M ManySignal

Product Tour

Investigation — Full Attack Chain in Minutes

Step 3 of 8

app.manysignal.io/cases/cas_00142/timeline

Case cas_00142 — Account Compromise: root

Investigation complete · Attack chain reconstructed · 4 MITRE ATT&CK techniques mapped

Escalated

Reconnaissance: AWS describe-instances called from unfamiliar IP

T1580 14:12 UTC

203.0.113.5 called DescribeInstances, DescribeSecurityGroups across 4 regions

Initial Access: AWS Console login as root, no MFA, new geolocation

T1078.004 14:28 UTC

Login from UA/Kyiv; IP reputation -85; no prior logins from this country

Persistence: New IAM admin user created ([email protected])

T1136.003 14:33 UTC

CreateUser + AttachUserPolicy (AdministratorAccess) in 43 seconds

Exfiltration: 14 GB GetObject from S3 bucket acme-pii-backup-prod

T1530 14:35 UTC

14,211 objects accessed over 8 minutes from newly created access key

1

Automatic attack chain reconstruction

The Investigate Agent correlates events across all connected sources to reconstruct the complete attack sequence — from initial access through persistence and exfiltration — without manual pivoting.

2

MITRE ATT&CK auto-mapping

Each observed TTP is automatically mapped to the MITRE ATT&CK technique, with the relevant events as supporting evidence. Export as a MITRE Navigator layer.

3

Full evidence audit trail

Every data point the agent accessed is logged — which entity it queried, which events it retrieved, which TI lookups it ran — creating a defensible, reproducible investigation record.