Role-Based LinkedIn Profile Discovery using Google Search OSINT - n8n Workflow

Use this powerful n8n workflow to automate Open-Source Intelligence (OSINT) gathering, specifically targeting LinkedIn profiles based on defined roles or keywords using the Google Search API. Ideal for security analysis.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?

OSINT Researchers: Professionals needing structured, repeatable methods for public data collection.
Security & Red Teams: Analysts focused on building social graphs or target lists for simulated attacks.
Competitive Intelligence Analysts: Users seeking to map out organizational structures of competitors.
n8n Automation Users: Anyone looking for advanced examples of HTTP Request usage combined with data storage in Google Sheets.

Overview

This advanced n8n workflow serves as an automated reconnaissance tool designed to efficiently build a target list of LinkedIn profiles. Often used in Red Team operations or competitive analysis, this powerful n8n template eliminates manual searching.

The core challenge in OSINT is scaling the search and standardizing the output. This n8n node sequence solves this by defining precise search queries (e.g., specific job roles within a company domain) and pushing them through the Google Search API. The structured data returned by the API is then cleaned and appended directly to a Google Sheet, creating a dynamic, organized 'Social Graph' or target database. Utilizing this n8n workflow drastically speeds up the initial phase of information gathering.

How it Works

The process begins with the manual n8n trigger, initiating the collection process.


  1. Trigger and Setup: The workflow starts with the โšก Trigger SocialGraph n8n trigger. This immediately flows into the ๐Ÿง  Set Search Queries n8n node, which contains the list of pre-defined Google Dorks (e.g., site:linkedin.com/in/ "job title" "company name").

  2. Query Splitting: The list of queries is then passed to the ๐Ÿ” Split Queries n8n node. This essential flow control step ensures that each query is run individually and sequentially, managing API rate limits and preventing large payload errors.

  3. Data Extraction: For each query, the flow executes the ๐ŸŒ Google Search API n8n node, making an HTTP Request to perform the specialized search. This request is configured to return structured JSON data containing search results, including potential LinkedIn URLs.

  4. Profile Cleanup: The raw JSON output is then processed by the ๐Ÿงช Extract Profiles n8n node. This set n8n node extracts the necessary profile fields (like URL, title, snippet) from the complex API response.

  5. Data Persistence: Finally, the cleaned profile data is sent to the ๐Ÿ“„ Append to RedOps_Targets n8n node (Google Sheets), where it is added as a new row in a designated spreadsheet. The flow then loops back to the ๐Ÿ” Split Queries n8n node to process the next search term until all queries are exhausted. This repeatable n8n workflow ensures comprehensive data collection.

Installation Guide

To implement this n8n workflow, follow these steps:


  1. Import the n8n template: Copy the provided JSON and paste it into your n8n instance via the 'New' menu > 'Import from JSON'.

  2. Google Sheets Credential: Click on the ๐Ÿ“„ Append to RedOps_Targets n8n node and create or select a Google Sheets credential allowing read/write access to the spreadsheet where targets will be stored.

  3. Google Search API Setup: Configure the ๐ŸŒ Google Search API HTTP Request n8n node. This requires either a dedicated API key (such as Google Custom Search JSON API) or a third-party OSINT tool endpoint. Ensure your API endpoint and key are correctly placed in the request URL or headers.

  4. Define Queries: Open the ๐Ÿง  Set Search Queries n8n node and update the input data with the specific search queries (Google Dorks) you wish to execute.

  5. Activation: Once credentials and settings are complete, activate the n8n workflow and run the โšก Trigger SocialGraph n8n trigger manually.

Node Details

This n8n workflow utilizes several key nodes to achieve its objective:

โšก Trigger SocialGraph (Manual Trigger n8n trigger): The starting point for the n8n workflow. Used here for on-demand execution of the OSINT operation.
๐Ÿง  Set Search Queries (Set n8n node): Holds the input dataโ€”an array of search query strings (Google Dorks). This is the source of the targets for the entire n8n workflow.
๐Ÿ” Split Queries (Split In Batches n8n node): Splits the array of queries into individual items, ensuring the downstream Google Search API n8n node processes one query per execution cycle, which is crucial for managing rate limits.
๐ŸŒ Google Search API (HTTP Request n8n node): The core of the extraction logic. Sends the search query as a parameter to the external Google Search endpoint. Key Configuration: Requires specific URL structure for accessing the search API.
๐Ÿงช Extract Profiles (Set n8n node): Processes the incoming JSON data from the Google Search API. Function: Uses expressions or JQ processing to isolate the relevant fields (title, snippet, link) corresponding to the LinkedIn profiles found.
๐Ÿ“„ Append to RedOps_Targets (Google Sheets n8n node): The final storage step. Function: Appends the structured profile data extracted by the previous n8n node to a specified Google Sheet, ensuring persistence and centralized tracking of targets.

Related n8n Workflows

Paid

Nodes: 6 Nodes
Updated: December 26 2025
View all
Created by

Founder of CYBERPULSE AI โ€” helping security teams and SMEs eliminate repetitive tasks through modular n8n automations. I build workflows for vulnerability triage, compliance reporting, threat intel, and Red/Blue/GRC ops. Book a session if you'd like custom automation for your use case. https://linkedin.com/in/adnan-tariq-4b2a1a47

Featured*