Use Cases
Every alert has a story. Read the whole thing.
71 end-to-end detection and response workflows — from the first signal to the closed case. Each use case includes the attack scenario, detection logic, triage agent questions, and a response playbook.
Identity & Access
Impossible Travel
Two logins from cities 5,000 km apart within 12 minutes.
MFA Fatigue
Push flood until the user taps approve out of exhaustion.
Compromised Credentials
Valid credentials from a breach list working in production.
Session Token Theft
Attacker replays a stolen cookie from a different IP.
Privilege Escalation
Low-privilege user obtains admin rights via misconfigured policy.
Password Spraying
One password tried against thousands of accounts.
Brute Force
Automated credential guessing against login endpoints.
Credential Stuffing
Breach-list logins targeting your SSO.
MFA Bypass
Adversary-in-the-middle proxy intercepts OTP in transit.
Golden SAML
Forged SAML assertion grants persistent cloud access.
Identity Federation Tampering
Attacker modifies OIDC or SAML config to add a backdoor IdP.
OAuth App Abuse
Phishing page tricks user into granting a malicious app M365 access.
Cloud & Infrastructure
S3 Bucket Exposure
Public read or ACL misconfiguration exposes customer data.
Cloud Storage Exposure
GCS or Azure Blob container made public by misconfiguration.
Dangerous IAM Policy Changes
Star wildcard or passRole added to production IAM policy.
Risky Security Group Changes
0.0.0.0/0 added to inbound rules for database tier.
CloudTrail Tampering
Trail disabled or log file validation turned off.
Audit Logging Disabled
Cloud audit sink deleted or Unified Audit Log toggled off.
Cloud Persistence
Backdoor IAM user created after initial compromise.
Cryptomining
Unexpected GPU or high-CPU workload in production account.
Service Account Abuse
GCP or AWS service account used interactively outside automation.
Shared IAM Role Abuse
Cross-account role assumed from untrusted principal.
Endpoint & Malware
Ransomware Early Warning
VSS deletion + rapid file rename before encryption begins.
Endpoint Malware Alert Triage
EDR fires 400 alerts — which three are real threats?
EDR Alert Enrichment
Add identity, network, and cloud context to every EDR alert.
Lateral Movement
Pass-the-hash or WMI used to pivot across internal hosts.
Command & Control
HTTPS beacon to rotating domain infrastructure.
Data Exfiltration
Large compressed archive uploaded to consumer cloud storage.
Email & Phishing
Supply Chain & Code
Supply Chain Compromise
Malicious package injected into upstream open-source dependency.
GitHub Repository Compromise
PAT or deploy key used to push to protected branch.
CI/CD Pipeline Abuse
Attacker injects secrets-exfil step into GitHub Actions workflow.
Branch Protection Bypass
Admin bypasses required reviews to merge directly to main.
Dependency Confusion
Internal package name squatted on public registry.
Exposed Secrets in Code
AWS key committed to a public or private repository.
Leaked API Keys
Stripe or SendGrid key appears in a public GitHub search.
Insider Threat
AI & Emerging
Prompt Injection
Attacker plants hidden instructions in user-supplied input to an LLM.
AI Agent Abuse
Compromised agent uses tool calls to access unauthorized resources.
Rogue MCP Server
Malicious MCP server injected into agent runtime.
Shadow AI Discovery
Employee-connected AI tools not approved by security.
AI Identity Sprawl
Uncatalogued AI service accounts accumulating permissions.
LLM Data Leakage
Sensitive PII sent to an external model API.
Model Exfiltration
Fine-tuned model weights exfiltrated from training infrastructure.
SOC Operations
False Positive Reduction
Analyst burns 4 hours on alerts that resolve to nothing.
Alert Deduplication
Same event firing from SIEM, EDR, and CSPM simultaneously.
Shift Handover
Night-shift analyst misses context left by day-shift.
Threat Intel Enrichment
IOC matched — is it still active? What's the full campaign?
Vulnerability Prioritization
CVE-2024-XXXX: exploited in the wild or theoretical?
Detection Tuning
Rule fires 500 times a day; 499 are noise.
Use cases FAQ
How are use cases different from detection rules?
A detection rule is a single signal. A use case is an end-to-end workflow: detection, triage agent questions, evidence collection, and a response playbook. ManySignal ships both — the rule fires the alert, the use case defines what happens next.
Can I add custom use cases that aren't listed here?
Yes. The agent builder lets you define custom use case workflows with your own trigger conditions, question sets, and playbook steps. Existing use cases can be cloned and modified without writing code.
Do use cases work across different data sources?
Each use case lists its required telemetry. Most correlate across 3-5 sources — for example, impossible travel needs an IdP log and an IP geolocation enrichment. ManySignal's universal data connector normalizes these regardless of the originating vendor.
What's the MITRE ATT&CK coverage of these use cases?
The 71 use cases map to coverage across all 14 MITRE ATT&CK tactics (Initial Access through Impact). The platform's coverage mapping view shows your current detection breadth per tactic and flags gaps.
Can use cases trigger fully autonomous responses?
Select actions can be configured as autonomous — account suspension, session revocation, IP block — with analyst-approved guardrails. Approval-gated steps pause execution until a human approves in Slack or the case console.
See any use case in a live demo
Pick a scenario from the list. We'll run through detection, triage, and response in your actual environment.