Varonis Threat Detection and Response
Unified workflow capability for SOC analysts performing threat detection, alert triage, and incident response using the Varonis DatAlert API. Combines alert management, forensic event investigation, and threat model reference into a single AI-accessible interface.
What You Can Do
MCP Tools
get-alerts
Retrieve Varonis DatAlert security alerts with filtering by threat model, severity, status, and time range.
update-alert-status
Update the status of a Varonis DatAlert alert to Open or Under Investigation, with optional investigation note.
close-alert
Close a Varonis DatAlert alert with a resolution reason such as Resolved, Legitimate activity, or Misconfiguration.
add-alert-note
Add an investigation note to a Varonis DatAlert alert to document findings and remediation steps.
get-alerted-events
Retrieve forensic events associated with a Varonis alert for threat hunting and incident investigation.
get-threat-models
List Varonis DatAlert threat model definitions including category, severity, and MITRE ATT&CK alignment.