Managed detection and response, in your tenant
24/7 analyst coverage. Verdicts in minutes. Full evidence in your environment, not a black box portal.
MDR without the black box
Head-to-head: traditional MDR provider vs ManySignal MDR.
| Capability | Traditional MDR | ManySignal MDR |
|---|---|---|
| Transparency of verdicts | Black box — you get a ticket, not reasoning | Full evidence chain, agent reasoning, and confidence score in your tenant |
| Data location | Ingested into provider's SIEM — your data leaves your environment | Your data stays in your tenant. Analysts access in-environment, not via VPN to theirs |
| Custom detection support | Ruleset owned by provider — change requests take weeks | Detection-as-code in your repo. MDR team co-authors detections with you |
| Containment actions | Phone call required to authorise response | In-tenant automation with your pre-approved playbooks — no phone tag |
| Monthly reporting depth | PDF with alert count and SLA adherence | Drill-down report: entity timelines, detection coverage map, MTTR trends |
| Exit costs | Data locked in provider SIEM. Export takes months and costs extra | Your data, your tenant. Leave any time. Detection library stays with you |
What your MDR shift looks like
Midnight P1, resolved in 3 minutes, morning brief on your desk.
Impossible travel flagged
ManySignal agent detects a login from Singapore 8 minutes after a confirmed session in London. Risk score: Critical. Agent enriches with entity history and drafts a containment recommendation.
MDR analyst reviews in your tenant
On-call analyst opens the case directly in your ManySignal tenant — not a separate portal. Raw logs, entity graph snapshot, similar historic events. No context switching.
Session terminated in 3 minutes
Analyst approves the pre-authorised containment playbook. Okta session revoked, Slack notification to your security lead, case escalated to P1. Alert to containment: 3 minutes.
Morning brief in your inbox
Overnight shift summary: 1 P1 resolved, 3 P2 analyst-reviewed false positives documented, 0 missed SLAs. Your team starts the day with full situational awareness.
Service level agreements
SLA credits applied automatically — no claim needed.
| Severity | Acknowledge | Contain | Resolve |
|---|---|---|---|
| P1 — Critical | 5 min | 15 min | 2 hours |
| P2 — High | 15 min | 1 hour | 8 hours |
| P3 — Medium | 1 hour | 4 hours | 24 hours |
| P4 — Low | 4 hours | 24 hours | 72 hours |
Onboarding timeline
From contract signature to 24/7 production coverage in four weeks.
Connectors & baseline
Connect primary telemetry — EDR, IdP, cloud logs, email. MDR team validates coverage against your MITRE ATT&CK priorities.
Baseline learning
Agents learn your entity landscape: normal working hours, typical cloud API patterns, expected data flows to seed detection thresholds.
Shadow run
MDR team monitors alongside your existing process. Every verdict recorded, no autonomous actions. You review daily and calibrate.
Production handover
Autonomy ladder configured per your approved playbooks. MDR team takes 24/7 primary responsibility. You govern; ManySignal executes.
Priced by monthly telemetry volume and entity count — no per-alert charges. Talk to sales for enterprise pricing.
Talk to sales"I was sceptical of MDR — every provider I tried was a black box. ManySignal MDR is the first service where I can see exactly what the analysts saw, why they made the call they made, and what was executed. That transparency is what convinced my board."
CISO — Series D Fintech, London
ManySignal MDR: frequently asked questions
- Do we lose visibility into what the MDR team is doing?
- Every action is recorded in your tenant's audit log with analyst identity, timestamp, and evidence reviewed. You see more than with a traditional MDR.
- Can we keep our own detections?
- Yes. Your detection library is yours. The MDR team operates on your rules, with detection-as-code co-authoring available so your engineers and our analysts collaborate in the same repo.
- What is the exit path if we want to bring the SOC in-house?
- Your data stays in your tenant. Your detection library, entity baselines, and case history come with you. Offboarding is removing MDR team access — no export project, no ransom pricing.
- How is MDR priced?
- Priced by monthly telemetry volume plus entity count — no per-alert charges. Enterprise volume discounts available. Talk to sales for a custom quote based on your environment.
- Are SLA credits automatic?
- Yes. If we miss a documented SLA for a confirmed incident, a credit is automatically applied to your next invoice. You do not need to file a claim.
- What detection coverage do MDR analysts use, and can we influence it?
- MDR analysts operate on ManySignal's 500+ shipped detection rules plus any custom rules your team has authored. Detection-as-code co-authoring is available: your detection engineers and ManySignal MDR analysts can collaborate in the same Git repository, propose new rules, and review each other's changes. Custom detection rules built during the MDR engagement are your intellectual property.
- How does the MDR team handle an active incident at 3 AM?
- When the triage agent escalates a P1 finding overnight, the on-duty MDR analyst reviews the pre-assembled evidence package and executes approved containment actions within the P1 SLA window — typically 15 minutes from initial escalation. You receive a Slack and PagerDuty notification simultaneously showing the analyst's actions in real time. For incidents requiring customer approval (higher-risk actions), the analyst pages your designated approver with a one-click approve/deny.
- What certifications does the MDR team hold?
- ManySignal MDR analysts hold industry-standard certifications including GCIH, GCIA, GCFE, and CISSP across the team. The team operates a documented incident response methodology aligned with NIST SP 800-61. Certification details and the MDR team's operational methodology are available for review under NDA as part of the vendor assessment process.
- How does ManySignal MDR compare to traditional MDR providers like Secureworks, Arctic Wolf, and Rapid7 MDR?
- Traditional MDR providers use proprietary tooling and deliver outcomes through a managed portal — you see summaries and recommendations, not the underlying investigation. ManySignal MDR operates inside your tenant: all investigation evidence, triage reasoning, and action records are in your environment, not a vendor-controlled portal. When you transition away from MDR or bring the SOC in-house, all evidence and detection logic travel with you. Traditional MDRs typically create data lock-in; ManySignal MDR is structured around data portability.
Explore ManySignal MDR
Book a session to see 24/7 analyst coverage, live verdict trails, and P1 containment in action — in your environment.