M ManySignal

Use Cases

Every alert has a story. Read the whole thing.

71 end-to-end detection and response workflows — from the first signal to the closed case. Each use case includes the attack scenario, detection logic, triage agent questions, and a response playbook.

Use cases FAQ

How are use cases different from detection rules?

A detection rule is a single signal. A use case is an end-to-end workflow: detection, triage agent questions, evidence collection, and a response playbook. ManySignal ships both — the rule fires the alert, the use case defines what happens next.

Can I add custom use cases that aren't listed here?

Yes. The agent builder lets you define custom use case workflows with your own trigger conditions, question sets, and playbook steps. Existing use cases can be cloned and modified without writing code.

Do use cases work across different data sources?

Each use case lists its required telemetry. Most correlate across 3-5 sources — for example, impossible travel needs an IdP log and an IP geolocation enrichment. ManySignal's universal data connector normalizes these regardless of the originating vendor.

What's the MITRE ATT&CK coverage of these use cases?

The 71 use cases map to coverage across all 14 MITRE ATT&CK tactics (Initial Access through Impact). The platform's coverage mapping view shows your current detection breadth per tactic and flags gaps.

Can use cases trigger fully autonomous responses?

Select actions can be configured as autonomous — account suspension, session revocation, IP block — with analyst-approved guardrails. Approval-gated steps pause execution until a human approves in Slack or the case console.

See any use case in a live demo

Pick a scenario from the list. We'll run through detection, triage, and response in your actual environment.