M ManySignal

Guide · ManySignal

The Incident Response Handbook

Incident response fails not from lack of process but from process that breaks under pressure. This handbook provides a field-tested IR framework built around ManySignal's case timeline, agentic response actions, and evidence trail — covering detection through containment, eradication, recovery, and post-incident review.

SA Sofia Andersson — Principal Security Researcher, ManySignal
MH Marcus Hale — Head of Detection Engineering
18 min read Published Jul 15, 2026 Download PDF
01

IR phases and the ManySignal case lifecycle

Every IR framework follows the same skeleton: Preparation, Detection, Analysis, Containment, Eradication, Recovery, Post-Incident. The ManySignal case lifecycle maps directly: a finding triggers a case, triage produces analysis, approved response actions execute containment and eradication, and the closed case timeline becomes the post-incident artefact.

The advantage of an agentic IR model is speed. Containment that previously required a human to log in to four systems, verify permissions, and click through confirmation dialogs now executes in seconds via the respond agent — with the same audit trail, the same approval gate, and the same rollback capability.

02

Detection and initial analysis

Effective IR begins with a high-confidence detection that carries enough context to start analysis immediately. ManySignal findings include: the triggering event, the entity graph snapshot at detection time, the behavioural score, the ATT&CK technique, and the pre-computed triage question answers. The analyst opening the case does not start from raw logs.

Initial analysis should answer four questions in under 10 minutes: What happened? Which entities are involved? Is activity ongoing? What is the initial blast radius? The entity graph answers questions two and four; the case timeline answers one and three.

Scope creep is the most common analysis failure. Set a scope boundary early — the specific identity, device, or application under investigation — and expand it deliberately rather than following every tangential indicator.

03

Containment: actions, approval gates, rollback

Containment options in ManySignal: isolate host (EDR quarantine), revoke session (Okta/Entra ID), disable account (IdP), block IP (firewall/WAF), rotate credentials (secrets manager), restrict role (IAM policy update). Each action has a configured autonomy rung and blast-radius limit.

Every containment action is reversible. Rollback is a first-class operation on the case timeline — one click reverses the action and logs the reversal with actor and timestamp. This matters when containment turns out to be a false positive: the analyst can undo in the same interface without touching the underlying system directly.

For high-severity incidents (ransomware, credential compromise at scale), use the tenant-level kill switch to halt all agentic actions mid-flight while humans assess scope. The kill switch is not a panic button — it is a deliberate tool that should be practiced in tabletops so the team knows exactly what it does and doesn't do.

04

Evidence collection and chain of custody

The ManySignal case timeline is an append-only, hash-chained evidence log. Every action, every verdict, every human comment, every agent output lands on the timeline with a timestamp and actor identity. The timeline is the chain of custody — it does not need to be reconstructed after the fact.

For forensic preservation beyond the platform, export the case timeline as a signed JSON package. The package includes the raw event log, the entity graph snapshot, all action records, and the cryptographic hashes that prove the record was not modified post-incident.

05

Post-incident review

Post-incident review has one purpose: make the next incident faster and cheaper to handle. Use the ManySignal case timeline to run a structured timeline replay — walk every action and decision in order and identify the earliest point where a different detection, question set, or response action would have reduced impact.

Output from every PIR should be at least one detection improvement (new rule, updated question set, or threshold change), one playbook update, and one tabletop scenario derived from the actual TTP used in the incident.

The report agent can generate a draft PIR from the case timeline automatically. The draft includes timeline, entities involved, ATT&CK mapping, actions taken, and metrics (time to detect, contain, eradicate). Human review adds the improvement recommendations.

Key takeaways

  • ManySignal case lifecycle maps directly to Preparation → Detection → Analysis → Containment → Eradication → Recovery → PIR.
  • Findings include entity graph snapshot and pre-computed triage answers — analysts don't start from raw logs.
  • Every containment action is reversible via one-click rollback on the case timeline.
  • Contain identity before host before artefacts — eradicating before containing enables re-deployment.
  • The case timeline is the chain of custody — append-only, hash-chained, exportable as signed JSON.
  • Every PIR should produce one detection improvement, one playbook update, and one tabletop scenario.

Further reading

Frequently asked questions

What is The Incident Response Handbook in an agentic SOC?

The Incident Response Handbook is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle the incident response handbook?

ManySignal grounds the incident response handbook in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for the incident response handbook?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.