Integration Category
Endpoint & EDR Integrations
CrowdStrike Falcon, SentinelOne, Microsoft Defender, Palo Alto Cortex XDR — ManySignal correlates endpoint detections with identity and cloud events for complete attack chain visibility.
Supported integrations
Endpoint protection and device management platforms
CrowdStrike Falcon
Detections, events, threat graph data, device management
SentinelOne
Threats, alerts, events, deep visibility telemetry
Microsoft Defender
Endpoint alerts, advanced hunting events, device timeline
Palo Alto Cortex XDR
Incidents, alerts, causality chains, endpoint data
Sophos Central
Threat detections, device health, tamper protection events
Trend Micro
Detection events, response logs, threat intelligence
Carbon Black
Process events, alerts, watchlist hits, device data
Tanium
Threat response alerts, endpoint inventory, compliance data
Jamf
macOS device compliance, MDM events, management logs
Kandji
Apple device management events, compliance status
Automox
Patch compliance, software inventory, remediation events
Fleet
osquery results, device inventory, vulnerability data
Data collected across EDR integrations
- Endpoint detection and alert events with process chain context
- Process creation, network connection, and file system events
- Device inventory and compliance status changes
- Threat intelligence matches and known-bad indicator hits
- EDR telemetry for custom detection and threat hunting
- MDM policy compliance and management command events
Automated response actions
- Network isolate a compromised endpoint via EDR API
- Kill a malicious process or quarantine a file on endpoint
- Run a live response investigation command on the endpoint
- Force device compliance scan and patch remediation
- Wipe or lock a managed mobile or macOS device
- Trigger an EDR-native playbook on verdict
Endpoint integration FAQs
Does ManySignal require an EDR to be deployed?
No. ManySignal works without an EDR connector, using identity, cloud, and SaaS telemetry for detection. However, adding an EDR connector (CrowdStrike, SentinelOne, etc.) dramatically improves detection coverage, particularly for post-compromise activity on endpoints.
What is the difference between using CrowdStrike standalone and using it with ManySignal?
CrowdStrike Falcon provides excellent endpoint detection and prevention. ManySignal correlates CrowdStrike endpoint alerts with Okta authentication events, AWS CloudTrail, and other sources — building a complete attack chain rather than isolated endpoint alerts. Triage that takes an analyst 30 minutes in Falcon is automated in seconds by ManySignal.
Does ManySignal support multiple EDR vendors simultaneously?
Yes. Many organisations have a mix of EDR vendors (CrowdStrike for Windows/Linux, Jamf/Kandji for macOS, Microsoft Defender on some segments). ManySignal ingests all of them and correlates across vendors at the entity level.
Can ManySignal automatically isolate a compromised endpoint?
Yes. When a high-confidence verdict fires for an endpoint-specific threat, ManySignal can trigger network isolation via the CrowdStrike, SentinelOne, or Microsoft Defender API. The isolation action is logged with the triggering evidence and confidence score.
How does ManySignal handle EDR alert storms?
During ransomware or mass malware events, EDR platforms can generate thousands of alerts simultaneously. ManySignal's entity-graph deduplication groups alerts by affected device and attack chain, presenting the incident as a single investigation rather than a flood of individual alerts.
What is deep visibility (SentinelOne) and how does ManySignal use it?
SentinelOne Deep Visibility provides granular process, file, and network telemetry beyond standard detection events. ManySignal ingests this telemetry for custom threat hunting queries and for building richer evidence chains in investigation timelines.
Does ManySignal work with Windows, macOS, and Linux endpoints?
Yes. All major EDR platforms supported by ManySignal cover Windows, macOS, and Linux. ManySignal ingests events from all OS types without platform-specific limitations.
How does ManySignal enrich EDR alerts with identity context?
ManySignal's entity graph links the device identifier from the EDR alert to the authenticated user session from Okta or Entra ID at the time of the event. This immediately answers 'who was logged in when this happened?' — a key question in every endpoint investigation.
Can ManySignal replace our current SOAR for EDR response actions?
Yes. ManySignal's workflow builder can execute EDR response actions (isolate, kill, quarantine) directly, replacing SOAR playbooks that exist only to relay these commands. For complex orchestration workflows that span multiple systems, ManySignal can serve as the decision layer while the SOAR handles execution.
Does ManySignal support EDR-as-code via Terraform?
EDR configuration management is generally handled by the EDR vendor's own management plane. ManySignal's Terraform provider manages ManySignal connector configuration, including EDR connector settings — enabling infrastructure-as-code deployment of the full ManySignal setup.
Connect your EDR to ManySignal
Correlate endpoint detections with identity and cloud telemetry in a single unified investigation timeline.