Integration Category
Email Security Integrations
Microsoft Defender for Office 365, Proofpoint, Mimecast, Exchange Online — ManySignal correlates email gateway events, mailbox audit logs, and identity events to detect phishing, BEC, and email forwarding rule abuse.
Email security integrations
Microsoft 365 / Exchange Online
Mail flow, mailbox audit, phishing submissions, message trace
Google Workspace Gmail
Gmail security events, phishing reports, mail routing changes
Microsoft Defender for Office 365
Email threat protection events, Safe Links clicks, quarantine actions
Proofpoint
Email security gateway events, TRAP actions, threat intelligence
Mimecast
Gateway events, threat intelligence, security awareness events
Email security integration FAQs
Why is email monitoring critical for SOC operations?
Email is the primary initial access vector in most breaches. Phishing, BEC, and malicious attachment delivery all start with email. Monitoring email security events — not just at the gateway but also post-delivery actions, forwarding rule changes, and user report events — provides critical early warning of active attacks.
Does ManySignal detect email forwarding rules?
Yes. Email forwarding rule creation to external domains is one of ManySignal's highest-priority detections. It appears in Microsoft 365 Unified Audit Log and Google Workspace Admin Audit as a specific event type that ManySignal monitors continuously.
What is the difference between monitoring the gateway (Proofpoint) vs. the mailbox (M365)?
Gateway monitoring (Proofpoint, Mimecast) provides signals about emails before delivery: blocked phishing, malware attachments, spam scoring. Mailbox monitoring (M365, Google Workspace) provides signals about what happens after delivery: user clicks, forwarding rules, admin actions. ManySignal correlates both for complete email threat visibility.
Can ManySignal detect AiTM phishing attacks?
Yes. AiTM phishing is detected via identity correlation: the user authenticates (including MFA) from one IP through the phishing proxy, then the attacker's session cookie is used immediately from a different IP. ManySignal connects the email gateway alert (phishing email delivered) to the subsequent authentication anomaly.
Does ManySignal ingest user-reported phishing?
Yes. Microsoft Defender for Office 365 and Proofpoint both emit events when users report emails as phishing. ManySignal ingests these and correlates them with other signals — was the reported email from a known threat actor domain? Did the user click before reporting?
How does ManySignal handle business email compromise (BEC) detection?
BEC is detected via a correlation chain: compromised account authentication anomaly + mailbox rule creation + financial-keyword email activity. ManySignal's entity graph connects these signals across identity, email, and cloud events into a single BEC investigation.
Does ManySignal support Mimecast threat intelligence ingestion?
Mimecast's threat intelligence data (URL reputation, attachment verdicts, sender reputation) is ingested alongside gateway event logs. ManySignal uses this intelligence to enrich alerts from other data sources.
Can ManySignal detect when an email account is sending spam (compromised account)?
Yes. Anomalous outbound email volume from a corporate account, emails sent from unusual locations or devices, and email to domains the user has never contacted are detected as potential account compromise indicators.
What email compliance data does ManySignal capture?
Email audit events relevant to SOC 2, HIPAA, and GDPR compliance requirements — including data exports, external sharing, and message recall events — are captured and available in ManySignal's compliance reporting dashboard.
Does ManySignal correlate email threats with endpoint activity?
Yes. If a user clicks a phishing link (detected in Microsoft Safe Links or Zscaler web proxy) and then their endpoint shows suspicious process activity (detected in CrowdStrike), ManySignal connects both events in the investigation timeline under the user entity.
Detect email-based attacks before they succeed
Connect your email security platform to ManySignal for correlated phishing and BEC detection.