs
- ๐ CISA for the KEV Catalog and public threat intelligence
- ๐ฌ Dev.to community for continuous support and feedback
From n8n automation to Chrome AI innovation: Building the first cybersecurity extension with Virtual CVE Intelligence and real-time CISA KEV correlation.
Series: SOC-CERT Evolution ๐๐๐ค
- โ Part 1: Winning n8n + Bright Data AI Agents Challenge
- โ Part 2: Enterprise Cybersecurity Dashboard with KendoReact
- ๐ข Part 3: Chrome AI Pioneer with Virtual CVE Intelligence (current)
- ๐ Part 4: Open Source Launch & Enterprise Adoption (November 2025)
3 months. 3 challenges. 1 ecosystem. The SOC-CERT evolution continues. ๐
Top comments (0)