The ManySignal Detection Library
1,000+ production-ready detections across 15 attack surfaces, mapped to MITRE ATT&CK, deployable in minutes. Written by detection engineers, validated in production.
1,247
production-ready detections
560
unique techniques covered
15
attack surfaces monitored
97%
MITRE ATT&CK coverage
Browse the detection library
Filter by attack surface, MITRE tactic, or detection pack.
By attack surface
By MITRE ATT&CK tactic
- Initial Access 9 techniques
- Execution 14 techniques
- Persistence 19 techniques
- Privilege Escalation 13 techniques
- Defense Evasion 42 techniques
- Credential Access 17 techniques
- Lateral Movement 9 techniques
- Exfiltration 9 techniques
- Command & Control 18 techniques
- Impact 14 techniques
- Collection 17 techniques
- Discovery 32 techniques
- Reconnaissance 10 techniques
- Resource Development 8 techniques
Featured detections
AWS IAM Assume Role from Unfamiliar Country
Detects AssumeRole API calls originating from a country not previously observed for this principal, with geolocation enrichment from the entity graph.
Okta MFA Push Bombing
Identifies more than five consecutive rejected MFA push notifications for a single identity within a 10-minute window — indicative of MFA fatigue attacks.
GitHub PAT Used From New IP Range
Detects a personal access token authenticating from a previously unobserved IP CIDR block, correlated with the token owner's historical access pattern.
M365 Suspicious Mailbox Rule Creation
Flags mailbox rules that redirect, delete, or mark-as-read external emails matching keywords associated with BEC and financial fraud patterns.
Kubernetes Secret Access Anomaly
Detects service accounts reading secrets outside their declared namespace or at an anomalously high frequency relative to their established baseline.
Ransomware File Rename Burst
Identifies mass file rename events with encryption-characteristic extensions (.locked, .encrypted, randomised alphanumeric) across more than 50 files in under 60 seconds.
What ships with every ManySignal detection
Every detection in the library is more than a rule — it is a complete operational package.
Compiled detection rule
A production-ready rule in ManySignal DSL with OCSF-aligned field references, aggregation conditions, and tested threshold values. Also exported as Sigma YAML.
Triage question set
A structured question set the triage agent answers on every alert: 5-8 yes/no/value questions grounding the verdict in entity context, threat intel, and baseline deviation.
Response playbook
A governed workflow with configurable actions: disable account, isolate endpoint, revoke session, or page the on-call analyst — with blast-radius checks built in.
ATT&CK mapping
Every detection maps to one or more MITRE ATT&CK Enterprise techniques and sub-techniques, contributing to your real-time coverage map in the platform.
MITRE ATT&CK coverage density
Coverage density per tactic — darker cells indicate more detections per technique. 97% overall technique coverage.
Contribute a detection
Built a detection your team is proud of? Share it with the community via Sigma YAML format. Accepted contributions are published in the library with full attribution.
Detection library: frequently asked questions
How often are new detections added to the library?
ManySignal's detection engineering team publishes new detections weekly, prioritising emerging threats tracked by our threat intelligence team. All new detections go through a review process including logic testing, false-positive validation, and ATT&CK mapping before publication.
Can I write and deploy custom detections?
Yes. ManySignal supports custom detections written in ManySignal DSL or imported as Sigma YAML. Custom rules appear alongside library rules in your coverage map and can be version-controlled in your Git repository via the detection-as-code workflow.
How are false-positive rates managed?
Each detection in the library includes a published false-positive rate from production deployments. Rules are auto-staged as 'alert-only' for the first 7 days in a new environment to allow baseline calibration before alerting. You can tune thresholds per entity type and per environment without forking the rule.
Can I test a detection rule before deploying it to production?
Yes. ManySignal's detection sandbox lets you backtest any rule against 30 days of historical events in your own environment before activating it. The sandbox shows match counts, sample matched events, and estimated alert volume per day.
How do I share detections with the community?
ManySignal supports contributing detections back to the community via the Sigma-format export and our public detection repository on GitHub. Contributed rules are reviewed and published with attribution to the contributing team.
What happens when an ATT&CK technique gets a new sub-technique in a new release?
When MITRE releases a new version of ATT&CK, ManySignal's detection engineering team reviews all mappings within 30 days. Where new sub-techniques represent meaningfully distinct detection logic, new rules are published. Existing rules are re-tagged to reflect sub-technique specificity.
Does ManySignal have detections for AI-specific threats?
Yes. The AI and MCP detection pack covers prompt injection attempts, AI agent abuse, MCP server compromise, model exfiltration, and shadow AI usage. This pack is updated frequently given the pace of AI security threat development.
Can I use the detection library without the full ManySignal platform?
Detections in the library are designed to run on the ManySignal platform and use the entity graph for context. Some detections can be exported as Sigma YAML and adapted for other SIEM platforms, but contextual detections (those that rely on behavioural baselines) require the ManySignal platform to function.
How do detection packs differ from individual detections?
A detection pack is a curated collection of individual detections scoped to a specific data source or threat category, tested together as an integrated coverage set, with shared response playbooks and coverage reporting. Individual detections can also be deployed standalone.
Deploy 1,247 detections in your environment today
Book a demo and we will show you your MITRE ATT&CK coverage map, built from your actual sources, in under 30 minutes.