About this workflow
Workflow Analysis: Perform a Domain Search (Single) with Icypeas
This N8n workflow template is designed to automate the process of performing a single domain or company reconnaissance scan using Icypeas, a powerful open-source intelligence (OSINT) tool that helps uncover digital footprints, subdomains, associated email addresses, and other publicly exposed information related to a target domain or organization. The workflow integrates seamlessly with the Icypeas API by handling authentication, generating secure signatures, and triggering a domain scan—all within the n8n automation platform.
What the Workflow Does
The primary function of this workflow is to initiate a domain or company scan via the Icypeas API. It starts from a manual trigger, authenticates the user using their API credentials (key, secret, and user ID), generates a cryptographically signed request header for security, and sends a POST request to the Icypeas API endpoint to begin scanning a specified domain or company name. Once executed, the scan runs on the Icypeas platform, and results can be viewed directly in your Icypeas dashboard.
This automation eliminates the need for manual API calls and ensures secure, repeatable execution of domain investigations—ideal for cybersecurity professionals, penetration testers, threat hunters, or IT administrators conducting surface-level exposure assessments.
Key Features and Capabilities
- Secure Authentication: Implements HMAC-SHA1 signature generation using
cryptomodule to securely sign API requests. - Dynamic Credential Handling: Uses runtime-generated headers based on timestamped signatures to meet Icypeas' security requirements.
- Manual Execution Control: Triggered manually, allowing users to run scans on-demand.
- Customizable Target Input: Allows users to define which domain or company to scan directly in the HTTP Request node.
- Self-Hosted Compatibility: Includes guidance for enabling the required
cryptomodule in self-hosted n8n instances. - Clear Documentation via Sticky Notes: Embedded instructional notes guide users through setup, configuration, and usage.
Main Nodes and Their Purposes
1. When clicking "Execute Workflow" (Manual Trigger Node)
- Type:
n8n-nodes-base.manualTrigger - Purpose: Serves as the starting point of the workflow. Initiates execution when the user clicks the "Execute Workflow" button in the n8n UI.
- Functionality: Provides a simple way to test or manually launch the domain scan without scheduling or external triggers.
2. Sticky Note(s) (Documentation Nodes)
- Types: Multiple
n8n-nodes-base.stickyNotenodes - Purpose: Act as embedded documentation panels within the canvas.
- Content Includes:
- Overview of the workflow’s purpose.
- Instructions for inserting API credentials into the Code node.
- Steps to enable the
cryptomodule in self-hosted environments. - Guidance on configuring the HTTP Request node (headers, body parameters).
- Link to view results in the Icypeas web interface.
These are non-functional but crucial for onboarding new users and ensuring correct setup.
3. Authenticates to your Icypeas account (Code Node)
- Type:
n8n-nodes-base.code - Language: JavaScript (
jsCode) - Purpose: Generates all necessary authentication data including:
- Current timestamp (ISO format)
- Full API URL
- HMAC-SHA1 signature derived from method, path, API secret, and timestamp
- Key Variables Set:
$input.first().json.api = { timestamp, secret: API_SECRET, key: API_KEY, userId: USER_ID, url: "https://app.icypeas.com/api/domain-search", signature: generatedSignature } - Security Note: Relies on Node.js
cryptomodule; must be enabled in self-hosted setups.
This node prepares the contextual data needed for secure communication with Icypeas.
4. Run domain scan (single) (HTTP Request Node)
- Type:
n8n-nodes-base.httpRequest - Method: POST
- URL: Dynamically set to
={{ $json.api.url }} - Headers Sent:
X-ROCK-TIMESTAMP:={{ $json.api.timestamp }}- Authorization: Constructed via credentials as
{{ $json.api.key }}:{{ $json.api.signature }}
- Body Parameter:
domainOrCompany: Default value set to"google"(user-modifiable)
- Authentication Type: Header-based (
httpHeaderAuth) using stored credential named “Header Auth account” - Purpose: Executes the actual API call to start the domain scan on Icypeas servers.
Results are not returned directly in n8n but processed asynchronously by Icypeas.
Use Cases and Benefits
✅ Ideal For:
- Cybersecurity Assessments: Quickly assess an organization's public attack surface.
- Penetration Testing Preparation: Gather subdomain and contact information before engagement.
- Brand Monitoring: Detect unauthorized use of corporate domains or subsidiaries.
- Bug Bounty Research: Automate initial recon steps across multiple targets.
- IT Security Audits: Regularly check for unknown assets tied to the company.
🌟 Benefits:
- Automation Efficiency: Eliminates repetitive manual API calls.
- Enhanced Accuracy: Reduces human error in signing requests.
- Integration Ready: Can be extended later to accept input from spreadsheets, webhooks, or forms.
- Scalable Foundation: This single-scan version can evolve into batch processing workflows.
- Educational Value: Demonstrates secure API pattern practices like time-limited signatures and header-based auth.
Step-by-Step Workflow Logic
-
Trigger Execution
- User clicks "Execute Workflow" in the n8n editor.
- Manual trigger node activates and passes control to the next node.
-
Authentication & Signature Generation
- The Code Node executes JavaScript:
- Defines constants: base URL, API path, HTTP method.
- Loads user-provided
API_KEY,API_SECRET, andUSER_ID. - Generates current ISO timestamp.
- Constructs payload string:
${METHOD}${PATH}${TIMESTAMP}in lowercase. - Uses
crypto.createHmac()to generate SHA1 hash usingAPI_SECRET. - Stores resulting
signature, along with other values, under$json.api.
- The Code Node executes JavaScript:
-
Prepare and Send Scan Request
- Data flows to the HTTP Request Node:
- URL is dynamically set to
https://app.icypeas.com/api/domain-search. - Method is POST.
- Header
X-ROCK-TIMESTAMPis populated with the generated timestamp. - Authorization Header is built using expression:
{{ $json.api.key }}:{{ $json.api.signature }}. - Body contains one parameter:
domainOrCompany(e.g.,google).
- URL is dynamically set to
- Data flows to the HTTP Request Node:
-
API Call Execution
- n8n sends the authenticated POST request to Icypeas.
- Icypeas verifies the signature and timestamp.
- If valid, it queues a new domain search task.
-
View Results
- No direct output is captured in n8n.
- Users are directed to log in to Icypeas Business Office to view scan results.
-
Optional Follow-Up
- Future enhancements could include polling for results, parsing findings, or exporting reports.
Summary
This workflow exemplifies how n8n can streamline secure interactions with third-party APIs requiring cryptographic authentication. By combining manual initiation, dynamic code execution, and HTTP requests, it enables efficient, auditable, and repeatable domain reconnaissance using Icypeas. With proper setup—especially inserting valid credentials and enabling the crypto module—it becomes a valuable asset in any OSINT toolkit.
How to use: download the JSON, then in n8n choose “Import from File”.