By Role: Incident Responder
Scope an incident in 30 minutes, not 4 hours
An incident is declared. You need to know: what systems are affected, what data was accessed, how did they get in, and are they still in the environment. ManySignal assembles that picture from the entity graph while you're still reading the alert.
The three phases where responders lose time
Initial scoping (2-4 hours)
Pulling logs from SIEM, EDR, cloud, and IdP to understand who's affected and how far the attacker has moved. Every source requires a separate query, different syntax, different schema.
Containment execution (1-2 hours)
Isolating systems, suspending accounts, blocking IPs across multiple tools with different APIs and different approval chains. Each action is a manual process with rollback risk.
Evidence compilation (3-6 hours)
Assembling the post-incident evidence package for legal, compliance, and insurance: timeline reconstruction, affected data inventory, containment chronology, and chain of custody.
Incident timeline: ransomware scenario
"A ransomware incident that would have taken 3 days to scope and contain took 4 hours with ManySignal. The evidence package we handed to legal was better than anything we'd produced manually — fully chronological, all hashes, complete chain of custody."
Incident responder FAQ
How does ManySignal accelerate the initial triage phase of incident response?
When an incident is declared, ManySignal immediately begins graph traversal from the initial indicator: tracing authentication chains, lateral movement paths, data access events, and persistence mechanisms across all ingested log sources. Within 30 minutes of declaration, the responder has a preliminary scope map showing affected systems, affected accounts, and the attack's progression. This replaces the first 2-4 hours of manual data collection.
Can ManySignal execute containment actions automatically during incident response?
Yes, within configured approval thresholds. ManySignal can autonomously isolate endpoints (via EDR), suspend identity accounts (via Okta, Entra ID), revoke API tokens, and block IP addresses at the firewall and cloud security group level. Higher-risk actions (production database isolation, bulk account suspension) require on-call approval via Slack or PagerDuty one-click approve. All containment actions are logged with timestamps to the case record.
How does ManySignal maintain the chain of custody needed for post-incident legal review?
ManySignal generates a signed evidence package for every investigation: SHA-256 hashes of all source log evidence, a chronological action log showing every query run and every action taken and by whom, analyst notes with timestamps, and a chain-of-custody certificate. The export format is accepted by eDiscovery platforms and can be presented to legal teams and regulators as incident documentation.
Does ManySignal integrate with incident response platforms like TheHive or XSOAR?
Yes. ManySignal integrates with TheHive, Palo Alto XSOAR, and Splunk SOAR. Evidence packages, timelines, and IOC lists can be automatically pushed to open incidents in these platforms. Bidirectional sync ensures that analyst notes added in the IR platform appear in the ManySignal case, and vice versa. Responders can work in their preferred interface without losing context.
How does ManySignal help responders determine if an attacker is still in the environment?
The 'live attacker' dashboard shows all entities with an open high-confidence finding, active sessions flagged as anomalous, and recent lateral movement indicators. The real-time view updates as new telemetry arrives — responders can see whether the attacker is active, quiet, or eradicated without manually querying logs.
Can ManySignal help responders prioritise containment actions when resources are limited?
Yes. Each affected entity has a blast-radius score showing how many additional resources are reachable from it. Responders prioritise containment of high-blast-radius entities first — typically the credential or pivot point the attacker is using for lateral movement. The attack chain view shows which containment action would cut the most paths.
How does ManySignal handle evidence preservation during active incident response?
ManySignal automatically places all events related to an open case on legal hold — preventing retention policy deletion until the case is closed and the hold is released. Forensic timeline exports can be triggered at any point during the investigation. In parallel, the investigation agent flags new matching events as they arrive, keeping the evidence set current.
What is the typical time to eradication with ManySignal vs. without it?
In environments without automated triage and response, median time to eradication (full containment and eviction) ranges from 12–48 hours for a credential-based attack. ManySignal customers report median eradication times of 2–6 hours — primarily because scope determination is complete within the first hour and containment actions can begin while investigation continues.
How does ManySignal support post-incident reporting and lessons learned?
The case close report generates a structured incident report: timeline, attack chain, affected entities, containment actions, eradication steps, and root cause analysis. The lessons-learned section is analyst-authored within the case, preserved with the evidence package. The report is formatted for C-suite briefings, regulator submissions, and internal security review boards.
Compress 4 hours of incident scoping into 30 minutes
Entity graph traversal, one-click containment, and auto-generated evidence packages — built for responders who measure response in minutes.