Cloud-Native SIEM
Built for cloud-first environments, not retrofitted
ManySignal ingests and normalizes CloudTrail, Azure Activity Log, and GCP Audit Log natively. Cloud posture scanning and active attack detection run in the same platform — with zero extra tooling required.
Cloud coverage map
Pre-built ingestion, normalization, and detection coverage across all three major cloud providers.
Amazon Web Services
Data Sources
- • CloudTrail (API activity)
- • VPC Flow Logs (network)
- • GuardDuty findings
- • Security Hub findings
- • S3 Access Logs
- • EKS audit logs
- • Config change events
Key Detections
- • IAM privilege escalation
- • S3 public access drift
- • EC2 instance compromise
- • Lambda exfiltration
- • Cross-account pivot
Microsoft Azure
Data Sources
- • Azure Activity Log
- • Entra ID sign-in logs
- • NSG Flow Logs
- • Microsoft Defender findings
- • Storage Analytics
- • AKS audit logs
- • Key Vault access logs
Key Detections
- • Entra ID account compromise
- • RBAC privilege escalation
- • Storage public access
- • AKS container escape
- • Logic App abuse
Google Cloud
Data Sources
- • Cloud Audit Logs
- • VPC Flow Logs
- • Security Command Center
- • Cloud Armor logs
- • GKE audit logs
- • Storage access logs
- • Identity Platform logs
Key Detections
- • IAM binding escalation
- • GCS public access
- • GKE workload compromise
- • Cloud Function abuse
- • Org policy bypass
Cloud-native SIEM capabilities
Three cloud providers, one query interface
Cross-cloud queries run against normalized CloudTrail, Activity Log, and GCP Audit Log in a single search.
Configuration posture every 15 minutes
CIS Benchmark checks run continuously against all cloud APIs. Drift appears as a case, not a weekly scan report.
Serverless and container coverage included
Lambda, Azure Functions, EKS, AKS, and GKE telemetry all pre-parsed and covered by built-in detections.
Flat asset-based pricing regardless of log volume
Cloud environments generate enormous log volumes. ManySignal pricing doesn't change as your CloudTrail volume grows.
CSPM and active detection in one tool
No separate CSPM subscription needed. Configuration posture and real-time attack detection share the same platform and case queue.
Cloud response actions: revoke, quarantine, remediate
Approved response actions include IAM key revocation, EC2 quarantine, and S3 public access removal — directly from the case.
Cloud-native SIEM — common questions
What does 'cloud-native SIEM' mean architecturally?
Cloud-native means the SIEM is built on cloud-managed services — object storage, managed streaming, serverless compute — rather than self-hosted software installed in a cloud VM. The benefit: elastic scaling with no infrastructure management, built-in regional redundancy, and no software patches to apply. ManySignal runs entirely on managed cloud services.
Does ManySignal handle CloudTrail, Activity Log, and GCP Audit Log normalization automatically?
Yes. Each cloud provider's audit log format is pre-parsed into ManySignal's normalized schema. CloudTrail API calls, Azure Activity Log events, and GCP Audit Log entries all land in a unified schema where cross-cloud queries run without per-provider translation.
How does ManySignal price for cloud-heavy environments with high log volume but fewer assets?
Pricing is per managed asset per year — compute instances, IAM principals, storage buckets, and managed services each count as an asset. Log volume does not affect pricing. A cloud-native environment with 10,000 assets and 5 TB/day of CloudTrail logs pays the same as one with 10,000 assets and 500 GB/day.
Can ManySignal detect misconfigured cloud resources in addition to active attacks?
Yes. The cloud posture scanner runs every 15 minutes against your cloud provider APIs, flagging configuration drift against CIS Benchmarks. Configuration findings appear in the same case queue as active attack detections. Both feed the triage agent and the response pipeline.
What cloud-native services does ManySignal cover beyond compute and IAM?
ManySignal covers: compute (EC2, Azure VMs, GCP Compute), containers (EKS, AKS, GKE), serverless (Lambda, Azure Functions, Cloud Run), storage (S3, Azure Blob, GCS), databases (RDS, Azure SQL, Cloud Spanner), IAM and identity, networking (VPC Flow Logs, NSG Flow Logs), and managed services (SQS, Azure Service Bus, Pub/Sub).
Connect your cloud environment in 15 minutes
Read-only IAM role in AWS, Azure, or GCP. We'll show you a full asset inventory, posture findings, and real-time detection results before the demo ends.