M ManySignal

Integration Category

Vulnerability Management Integrations

Wiz, AWS Security Hub, Microsoft Defender for Cloud — ManySignal correlates vulnerability findings with runtime security events, so you know when theoretical risk becomes active exploitation.

Vulnerability management integration FAQs

How does ManySignal use vulnerability data?

Vulnerability findings from scanners (Wiz, Tenable, Qualys) provide asset risk context for ManySignal's triage decisions. When an alert targets a system with a critical unpatched CVE, ManySignal elevates the alert severity and flags the vulnerability context in the investigation.

Does ManySignal integrate with Wiz for cloud security posture?

Yes. ManySignal ingests Wiz issue findings via the Wiz API. Critical and High severity Wiz findings are correlated with runtime security events (CloudTrail, identity events) to distinguish exploited vulnerabilities from unpatched but unexploited ones.

What is the difference between vulnerability management and SOC operations?

Vulnerability management identifies and tracks vulnerabilities in an environment. SOC operations detect when those vulnerabilities are exploited. ManySignal bridges both: vulnerability context informs alert prioritisation, and runtime exploitation evidence confirms when a vulnerability is actively targeted.

Does ManySignal correlate CVEs with active exploitation?

Yes. When a CISA KEV CVE matches a system in your environment that subsequently shows suspicious activity, ManySignal flags the CVE as context in the alert. This prioritises response to exploitable vulnerabilities over theoretical risk.

Can ManySignal trigger vulnerability remediation workflows?

ManySignal can create Jira or ServiceNow tickets for critical vulnerability findings that correlate with active exploitation indicators. Direct vulnerability remediation (patching) requires integration with patch management tools (Automox, JAMF, etc.).

How does AWS Security Hub integration work?

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie, and third-party integrations into a single feed. ManySignal ingests Security Hub findings via the Security Hub API and correlates them with CloudTrail and identity events.

Does ManySignal support Tenable or Qualys?

Tenable and Qualys vulnerability findings can be ingested via their REST APIs. Contact ManySignal support for current connector availability. AWS Inspector findings are available via the AWS Security Hub integration.

How does Wiz Cloud Security Posture Management (CSPM) data help SOC teams?

Wiz CSPM identifies misconfigurations, exposed resources, and attack paths in your cloud environment. ManySignal uses this data to enrich runtime alerts with the attack path context — making it immediately clear whether an attacker could exploit the detected activity to reach sensitive data.

Does ManySignal alert on Wiz issues in real time?

ManySignal polls the Wiz API periodically for new Critical and High severity issues. Webhook-based real-time delivery is available for Wiz Enterprise customers. Critical cloud misconfigurations generate alerts in ManySignal within minutes of detection.

Can ManySignal suppress vulnerability alerts that have been accepted as risk?

Yes. Wiz risk acceptances and AWS Security Hub suppression rules are respected by ManySignal. Accepted risks are excluded from active alerting but remain visible in the investigation timeline for audit purposes.

Know when vulnerabilities are being exploited

Connect Wiz or AWS Security Hub to ManySignal and see vulnerability context in every security alert.