Integration Category
Cloud & IaaS Integrations
Connect ManySignal to your AWS, Azure, GCP, and edge infrastructure. CloudTrail, Entra ID, VPC Flow Logs, GuardDuty, Security Command Center — all correlated in a unified cloud threat detection timeline.
Supported integrations
Cloud platforms and services
Amazon Web Services
CloudTrail, GuardDuty, Security Hub, VPC Flow Logs, Config
Microsoft Azure
Activity Logs, Entra ID, Defender for Cloud, Azure Policy
Google Cloud Platform
Cloud Audit Logs, Security Command Center, VPC Flow Logs
Cloudflare
WAF events, Firewall rules, DNS logs, Access logs
AWS CloudTrail
Management events, data events, Insights anomalies
AWS GuardDuty
Threat findings, malware protection results, runtime monitoring
AWS Security Hub
Consolidated security findings across AWS services and partners
AWS VPC Flow Logs
Network traffic records for VPC interfaces and subnets
AWS Config
Resource configuration history, compliance evaluation results
Azure Activity Logs
Subscription-level management operations across all Azure services
Microsoft Defender for Cloud
Security alerts, vulnerability assessments, posture recommendations
Google SecOps
Chronicle/Google SecOps detections and UDM events
Data collected across cloud integrations
- Cloud management API calls and control-plane operations
- Network flow logs for VPC and virtual network traffic
- Security service findings (GuardDuty, Security Command Center, Defender)
- Resource configuration change events
- Identity and access management events (IAM roles, policies)
- Compliance evaluation results and posture findings
Automated response actions
- Isolate EC2 instance, Azure VM, or GCP Compute instance via API
- Revoke IAM credentials or disable service accounts on verdict
- Add restrictive security group / firewall rule on suspicious IP
- Create ServiceNow, Jira, or PagerDuty incident automatically
- Trigger AWS Lambda or Azure Function for custom remediation
- Apply restrictive SCP to an AWS account under investigation
Setup considerations
What to know before you connect
IAM permissions
Cloud integrations require read-only IAM roles/service principals. ManySignal provides Terraform and CloudFormation templates to create the minimum necessary permissions without manual configuration.
Log delivery latency
Most cloud audit logs have a 5–15 minute delivery delay to S3 or Log Analytics. For near-real-time detection, use EventBridge (AWS) or Event Hub (Azure) for sub-minute event delivery.
Multi-account / multi-subscription
AWS Organisations and Azure Management Groups allow a single ManySignal integration to monitor all accounts and subscriptions. No per-account credentials needed.
Data residency
ManySignal's data residency options let you store cloud telemetry in your chosen geographic region. Contact your account team if data must remain in specific jurisdictions.
Cloud integration FAQs
What cloud providers does ManySignal support?
ManySignal has native connectors for Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) with equal coverage depth across all three. Each cloud provider connector ingests security service findings, audit logs, network flow data, and identity events.
How does ManySignal connect to AWS?
ManySignal connects via a cross-account IAM role with read-only permissions on CloudTrail, GuardDuty, Security Hub, Config, and VPC Flow Logs. A single role covers all AWS accounts in your organisation via the AWS Organisations integration.
What cloud events does ManySignal prioritise for detection?
High-priority events include: privilege escalation (IAM policy attachment, new admin role assumption), data exfiltration indicators (bulk S3 access, snapshot copying), persistence (new IAM users, API keys), and defence evasion (CloudTrail disabling, GuardDuty suppression).
Does ManySignal support multi-account AWS organisations?
Yes. Configure ManySignal once with an organisation-level role and it automatically monitors all accounts, including new accounts added to the organisation. A single pane of glass shows activity across the entire AWS footprint.
Can ManySignal take automated response actions in cloud environments?
Yes. ManySignal can isolate EC2 instances (security group modification), revoke IAM credentials, disable service accounts, and apply restrictive SCPs to AWS accounts — all triggered automatically on high-confidence verdicts or via analyst approval workflow.
How does ManySignal correlate cloud events with identity and endpoint data?
ManySignal's entity graph correlates cloud IAM principals with their associated human identities (from Okta, Entra ID) and endpoint devices (from CrowdStrike, SentinelOne). A single investigation view shows the full attack chain across cloud, identity, and endpoint.
What is the latency between a cloud event and a ManySignal alert?
AWS CloudTrail events are ingested within 5–15 minutes of occurrence (CloudTrail delivery latency). GuardDuty findings and Security Hub alerts appear within 2–5 minutes. Near-real-time events from EventBridge can be configured for sub-minute delivery.
Does ManySignal support multi-cloud environments with AWS, Azure, and GCP simultaneously?
Yes. ManySignal is designed for multi-cloud environments. Detections span all three cloud providers and are correlated at the identity and entity level — for example, detecting when a compromised Okta credential is used across both AWS and GCP.
What cloud compliance frameworks does ManySignal map to?
ManySignal maps detections to CIS Benchmarks for AWS/Azure/GCP, NIST CSF, SOC 2 CC controls, PCI DSS cloud requirements, and ISO 27001 cloud annexes. Compliance coverage reports are generated automatically.
How does ManySignal handle cloud Terraform or IaC-driven infrastructure changes?
ManySignal correlates Terraform Cloud and CI/CD pipeline events with downstream cloud API calls. IaC-driven changes are distinguished from direct API calls, enabling detection of out-of-band changes that bypass the approved IaC workflow.
Connect your cloud environment to ManySignal
Deploy the cloud connectors in minutes and see your first cloud threat detections within an hour.