M ManySignal

Use Case: Endpoint

EDR alert enrichment

Your CrowdStrike alert has a process name and a hash. ManySignal adds: the user who ran it, their travel status, the device's MDM compliance state, the network connection history, and 4 related alerts from last week.

The enrichment problem

Why every EDR alert requires 6 consoles

A raw EDR alert contains endpoint telemetry: process name, hash, parent process, command line, maybe a network connection. To investigate properly, an analyst needs to know: Who is the user? Are they in a high-risk group? Is this device managed? Is the IP a known bad actor? Has this user had similar alerts before? Are there related events across the environment? Finding those answers requires opening Okta, Intune or Jamf, VirusTotal, the SIEM, and the CMDB separately — and then copying data between them manually.

ManySignal's enrichment pipeline pulls all of that context automatically when the alert arrives. By the time the analyst sees the alert, the investigation is 80% done.

Okta / Entra ID

User identity, role, recent logins, MFA status

Intune / Jamf

Device compliance, MDM enrollment, patch level

VirusTotal / MalwareBazaar

Process hash and domain reputation

Recorded Future

Threat actor attribution, campaign context

CMDB / Asset inventory

Asset criticality, owner, business function

SIEM history

Related alerts for same user/device — 30 days

MITRE ATT&CK coverage

T1059 — Command and Scripting InterpreterT1204 — User ExecutionT1071 — Application Layer Protocol

EDR enrichment FAQ

What context does ManySignal add to each EDR alert?

ManySignal automatically appends: the user's identity across all linked accounts (AD, Entra, Okta, SaaS), the device's compliance status and MDM enrollment, the geolocation and ASN of any network connections, threat intelligence matches for IOCs in the alert, similar alerts from the past 30 days involving the same user or device, and any open ITSM tickets that might explain the activity.

Does enrichment happen before or after the alert appears in the queue?

Enrichment runs automatically when the alert arrives in ManySignal's pipeline — before it appears in the analyst queue. Analysts always see enriched alerts. There's no raw alert phase requiring manual pivot.

Can ManySignal enrich alerts from multiple EDRs in a mixed environment?

Yes. Organizations running CrowdStrike on servers and Microsoft Defender on workstations, for example, receive a unified enriched alert stream. The entity graph links the device identity across both EDR platforms, so a user's activity on both their workstation and a server appears in the same investigation context.

Does enrichment increase alert noise?

No. Enrichment adds context to existing alerts — it doesn't generate new ones. In practice, enrichment often reduces effective noise by providing context that allows analysts to close false positives faster. Alerts that would have taken 30 minutes of manual research to dismiss are dismissed in 30 seconds when the context is pre-populated.

Give every EDR alert its full investigation context

Zero-pivot investigations. Every enrichment source connected, every context available before you open the alert.