avanan_security_events

Manage Check Point Avanan security events with search, filtering, and quarantine actions.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill avanan-security-events
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: avanan_security_events
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/avanan/avanan/skills/security-events
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill avanan-security-events

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the management of Check Point Avanan security events, enabling users to efficiently search, investigate, and take action on detected threats within their email and collaboration environments.

Core Features & Use Cases

  • Event Triage: Search and filter security events by type, severity, status, sender, and recipient.
  • Threat Investigation: Retrieve detailed information about specific events, including URLs, attachments, and threat intelligence.
  • Action Execution: Perform actions such as quarantining, releasing, marking as safe, or reporting events.
  • Use Case: Quickly find and quarantine all new phishing events detected in the last 24 hours across all managed tenants.

Quick Start

Search for all new phishing events detected today.

Frequently Asked Questions about avanan_security_events

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate quarantine for phishing events detected in the last 24 hours?

You can automate quarantine for phishing events by filtering security events by type, severity, and date range, then executing quarantine actions. This Skill supports searching and acting on threats detected within specific timeframes.

What is the best way to triage Avanan security events across multiple tenants?

Triage Avanan security events across multiple tenants using MSP-wide Smart API operations. You can filter events by type, severity, status, sender, and recipient for comprehensive threat investigation and management.

Can I retrieve threat intelligence details for a specific security event?

Yes, you can retrieve detailed information for specific security events, including URLs, attachments, and threat intelligence. This supports retroactive remediation and helps triage potential false positives effectively.

How do I mark quarantined email threats as safe or release them?

Mark quarantined email threats as safe or release them by executing action commands on specific security events. The Skill automates these actions alongside searching and retrieving event details within your environment.

Does this tool support filtering events by sender or recipient address?

Yes, filtering security events by sender and recipient address is fully supported. You can also filter by event type, severity, status, and date range to isolate specific threats for investigation and remediation.

When should I use retroactive remediation for malware threats?

Use retroactive remediation for malware threats when integrating new threat intelligence data. This allows you to search historical security events and apply actions like quarantine to previously undetected threats.