Varonis · Arazzo Workflow
Varonis User High-Severity Investigation
Version 1.0.0
Find a user's high-severity alerts, pull the top alert's events, and annotate it.
View Spec
View on GitHub
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat DetectionArazzoWorkflows
Provider
Workflows
user-high-severity-investigation
Investigate a user's high-severity alerts and annotate the top one.
Retrieves high-severity alerts for a given user name, loads the events for the newest such alert, and adds an investigation note to that alert.
1
getUserAlerts
getAlerts
Retrieve high-severity alerts attributed to the supplied user name in descending time order.
2
getTopAlertEvents
getAlertedEvents
Load the forensic events for the user's highest-priority alert to understand the activity that triggered it.
3
annotateAlert
addAlertNote
Record an investigation note on the user's top alert to document that the insider-threat review has started.
Source API Descriptions
Arazzo Workflow Specification
Work with this as data
Every workflow here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for arazzo workflows
4 MCP tools reach this
find_arazzoBrowse and filter every workflow in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/varonis-user-high-severity-investigation-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.