M ManySignal
Detection Library

The ManySignal Detection Library

1,000+ production-ready detections across 15 attack surfaces, mapped to MITRE ATT&CK, deployable in minutes. Written by detection engineers, validated in production.

1,247

production-ready detections

560

unique techniques covered

15

attack surfaces monitored

97%

MITRE ATT&CK coverage

Browse the detection library

Filter by attack surface, MITRE tactic, or detection pack.

Featured detections

Medium CloudTrail

AWS IAM Assume Role from Unfamiliar Country

Detects AssumeRole API calls originating from a country not previously observed for this principal, with geolocation enrichment from the entity graph.

High Okta System Log

Okta MFA Push Bombing

Identifies more than five consecutive rejected MFA push notifications for a single identity within a 10-minute window — indicative of MFA fatigue attacks.

High GitHub Audit Log

GitHub PAT Used From New IP Range

Detects a personal access token authenticating from a previously unobserved IP CIDR block, correlated with the token owner's historical access pattern.

High Exchange Audit Log

M365 Suspicious Mailbox Rule Creation

Flags mailbox rules that redirect, delete, or mark-as-read external emails matching keywords associated with BEC and financial fraud patterns.

Medium Kubernetes Audit

Kubernetes Secret Access Anomaly

Detects service accounts reading secrets outside their declared namespace or at an anomalously high frequency relative to their established baseline.

Critical EDR

Ransomware File Rename Burst

Identifies mass file rename events with encryption-characteristic extensions (.locked, .encrypted, randomised alphanumeric) across more than 50 files in under 60 seconds.

What ships with every ManySignal detection

Every detection in the library is more than a rule — it is a complete operational package.

Compiled detection rule

A production-ready rule in ManySignal DSL with OCSF-aligned field references, aggregation conditions, and tested threshold values. Also exported as Sigma YAML.

Triage question set

A structured question set the triage agent answers on every alert: 5-8 yes/no/value questions grounding the verdict in entity context, threat intel, and baseline deviation.

Response playbook

A governed workflow with configurable actions: disable account, isolate endpoint, revoke session, or page the on-call analyst — with blast-radius checks built in.

ATT&CK mapping

Every detection maps to one or more MITRE ATT&CK Enterprise techniques and sub-techniques, contributing to your real-time coverage map in the platform.

MITRE ATT&CK coverage density

Coverage density per tactic — darker cells indicate more detections per technique. 97% overall technique coverage.

Cloud
Identity
SaaS
Endpoint
Network
Code
Recon
ResDev
Init
Exec
Pers
PrivEsc
DefEva
CredAcc
Disc
LatMov
Coll
Exfil
C2
Impact
Sparse coverage
Full coverage

Contribute a detection

Built a detection your team is proud of? Share it with the community via Sigma YAML format. Accepted contributions are published in the library with full attribution.

Detection library: frequently asked questions

How often are new detections added to the library?

ManySignal's detection engineering team publishes new detections weekly, prioritising emerging threats tracked by our threat intelligence team. All new detections go through a review process including logic testing, false-positive validation, and ATT&CK mapping before publication.

Can I write and deploy custom detections?

Yes. ManySignal supports custom detections written in ManySignal DSL or imported as Sigma YAML. Custom rules appear alongside library rules in your coverage map and can be version-controlled in your Git repository via the detection-as-code workflow.

How are false-positive rates managed?

Each detection in the library includes a published false-positive rate from production deployments. Rules are auto-staged as 'alert-only' for the first 7 days in a new environment to allow baseline calibration before alerting. You can tune thresholds per entity type and per environment without forking the rule.

Can I test a detection rule before deploying it to production?

Yes. ManySignal's detection sandbox lets you backtest any rule against 30 days of historical events in your own environment before activating it. The sandbox shows match counts, sample matched events, and estimated alert volume per day.

How do I share detections with the community?

ManySignal supports contributing detections back to the community via the Sigma-format export and our public detection repository on GitHub. Contributed rules are reviewed and published with attribution to the contributing team.

What happens when an ATT&CK technique gets a new sub-technique in a new release?

When MITRE releases a new version of ATT&CK, ManySignal's detection engineering team reviews all mappings within 30 days. Where new sub-techniques represent meaningfully distinct detection logic, new rules are published. Existing rules are re-tagged to reflect sub-technique specificity.

Does ManySignal have detections for AI-specific threats?

Yes. The AI and MCP detection pack covers prompt injection attempts, AI agent abuse, MCP server compromise, model exfiltration, and shadow AI usage. This pack is updated frequently given the pace of AI security threat development.

Can I use the detection library without the full ManySignal platform?

Detections in the library are designed to run on the ManySignal platform and use the entity graph for context. Some detections can be exported as Sigma YAML and adapted for other SIEM platforms, but contextual detections (those that rely on behavioural baselines) require the ManySignal platform to function.

How do detection packs differ from individual detections?

A detection pack is a curated collection of individual detections scoped to a specific data source or threat category, tested together as an integrated coverage set, with shared response playbooks and coverage reporting. Individual detections can also be deployed standalone.

Deploy 1,247 detections in your environment today

Book a demo and we will show you your MITRE ATT&CK coverage map, built from your actual sources, in under 30 minutes.