Integration Category
Threat Intelligence Integrations
VirusTotal, Recorded Future, MISP — ManySignal automatically enriches every alert with threat intelligence context, linking detections to known threat actors, campaigns, and IOC databases.
Threat intelligence integration FAQs
How does ManySignal use threat intelligence?
ManySignal uses threat intelligence for two purposes: (1) IOC enrichment — looking up IPs, domains, file hashes, and URLs against threat intel feeds to provide context for alerts. (2) Proactive hunting — scanning your environment for known indicators associated with active threat actors.
Does ManySignal have built-in threat intelligence?
Yes. ManySignal includes a curated built-in threat intelligence layer updated daily with IOCs from multiple commercial and open-source feeds. External threat intel integrations (VirusTotal, Recorded Future, MISP) supplement the built-in intelligence with additional context.
How does VirusTotal enrichment work in ManySignal?
When ManySignal detects a suspicious file hash, URL, or IP, it automatically queries the VirusTotal API for reputation data. The VirusTotal detection ratio and category labels appear as enrichment context in the alert evidence package.
What does Recorded Future add beyond VirusTotal?
Recorded Future provides risk scores calibrated to adversary context, industry-specific threat intelligence, and dark web intelligence that VirusTotal's community-based model doesn't cover. It also provides attribution to specific threat actor groups.
Can ManySignal ingest custom threat intel feeds?
Yes. ManySignal supports STIX/TAXII feeds, plain text IOC lists (CSV, JSON), and MISP event syncs for custom or private threat intelligence. Internal threat intelligence from your organisation's own research team can also be imported.
Does ManySignal integrate with MISP for ISACs and industry sharing?
Yes. ManySignal connects to MISP as both a consumer (ingesting shared IOCs from your MISP instance) and optionally as a publisher (sharing anonymised IOCs back to your MISP community). This enables ISAC participation from within ManySignal.
How are threat intel matches prioritised in ManySignal alerts?
Threat intel matches are weighted in ManySignal's evidence scoring model. A match against a high-confidence IOC from Recorded Future adds significantly more weight than a VirusTotal match with a low detection ratio. The combined evidence score determines alert severity.
Does ManySignal use threat intelligence for hunt campaigns?
Yes. ManySignal can run continuous hunt queries for new IOCs: when a new high-priority indicator is added to a feed, ManySignal retroactively searches your ingested telemetry for matches and alerts on any historical hits found.
What IOC types does ManySignal support for threat intel enrichment?
IP addresses, domain names, URLs, file hashes (MD5, SHA1, SHA256), email addresses, user agents, and YARA rules are all supported for threat intelligence enrichment and hunting.
How does threat intelligence integration affect alert false positive rates?
Threat intel context reduces false positives by distinguishing known-bad indicators from benign anomalies. An unusual connection to an IP with a Recorded Future Risk Score >90 is a True Positive with high confidence; the same connection to a low-risk IP may be deprioritised pending additional context.
Add threat intelligence context to every alert
Connect VirusTotal or Recorded Future to ManySignal and enrich your alerts with IOC context automatically.