# Prioritize and report Wazuh vulnerabilities with EPSS and CISA KEV

> Quick overview This workflow runs daily (or manually) to pull vulnerability findings from Wazuh Indexer, enriches CVEs with FIRST EPSS and the CISA KEV catalog, calculates a priority score, tracks finding lifecycle in n8n Data Tables, and emails an executive security report while logging run metrics. How it works 1. Runs on a daily schedule at 07:00 UTC (or via manual trigger) and loads configuration values like the Wazuh Indexer URL, scoring weights, thresholds, and email settings. 2. Queries the Wazuh vulnerability inventory from the Wazuh Indexer/OpenSearch API using Basic Auth and paginated search-after to retrieve all findings. 3. Normalizes the Wazuh results into a consistent finding record (including a stable finding key) and deduplicates CVEs into batches. 4. Fetches EPSS scores from the FIRST EPSS API in batches and downloads the CISA Known Exploited Vulnerabilities (KEV) catalog once per run. 5. Enriches each finding with EPSS and KEV context and computes an explainable prior

- **Domain**: `n8n-workflow-17782.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/17782
- Page (HTML): https://agenstry.com/agents/n8n-workflow-17782.n8n.io
- Documentation: https://n8n.io/workflows/17782
