Product updates, company milestones, research publications, and engineering deep-dives — in reverse chronological order.
Product Update
Detection-as-Code v2.0: Native GitHub Actions Integration and Auto-Validation
The ManySignal Detection SDK v2.0 ships with a native GitHub Actions runner, SIGMA lint scoring, and an automated test harness that runs your rule set against a continuously updated corpus of real attack replay data. Every merge triggers a coverage report.
Funding
ManySignal Closes $47M Series B
We announced our Series B led by Greenfield Ventures. The round funds detection library expansion, EU market launch, and 40 new hires across engineering, detection research, and go-to-market. Read the full announcement on the Press page.
Product Update
Governed Response Automation Now Generally Available
After six months in customer beta with 14 enterprise SOCs, Governed Response Automation is now GA. Configure autonomous response playbooks with approval thresholds, kill switches, and RBAC — and every action is logged immutably to the audit trail.
ManySignal Threat Intelligence publishes its quarterly adversary report. Key finding: LLM-generated phishing lures evade traditional URL reputation and language-model classifier detections at a 2.4x higher rate than Q1. Detection guidance and SIGMA rules included.
Community
Detection Day #8 Recap: 340 Practitioners, 12 Rule Packs Released
Our eighth monthly Detection Day virtual event drew 340 registered security engineers. The community shipped 12 new open-source detection rule packs covering Azure AD persistence, container escape patterns, and AWS CloudTrail evasion. Rules are available in the GitHub org.
Partnership
CrowdStrike Falcon Integration: Bidirectional Telemetry and Response
Joint customers can stream Falcon endpoint telemetry into ManySignal's entity graph and push isolation and containment actions back to Falcon from the ManySignal response console — no CSV exports, no manual re-entry.
Compliance
SOC 2 Type II Report Available — Achieving 99.97% Uptime Across the Period
Our first SOC 2 Type II examination covers the 12-month period ending April 30, 2026. The report is clean with no exceptions. Actual uptime over the period was 99.97%. Request access from your account team or via the Trust Portal.
Engineering
How We Reduced Alert-Triage Latency from 400ms to 18ms
A deep-dive from the ManySignal Platform Engineering team on how we redesigned the entity graph cache layer, replaced JSON serialisation with FlatBuffers, and eliminated three unnecessary network hops in the triage hot path. Full technical post on the engineering blog.
Product Update
Investigation Timeline View: Visualise Attacker Chains Across Hours or Days
The Investigation Timeline is a new UI component that renders an attacker's full sequence of observed behaviours as a zoomable, scrollable timeline. Link any alert verdict to the entity actions that preceded and followed it. Now in beta for all plans.
Company
ManySignal Joins FIRST as an Associate Member
ManySignal has joined the Forum of Incident Response and Security Teams (FIRST) as an Associate Member. Membership improves our access to coordinated vulnerability disclosure channels and the global incident response community.
Stay current
Get product updates and threat intelligence in your inbox — roughly twice a month, never more.
No spam. Unsubscribe at any time. See our Privacy Policy.