M ManySignal

Integration Category

Cloud & IaaS Integrations

Connect ManySignal to your AWS, Azure, GCP, and edge infrastructure. CloudTrail, Entra ID, VPC Flow Logs, GuardDuty, Security Command Center — all correlated in a unified cloud threat detection timeline.

Data collected across cloud integrations

  • Cloud management API calls and control-plane operations
  • Network flow logs for VPC and virtual network traffic
  • Security service findings (GuardDuty, Security Command Center, Defender)
  • Resource configuration change events
  • Identity and access management events (IAM roles, policies)
  • Compliance evaluation results and posture findings

Automated response actions

  • Isolate EC2 instance, Azure VM, or GCP Compute instance via API
  • Revoke IAM credentials or disable service accounts on verdict
  • Add restrictive security group / firewall rule on suspicious IP
  • Create ServiceNow, Jira, or PagerDuty incident automatically
  • Trigger AWS Lambda or Azure Function for custom remediation
  • Apply restrictive SCP to an AWS account under investigation

Setup considerations

What to know before you connect

IAM permissions

Cloud integrations require read-only IAM roles/service principals. ManySignal provides Terraform and CloudFormation templates to create the minimum necessary permissions without manual configuration.

Log delivery latency

Most cloud audit logs have a 5–15 minute delivery delay to S3 or Log Analytics. For near-real-time detection, use EventBridge (AWS) or Event Hub (Azure) for sub-minute event delivery.

Multi-account / multi-subscription

AWS Organisations and Azure Management Groups allow a single ManySignal integration to monitor all accounts and subscriptions. No per-account credentials needed.

Data residency

ManySignal's data residency options let you store cloud telemetry in your chosen geographic region. Contact your account team if data must remain in specific jurisdictions.

Cloud integration FAQs

What cloud providers does ManySignal support?

ManySignal has native connectors for Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) with equal coverage depth across all three. Each cloud provider connector ingests security service findings, audit logs, network flow data, and identity events.

How does ManySignal connect to AWS?

ManySignal connects via a cross-account IAM role with read-only permissions on CloudTrail, GuardDuty, Security Hub, Config, and VPC Flow Logs. A single role covers all AWS accounts in your organisation via the AWS Organisations integration.

What cloud events does ManySignal prioritise for detection?

High-priority events include: privilege escalation (IAM policy attachment, new admin role assumption), data exfiltration indicators (bulk S3 access, snapshot copying), persistence (new IAM users, API keys), and defence evasion (CloudTrail disabling, GuardDuty suppression).

Does ManySignal support multi-account AWS organisations?

Yes. Configure ManySignal once with an organisation-level role and it automatically monitors all accounts, including new accounts added to the organisation. A single pane of glass shows activity across the entire AWS footprint.

Can ManySignal take automated response actions in cloud environments?

Yes. ManySignal can isolate EC2 instances (security group modification), revoke IAM credentials, disable service accounts, and apply restrictive SCPs to AWS accounts — all triggered automatically on high-confidence verdicts or via analyst approval workflow.

How does ManySignal correlate cloud events with identity and endpoint data?

ManySignal's entity graph correlates cloud IAM principals with their associated human identities (from Okta, Entra ID) and endpoint devices (from CrowdStrike, SentinelOne). A single investigation view shows the full attack chain across cloud, identity, and endpoint.

What is the latency between a cloud event and a ManySignal alert?

AWS CloudTrail events are ingested within 5–15 minutes of occurrence (CloudTrail delivery latency). GuardDuty findings and Security Hub alerts appear within 2–5 minutes. Near-real-time events from EventBridge can be configured for sub-minute delivery.

Does ManySignal support multi-cloud environments with AWS, Azure, and GCP simultaneously?

Yes. ManySignal is designed for multi-cloud environments. Detections span all three cloud providers and are correlated at the identity and entity level — for example, detecting when a compromised Okta credential is used across both AWS and GCP.

What cloud compliance frameworks does ManySignal map to?

ManySignal maps detections to CIS Benchmarks for AWS/Azure/GCP, NIST CSF, SOC 2 CC controls, PCI DSS cloud requirements, and ISO 27001 cloud annexes. Compliance coverage reports are generated automatically.

How does ManySignal handle cloud Terraform or IaC-driven infrastructure changes?

ManySignal correlates Terraform Cloud and CI/CD pipeline events with downstream cloud API calls. IaC-driven changes are distinguished from direct API calls, enabling detection of out-of-band changes that bypass the approved IaC workflow.

Connect your cloud environment to ManySignal

Deploy the cloud connectors in minutes and see your first cloud threat detections within an hour.