Varonis · Arazzo Workflow
Varonis User High-Severity Investigation
Version 1.0.0
Find a user's high-severity alerts, pull the top alert's events, and annotate it.
View Spec
View on GitHub
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat DetectionArazzoWorkflows
Provider
Workflows
user-high-severity-investigation
Investigate a user's high-severity alerts and annotate the top one.
Retrieves high-severity alerts for a given user name, loads the events for the newest such alert, and adds an investigation note to that alert.
1
getUserAlerts
getAlerts
Retrieve high-severity alerts attributed to the supplied user name in descending time order.
2
getTopAlertEvents
getAlertedEvents
Load the forensic events for the user's highest-priority alert to understand the activity that triggered it.
3
annotateAlert
addAlertNote
Record an investigation note on the user's top alert to document that the insider-threat review has started.