Amazon Web Services Integration
Full-stack AWS telemetry ingested and correlated in real time.
What this integration does
Amazon Web Services meets agentic SOC
ManySignal connects to your AWS environment via native service APIs, pulling CloudTrail management events, GuardDuty findings, Security Hub aggregates, VPC Flow Logs, and Config change records into a unified OCSF timeline. Every AWS account and region is covered through a single cross-account IAM role — no per-service credentials to manage.
Cross-account, cross-region log collection via a single IAM role
Real-time GuardDuty finding ingestion with entity enrichment
AWS Config drift detection correlated with identity and network events
Data collected
- CloudTrail management and data events
- GuardDuty threat findings
- VPC Flow Logs (sampled and full)
- AWS Security Hub findings
- AWS Config configuration item changes
Actions supported
- Quarantine EC2 instance (update security group to deny-all)
- Revoke IAM session credentials
- Snapshot EBS volume for forensic preservation
- Disable IAM user or access key
- Create Security Hub custom finding on verdict
Getting started
Set up in minutes
- 1
Deploy the cross-account IAM role
- 2
Provide role ARN to ManySignal
- 3
Select data sources
- 4
Enable the AWS detection pack
- 5
Test with a simulated finding
Amazon Web Services Integration: frequently asked questions
Does ManySignal require root credentials?
No. The integration uses a cross-account IAM role with least-privilege policies. ManySignal never stores AWS credentials — only the role ARN.
Which AWS regions are supported?
All commercial AWS regions are supported. GovCloud is available for customers on the self-hosted or private-cloud deployment model.
How are VPC Flow Logs ingested?
ManySignal reads from an S3 bucket or CloudWatch Logs group. For large-volume environments, S3 with Athena-compatible partitioning is recommended to control cost.
Can I connect multiple AWS accounts?
Yes. ManySignal supports AWS Organizations integration; add a management account role and all member accounts are auto-discovered. Individual account roles are also supported.
Related integrations
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
Microsoft Sentinel Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.