Varonis · Arazzo Workflow
Varonis Threat Model Hunt
Version 1.0.0
Resolve a threat model by name, pull its recent alerts, and load the newest alert's events.
View Spec
View on GitHub
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat DetectionArazzoWorkflows
Provider
Workflows
threat-model-hunt
Pivot from a threat model name to its recent alerts and forensic events.
Looks up a threat model by name, retrieves recent alerts attributed to that model name, and loads the events behind the newest matching alert for forensic review.
1
resolveThreatModel
getThreatModels
Resolve the threat model definition by name to confirm it exists and to capture its category and severity before hunting on its alerts.
2
getModelAlerts
getAlerts
Retrieve recent alerts generated by the resolved threat model name in descending time order.
3
getNewestAlertEvents
getAlertedEvents
Load the forensic events behind the newest alert produced by the threat model to understand the detected activity.
Source API Descriptions
Arazzo Workflow Specification
Work with this as data
Every workflow here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for arazzo workflows
4 MCP tools reach this
find_arazzoBrowse and filter every workflow in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/varonis-threat-model-hunt-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.