M ManySignal

Attack Surface: Data

Data attack surface

The data left your environment 10 minutes ago. ManySignal detected the staging behavior 40 minutes earlier — bulk access 18x above baseline, followed by compression, followed by upload to a personal Google Drive. The alert fired at staging.

Attack surface map

Data flows through too many systems to monitor manually

Cloud object storage

T1530

Mass download, public ACL exposure, cross-account access

Relational databases

T1213

Bulk query exfiltration, credential-based direct access

SaaS collaboration tools

T1213.002

External sharing, bulk export, data copied out of tenant

Endpoint file systems

T1025

Large file staging, USB transfer, cloud sync upload

Email and messaging

T1114

Forwarding rules, bulk attachment forwarding

AI and LLM APIs

T1567

Sensitive data in prompt payloads sent to external AI services

Top 5 detection rules

1
Mass download anomaly
User downloads data volume exceeding 3x their 90-day P95 baseline
2
Sensitive data external share
File classified as confidential/restricted shared with external email domain
3
Database bulk query
Query returns more than 10,000 rows from a PII-classified table by non-service identity
4
Cloud storage made public
S3/GCS bucket or Azure container ACL changed to allow public access
5
Pre-exfiltration staging pattern
Mass access + compression + staging directory creation within 60-minute window
Data security coverage
Monitored data paths
  • S3 / GCS / Azure Blob access logs
  • Snowflake, BigQuery, RDS query history
  • Microsoft 365 and Google Workspace audit
  • Endpoint DLP events (Purview, Nightfall)
  • Proxy logs for outbound data transfer
  • AI API call content analysis
Detection thresholds
  • Volume: per-user 90-day P95 baseline
  • Sensitivity: DLP classification weight
  • Identity: normal vs. anomalous accessor
  • Time: business hours vs. off-hours access
  • Destination: internal vs. external recipient
  • Sequence: staging pattern correlation

Related use cases

Data attack surface FAQ

How does ManySignal classify data for sensitivity in access monitoring?

ManySignal integrates with DLP tools (Microsoft Purview, Google Cloud DLP, Nightfall) and data catalogs (Collibra, Alation) to pull sensitivity classifications. Resources without classification labels are analyzed using pattern matching (PII patterns, financial data patterns) and content-based classification. Sensitivity tiers (public, internal, confidential, restricted) are used to weight access anomaly scores.

Can ManySignal detect data exfiltration before the data leaves the perimeter?

Yes. ManySignal monitors the staging behavior that precedes exfiltration: bulk data access significantly above baseline, compression of large datasets, unusual file format conversions, and data being moved to staging directories outside normal workflow patterns. These pre-exfiltration signals are typically detectable 10-60 minutes before data crosses the network perimeter.

How does ManySignal monitor cloud storage like S3, GCS, and Azure Blob?

ManySignal ingests CloudTrail (S3), GCP Audit Logs (GCS), and Azure Monitor (Blob) to monitor every object access, ACL change, bucket policy modification, and public access configuration change. Access patterns are baselined per bucket and per identity. GetObject, ListBucket, and PutBucketPolicy events by non-standard identities are flagged against the baseline.

Does ManySignal integrate with database activity monitoring?

Yes. ManySignal integrates with database activity monitoring solutions (Imperva, IBM Guardium) and cloud-native database audit logs (AWS RDS audit, Snowflake QUERY_HISTORY, BigQuery data access logs). Queries returning unexpectedly large result sets, queries executed by compromised credentials, and direct database access bypassing application tier are all monitored.

How does ManySignal detect ransomware operators staging data for exfiltration before encryption?

Data staging before ransomware encryption follows a detectable pattern: bulk recursive file system access, compression of large directory trees, unusual network upload volumes to cloud storage or external destinations. ManySignal's pre-exfiltration detection fires on these staging behaviors, enabling containment before the ransomware encryption payload executes. The typical staging-to-encryption window is 10–45 minutes — sufficient time for autonomous containment actions to interrupt the attack.

Can ManySignal generate data breach impact assessments for regulatory notification?

Yes. When an incident is classified as involving potential data exfiltration, ManySignal's Report agent generates a structured data impact assessment: what data types were accessed, which identities accessed them, what volume of data was involved, and the time window of access. This assessment forms the basis for Article 33 GDPR notifications, HIPAA breach reports, and SEC cybersecurity incident disclosures. The assessment is continuously updated as investigation reveals additional scope.

How does ManySignal monitor data access across hybrid environments — both on-premises file servers and cloud storage?

ManySignal ingests file access events from on-premises sources (Windows file server audit logs, NFS access logs, SharePoint on-premises audit) and cloud storage simultaneously. Both sets of access events are correlated in the entity graph against the same user identity and behavioral baseline. An anomaly that crosses environments — accessing an on-premises file server and then a cloud storage bucket in the same session — is detected as a compound finding even though the events come from separate systems.

What data residency guarantees apply to data processed by ManySignal for data attack surface monitoring?

ManySignal processes log events and access metadata — not the content of protected data files. Log events are stored in the configured data residency region (US, EU, or APAC) for the customer account. No document content, database record content, or personal data from monitored storage is transmitted to ManySignal infrastructure. The DPA is available for review and specifies exactly what data is processed and where.

Detect data exfiltration at staging, not at the perimeter

Pre-exfiltration pattern detection across cloud, database, SaaS, and endpoint — before the data leaves your environment.