Attack Surface: Data
Data attack surface
The data left your environment 10 minutes ago. ManySignal detected the staging behavior 40 minutes earlier — bulk access 18x above baseline, followed by compression, followed by upload to a personal Google Drive. The alert fired at staging.
Data flows through too many systems to monitor manually
Cloud object storage
T1530Mass download, public ACL exposure, cross-account access
Relational databases
T1213Bulk query exfiltration, credential-based direct access
SaaS collaboration tools
T1213.002External sharing, bulk export, data copied out of tenant
Endpoint file systems
T1025Large file staging, USB transfer, cloud sync upload
Email and messaging
T1114Forwarding rules, bulk attachment forwarding
AI and LLM APIs
T1567Sensitive data in prompt payloads sent to external AI services
Top 5 detection rules
- S3 / GCS / Azure Blob access logs
- Snowflake, BigQuery, RDS query history
- Microsoft 365 and Google Workspace audit
- Endpoint DLP events (Purview, Nightfall)
- Proxy logs for outbound data transfer
- AI API call content analysis
- Volume: per-user 90-day P95 baseline
- Sensitivity: DLP classification weight
- Identity: normal vs. anomalous accessor
- Time: business hours vs. off-hours access
- Destination: internal vs. external recipient
- Sequence: staging pattern correlation
Related use cases
Data attack surface FAQ
How does ManySignal classify data for sensitivity in access monitoring?
ManySignal integrates with DLP tools (Microsoft Purview, Google Cloud DLP, Nightfall) and data catalogs (Collibra, Alation) to pull sensitivity classifications. Resources without classification labels are analyzed using pattern matching (PII patterns, financial data patterns) and content-based classification. Sensitivity tiers (public, internal, confidential, restricted) are used to weight access anomaly scores.
Can ManySignal detect data exfiltration before the data leaves the perimeter?
Yes. ManySignal monitors the staging behavior that precedes exfiltration: bulk data access significantly above baseline, compression of large datasets, unusual file format conversions, and data being moved to staging directories outside normal workflow patterns. These pre-exfiltration signals are typically detectable 10-60 minutes before data crosses the network perimeter.
How does ManySignal monitor cloud storage like S3, GCS, and Azure Blob?
ManySignal ingests CloudTrail (S3), GCP Audit Logs (GCS), and Azure Monitor (Blob) to monitor every object access, ACL change, bucket policy modification, and public access configuration change. Access patterns are baselined per bucket and per identity. GetObject, ListBucket, and PutBucketPolicy events by non-standard identities are flagged against the baseline.
Does ManySignal integrate with database activity monitoring?
Yes. ManySignal integrates with database activity monitoring solutions (Imperva, IBM Guardium) and cloud-native database audit logs (AWS RDS audit, Snowflake QUERY_HISTORY, BigQuery data access logs). Queries returning unexpectedly large result sets, queries executed by compromised credentials, and direct database access bypassing application tier are all monitored.
How does ManySignal detect ransomware operators staging data for exfiltration before encryption?
Data staging before ransomware encryption follows a detectable pattern: bulk recursive file system access, compression of large directory trees, unusual network upload volumes to cloud storage or external destinations. ManySignal's pre-exfiltration detection fires on these staging behaviors, enabling containment before the ransomware encryption payload executes. The typical staging-to-encryption window is 10–45 minutes — sufficient time for autonomous containment actions to interrupt the attack.
Can ManySignal generate data breach impact assessments for regulatory notification?
Yes. When an incident is classified as involving potential data exfiltration, ManySignal's Report agent generates a structured data impact assessment: what data types were accessed, which identities accessed them, what volume of data was involved, and the time window of access. This assessment forms the basis for Article 33 GDPR notifications, HIPAA breach reports, and SEC cybersecurity incident disclosures. The assessment is continuously updated as investigation reveals additional scope.
How does ManySignal monitor data access across hybrid environments — both on-premises file servers and cloud storage?
ManySignal ingests file access events from on-premises sources (Windows file server audit logs, NFS access logs, SharePoint on-premises audit) and cloud storage simultaneously. Both sets of access events are correlated in the entity graph against the same user identity and behavioral baseline. An anomaly that crosses environments — accessing an on-premises file server and then a cloud storage bucket in the same session — is detected as a compound finding even though the events come from separate systems.
What data residency guarantees apply to data processed by ManySignal for data attack surface monitoring?
ManySignal processes log events and access metadata — not the content of protected data files. Log events are stored in the configured data residency region (US, EU, or APAC) for the customer account. No document content, database record content, or personal data from monitored storage is transmitted to ManySignal infrastructure. The DPA is available for review and specifies exactly what data is processed and where.
Detect data exfiltration at staging, not at the perimeter
Pre-exfiltration pattern detection across cloud, database, SaaS, and endpoint — before the data leaves your environment.