M ManySignal

Product Tour

Case Management — Every Incident, Start to Finish

Step 5 of 8

app.manysignal.io/cases/cas_00142
Critical cas_00142 · Opened 14:28 UTC

Account Compromise: AWS root

4 findings · 3 response actions · Assignee: Alice Chen · MTTR: 18 min

Detect Agent 14:28 UTC

Finding fnd_01HX001 created: AWS Root Account Login (critical). Blast radius: 100.

Triage Agent 14:28 UTC

Triage complete: True positive (99% confidence). Login from UA/Kyiv; no MFA; no change ticket.

System 14:28 UTC

Case cas_00142 auto-created. Severity: Critical. Assignee: Alice Chen (on-call rotation).

Investigate Agent 14:29 UTC

Investigation started. Attack chain reconstructed: 4 events, 4 MITRE techniques, 14 GB exfiltration detected.

Respond Agent 14:30 UTC

Proposed action plan: suspend root Okta user, deactivate access key, request approval for IAM user delete.

Alice Chen 14:31 UTC

Analyst note: Confirmed account compromise. Approved IAM user deletion. Notified legal team per IR policy.

Respond Agent 14:32 UTC

IAM backdoor user deleted. All 3 response actions complete. Containment verified.

System 14:46 UTC

MTTR calculated: 18 min (detect to containment). IR report generated and attached to case.

1

Unified case timeline

Every agent action, analyst note, system event, and response action appears in a single chronological timeline. No stitching together separate systems to reconstruct what happened.

2

Auto-calculated MTTR

Mean time to respond is calculated automatically from case open to containment verified, giving you accurate IR metrics without manual tracking. Export to your reporting dashboard via API.

3

One-click compliance reports

Generate a formatted incident report from the case data — timeline, entities, response actions, MITRE mapping — suitable for security leadership, legal, or compliance auditors.