M ManySignal

By Role: Incident Responder

Scope an incident in 30 minutes, not 4 hours

An incident is declared. You need to know: what systems are affected, what data was accessed, how did they get in, and are they still in the environment. ManySignal assembles that picture from the entity graph while you're still reading the alert.

The three phases where responders lose time

Initial scoping (2-4 hours)

Pulling logs from SIEM, EDR, cloud, and IdP to understand who's affected and how far the attacker has moved. Every source requires a separate query, different syntax, different schema.

ManySignal: entity graph traversal delivers scope in 30 minutes

Containment execution (1-2 hours)

Isolating systems, suspending accounts, blocking IPs across multiple tools with different APIs and different approval chains. Each action is a manual process with rollback risk.

ManySignal: one-click containment with approval workflow and full audit log

Evidence compilation (3-6 hours)

Assembling the post-incident evidence package for legal, compliance, and insurance: timeline reconstruction, affected data inventory, containment chronology, and chain of custody.

ManySignal: signed evidence export generated automatically from the case record

Incident timeline: ransomware scenario

T+0:00Incident declared. ManySignal begins entity graph traversal from initial IOC (compromised user account).
T+0:12Graph traversal complete: 3 compromised accounts, 7 affected hosts, 2 data exfiltration events identified.
T+0:18Responder reviews scope map, approves account suspension for all 3 compromised identities.
T+0:22ManySignal suspends accounts via Okta, isolates 2 hosts via CrowdStrike, blocks 4 C2 IPs at WAF.
T+0:31Forensic timeline assembled: initial access via phishing T-7d, full 7-day attack chain documented.
T+1:15Evidence package generated: signed, hashed, chain-of-custody ready for legal and insurer.
"A ransomware incident that would have taken 3 days to scope and contain took 4 hours with ManySignal. The evidence package we handed to legal was better than anything we'd produced manually — fully chronological, all hashes, complete chain of custody."
Incident Response Lead, retail company, 3,000 employees

Incident responder FAQ

How does ManySignal accelerate the initial triage phase of incident response?

When an incident is declared, ManySignal immediately begins graph traversal from the initial indicator: tracing authentication chains, lateral movement paths, data access events, and persistence mechanisms across all ingested log sources. Within 30 minutes of declaration, the responder has a preliminary scope map showing affected systems, affected accounts, and the attack's progression. This replaces the first 2-4 hours of manual data collection.

Can ManySignal execute containment actions automatically during incident response?

Yes, within configured approval thresholds. ManySignal can autonomously isolate endpoints (via EDR), suspend identity accounts (via Okta, Entra ID), revoke API tokens, and block IP addresses at the firewall and cloud security group level. Higher-risk actions (production database isolation, bulk account suspension) require on-call approval via Slack or PagerDuty one-click approve. All containment actions are logged with timestamps to the case record.

How does ManySignal maintain the chain of custody needed for post-incident legal review?

ManySignal generates a signed evidence package for every investigation: SHA-256 hashes of all source log evidence, a chronological action log showing every query run and every action taken and by whom, analyst notes with timestamps, and a chain-of-custody certificate. The export format is accepted by eDiscovery platforms and can be presented to legal teams and regulators as incident documentation.

Does ManySignal integrate with incident response platforms like TheHive or XSOAR?

Yes. ManySignal integrates with TheHive, Palo Alto XSOAR, and Splunk SOAR. Evidence packages, timelines, and IOC lists can be automatically pushed to open incidents in these platforms. Bidirectional sync ensures that analyst notes added in the IR platform appear in the ManySignal case, and vice versa. Responders can work in their preferred interface without losing context.

How does ManySignal help responders determine if an attacker is still in the environment?

The 'live attacker' dashboard shows all entities with an open high-confidence finding, active sessions flagged as anomalous, and recent lateral movement indicators. The real-time view updates as new telemetry arrives — responders can see whether the attacker is active, quiet, or eradicated without manually querying logs.

Can ManySignal help responders prioritise containment actions when resources are limited?

Yes. Each affected entity has a blast-radius score showing how many additional resources are reachable from it. Responders prioritise containment of high-blast-radius entities first — typically the credential or pivot point the attacker is using for lateral movement. The attack chain view shows which containment action would cut the most paths.

How does ManySignal handle evidence preservation during active incident response?

ManySignal automatically places all events related to an open case on legal hold — preventing retention policy deletion until the case is closed and the hold is released. Forensic timeline exports can be triggered at any point during the investigation. In parallel, the investigation agent flags new matching events as they arrive, keeping the evidence set current.

What is the typical time to eradication with ManySignal vs. without it?

In environments without automated triage and response, median time to eradication (full containment and eviction) ranges from 12–48 hours for a credential-based attack. ManySignal customers report median eradication times of 2–6 hours — primarily because scope determination is complete within the first hour and containment actions can begin while investigation continues.

How does ManySignal support post-incident reporting and lessons learned?

The case close report generates a structured incident report: timeline, attack chain, affected entities, containment actions, eradication steps, and root cause analysis. The lessons-learned section is analyst-authored within the case, preserved with the evidence package. The report is formatted for C-suite briefings, regulator submissions, and internal security review boards.

Compress 4 hours of incident scoping into 30 minutes

Entity graph traversal, one-click containment, and auto-generated evidence packages — built for responders who measure response in minutes.