Varonis · Arazzo Workflow
Varonis User High-Severity Investigation
Version 1.0.0
Find a user's high-severity alerts, pull the top alert's events, and annotate it.
View Spec
View on GitHub
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat DetectionArazzoWorkflows
Provider
Workflows
user-high-severity-investigation
Investigate a user's high-severity alerts and annotate the top one.
Retrieves high-severity alerts for a given user name, loads the events for the newest such alert, and adds an investigation note to that alert.
1
getUserAlerts
Retrieve high-severity alerts attributed to the supplied user name in descending time order.
2
getTopAlertEvents
Load the forensic events for the user's highest-priority alert to understand the activity that triggered it.
3
annotateAlert
Record an investigation note on the user's top alert to document that the insider-threat review has started.
Source API Descriptions
openapi
Arazzo Workflow Specification
Work with this as data
Every workflow here is available over the APIs.io API and to AI agents over MCP.