Integration Category
Network & Edge Integrations
Cloudflare, Zscaler, Palo Alto, Check Point, Fortinet, Netskope — ManySignal correlates network telemetry with identity and endpoint data to detect C2 beaconing, exfiltration, and lateral movement.
Network and edge security integrations
Cloudflare
WAF events, Firewall Rules, Access, DNS, Gateway
Zscaler
ZIA web access logs, ZPA private access, DNS, DLP events
Palo Alto Cortex XDR
Network alerts, NGFW syslog, Prisma Access events
Check Point
NGFW logs, IPS events, threat prevention alerts
Fortinet
FortiGate firewall logs, FortiAnalyzer events, VPN logs
Netskope
CASB events, DLP alerts, web proxy logs, private access
Network integration FAQs
What network threats does ManySignal detect?
Key network threats: command and control beaconing, data exfiltration over web protocols, lateral movement between segments, VPN credential abuse, DNS tunnelling, and AiTM proxy traffic. ManySignal correlates network events with identity and endpoint data for full attack chain visibility.
Does ManySignal support SSL inspection data?
Yes. When SSL inspection is performed by the network proxy (Zscaler, Netskope, Palo Alto Prisma Access), ManySignal ingests the decrypted URL and content classification metadata for richer network threat detection.
How does ManySignal integrate with Zscaler?
ManySignal connects to Zscaler ZIA via the Nanolog Streaming Service (NSS) or Cloud NSS for real-time web access log streaming. ZPA private access logs are ingested via the ZPA API. Both are configured in the ManySignal Zscaler connector.
Does ManySignal support firewall syslog ingestion?
Yes. Palo Alto, Check Point, and Fortinet firewall syslog is ingested via ManySignal's syslog receiver endpoint or via the log agent deployed on the syslog aggregator. CEF and LEEF formats are both supported.
Can ManySignal detect C2 beaconing in network traffic?
Yes. ManySignal's network anomaly models detect regular, low-volume HTTPS connections with consistent time intervals (beaconing) and long-duration connections to uncommon destinations. JA3/JA3S fingerprinting is applied for known-bad C2 signatures.
How does Cloudflare integration work?
ManySignal ingests Cloudflare Logpush events (WAF, Firewall, Access, DNS) via the Cloudflare Logpush job to an S3 bucket or direct HTTPS endpoint. Cloudflare Access authentication events are correlated with identity events for zero-trust access monitoring.
Does ManySignal detect DNS tunnelling?
Yes. DNS logs from Cloudflare, Zscaler, or Palo Alto are analysed for high-entropy subdomain patterns, anomalous query volumes, and unusually long query strings — all indicators of DNS tunnelling C2 channels.
How does ManySignal handle VPN authentication events?
VPN authentication events from Cisco ASA, Fortinet, Palo Alto GlobalProtect, and Zscaler are ingested and correlated with the user's identity provider authentication events. Failed VPN attempts followed by success from a new location is a credential abuse indicator.
Does ManySignal correlate network data with endpoint and identity events?
Yes. ManySignal's entity graph links network session data (source IP, device ID) to the authenticated user (from IdP) and the device (from EDR). A lateral movement event in the network appears alongside the credential event that enabled it and the process event on the target.
What is Netskope CASB and how does ManySignal use its events?
Netskope's CASB (Cloud Access Security Broker) monitors cloud application usage and applies DLP policies. ManySignal ingests Netskope CASB events (DLP violations, unsanctioned app access, risky activities) and correlates them with identity and endpoint events for insider threat detection.
Correlate network telemetry with identity and endpoint
Connect your network security platform to ManySignal for complete attack chain visibility.