Identity Attack Surface Defense
Your identity layer is the perimeter. Defend it like one.
ManySignal builds a unified identity graph across Active Directory, Entra ID, Okta, and SaaS apps. Credential abuse, MFA bypass, token theft, and privilege escalation are detected in real time — with full entity context from day one.
Unified identity graph
Most organizations have the same human represented as multiple accounts across AD, Entra ID, Okta, and SaaS apps. ManySignal links these accounts into a single entity — so when a credential in one system behaves anomalously, context from all linked accounts informs the triage decision.
AD account
Entra ID
Okta
GitHub
johnsmith-dev
Salesforce
All five accounts linked as one entity in the ManySignal identity graph.
Detection coverage
Valid Account Abuse
Credential use from new device, location, or time pattern
MFA Fatigue (Push Flood)
High-volume MFA push requests in a short window
AiTM Proxy
Auth token capture via adversary-in-the-middle pattern
Kerberoasting
Service ticket requests for high-privileged accounts
Pass-the-Hash
NTLM authentication without corresponding password event
Token Theft
Bearer token reuse from unexpected IP or user agent
Privilege Escalation
Role or group assignment outside approved change window
Identity defense outcomes
Impossible travel detected in under 60 seconds
Authentication events from geographically impossible locations fire within the detection latency SLA.
MFA bypass coverage across 6 attack patterns
Push fatigue, OTP interception, SS7 bypass, AiTM proxy, recovery code abuse, and biometric bypass are all detected.
Service account baselines from day 7
Machine and service account behavioral baselines are ready within one week of connection.
Privilege escalation detected in real time
Any AD group membership change or IAM role assignment triggers immediate context review against the change management window.
Unified entity context across all IdPs
Correlated identity activity across AD, Entra, and Okta in a single entity timeline — not separate alerts per system.
Automated response: disable account, revoke tokens
Approval-gated containment actions execute across all identity systems from a single case.
Identity attack surface — common questions
Which identity providers does ManySignal support?
ManySignal connects natively to Microsoft Active Directory, Microsoft Entra ID (Azure AD), Okta, Ping Identity, JumpCloud, and Google Workspace. LDAP-based directories and SCIM-compatible providers are supported via generic connectors.
How does ManySignal detect MFA bypass attempts?
ManySignal looks for authentication patterns associated with MFA fatigue (push flood), OTP interception (rapid OTP retry), SS7-based bypass (auth from unexpected carrier origin), and adversary-in-the-middle proxy (auth source IP not matching device IP). Each pattern fires a dedicated detection rule with contextual evidence.
Can ManySignal detect impossible travel without location data from every source?
ManySignal infers location from IP geolocation when device GPS is unavailable. Impossible travel fires when two authentications occur for the same user from geographically distant IPs within a time window that makes physical travel impossible. The detection includes travel speed calculation in the evidence package.
How are privileged accounts monitored differently from standard users?
Privileged accounts — domain admins, cloud IAM admins, service accounts with elevated access — have tighter behavioral baselines and lower anomaly thresholds. Any privilege use outside business hours, from an unexpected device, or for a resource not accessed in the past 90 days fires a high-confidence triage case.
What's the difference between identity attack surface defense and standard UEBA?
Standard UEBA tracks behavioral anomalies per user in isolation. Identity attack surface defense adds: a unified identity graph linking all accounts for a single human (AD, Entra, Okta, SaaS), detection of specific identity attack techniques (credential stuffing, golden ticket, pass-the-hash), and coverage of service accounts and machine identities — not just human users.
How does ManySignal detect pass-the-hash and Kerberoasting attacks?
ManySignal monitors Windows Security Event logs for the specific event IDs associated with credential theft techniques: Event 4768/4769 for Kerberoasting (service ticket requests for high-value SPNs), NTLM authentication patterns associated with pass-the-hash (network logins without interactive session), and DCSync activity (DRSUAPI replication calls from non-domain-controller hosts). Each detection correlates the technical event with the identity context of the requesting account.
What happens when a privileged account is compromised and the attacker begins lateral movement?
ManySignal's Investigate agent traces the full lateral movement chain starting from the compromised credential: which hosts authenticated, which resources were accessed, which additional credentials were harvested. The blast-radius view shows every system reachable from the compromised account before containment. The Respond agent can suspend the identity across all connected directories simultaneously — Okta, Entra ID, and Active Directory — in a single approval action.
Can ManySignal detect federated identity attacks — attacks that cross trust boundaries between identity providers?
Yes. ManySignal monitors SAML assertion logs, OAuth token issuances, and federated authentication events. Golden SAML attacks (forged SAML assertions), token replay across federation boundaries, and audience-unrestricted tokens are all detected via specific detection rules. The entity graph links the federated identity event to the source IdP and destination application, providing full context for the attack path.
Does ManySignal help with identity hygiene — finding stale accounts, excessive permissions, and orphaned credentials?
Yes. The identity posture view surfaces: accounts inactive for more than 30/60/90 days, accounts with admin privileges not used in the past 90 days, service accounts with broad access but no recent activity, and API keys older than your configured rotation policy. These findings are not behavioral anomalies — they are identity hygiene risks surfaced via the entity graph. Remediation workflows can be triggered directly from the posture view.
Map your identity attack surface in 48 hours
Connect your IdP. We'll generate a full identity graph, entity risk scores, and coverage gaps in 48 hours — with zero impact on production systems.