Threat hunting workspace
Turn intelligence into testable hypotheses, run them to a verdict, and keep every finding and decision as evidence. Nothing lives in a spreadsheet or a private script.
Most security teams cannot prove which attacks they would stop. Obsera measures your real detection coverage, tests it against live adversary behaviour, and turns every blind spot into a tracked piece of work.
The platform
No spreadsheets, no scattered scripts. Hypothesis to evidence to detection, tracked in a single place.
Turn intelligence into testable hypotheses, run them to a verdict, and keep every finding and decision as evidence. Nothing lives in a spreadsheet or a private script.
See which techniques you can detect, which you cannot, and how you measure up against the specific groups that target your sector.
Tabletop exercises, adversary emulation and live simulation in one place, with red actions and blue outcomes on a single timeline.
A lightweight signed agent for Windows, Linux and macOS streams the process, network and identity signal your hunts depend on.
Grade every log source against the techniques it should reveal, and find the silent gaps before an attacker does.
Board ready reports in one click, and a maturity benchmark that shows leadership measurable progress quarter over quarter.
Starting points
A hunt never starts from a blank page. Pick the angle that fits what you know today.
Hunt based on a specific TTP, technique or tactic.
Hunt based on a simulation profile you have already run.
Hunt based on a threat hypothesis or behavioural pattern.
Hunt for the indicators and TTPs of a specific adversary.
Hunt using your own search logic against your own data.
Hunt from an intelligence report. Upload the files and Obsera turns them into a live hunt.
How it works
Obsera runs the same cycle continuously, so coverage improves every sprint instead of every audit.
Point Obsera at your SIEM and roll out the endpoint agent. Data stays in your environment.
Coverage is scored against ATT&CK using your real log sources and detection rules.
Run a tabletop or a live simulation and confirm what alerts, what only logs, and what passes silently.
Ship the missing detections, re-run the simulation, and watch the coverage number move.
Purple team
Obsera runs the whole purple team programme: discussion based tabletop exercises, technical adversary emulation, and continuous simulation against live endpoints. Every exercise ends with evidence, not opinions.
Test decisions and playbooks, or test detections. Both run from the same scenario library, mapped to MITRE ATT&CK.
The offensive action and the defensive response are recorded against the same clock, so debriefs argue about evidence rather than memory.
Every action is scoped, approved and reversible before it runs, with an automatic cleanup and integrity check after it. No destructive payloads, no surprises for the asset owner, a full audit trail either way.
Anything that logged silently or never appeared at all lands in the hunt backlog with the technique, host and log source already attached.
MITRE ATT&CK
Built on Enterprise ATT&CK v19, including the split of Defense Evasion into Stealth and Defense Impairment. Every technique is tagged by how it is defended today: a live hunt, a purple team simulation, both, or nothing yet.
Haseen Hunt
A national advisory, a vendor report, a bundle of rules from a partner. Upload the files exactly as you received them and Obsera turns them into a live hunt running across your endpoints and your SIEM at the same time. No analyst spends a day retyping indicators.
Bring the rules exactly as they arrived. Obsera checks each one before anything reaches a host, then sweeps disk and memory across the estate, from a single folder to every machine you own.
Indicators that arrive with no rule attached are hunted too, so nothing in the package goes to waste.
| Host | Path | Rule | Sev |
|---|---|---|---|
| WKS-4471 | C:\…\svc.tmp | Wiper_Generic_A | High |
| SRV-DB02 | D:\…\up.dat | Wiper_Generic_A | High |
| WKS-1180 | C:\…\cache9 | Wiper_Generic_B | Med |
The same intelligence is hunted in your SIEM and directly in endpoint event logs, in the dialect your platform already speaks. No rewriting, no second copy of your data.
Every hit lands on the ATT&CK matrix on its own, so a report becomes measurable coverage instead of a list of strings.
| Time | Host | ATT&CK | Sev |
|---|---|---|---|
| 02:14 | SRV-APP07 | T1546.003 | Med |
| 02:15 | SRV-APP07 | T1059.001 | High |
| 03:40 | WKS-2231 | T1546.003 | Med |
Reports, rule files and indicator lists together, in whatever shape they arrived. No pre sorting, no reformatting, no manual extraction.
Everything is sorted and verified first. Broken or unsafe content is flagged and held back before it ever reaches an endpoint.
Target by operating system, host group or a single machine, and get findings back with the evidence already attached.
Scan only during approved hours. If the window closes mid hunt it pauses and resumes the next night until every rule has run, with nobody watching the screen.
Cap what the scan may consume on each host before it starts. Business machines stay usable while the hunt runs across them.
Live malicious indicators are neutralised on screen by default, and every rule and indicator carries a traffic light protocol marking your team controls.
Rule matches, endpoint events and indicator hits export as one report, complete with the scope and settings that produced them.
Log visibility
A hunt is only as good as the data underneath it. Obsera checks continuously that every connected source is still reporting as it should, so a gap never goes unnoticed until an attacker uses it.
Obsera reads from the platform you already run, with no new collectors to deploy.
Firewall, network, endpoint, security tooling, web, cloud, identity and more.
Every source gets a baseline, so normal is a measured fact rather than an assumption.
Drops, parser breaks and missing fields surface the moment they appear, not at the next audit.
Integrations
Obsera queries your SIEM in place. No second data lake to fund, migrate to, or secure. Point it at what you already have and hunt in the dialect your team already writes.
Deployment
Run Obsera as a managed cloud tenant or install it entirely inside your own perimeter.
Most teams start here
A dedicated managed tenant. We handle upgrades, hardening and availability, you handle the hunting.
Regulated environments
The full platform inside your network for sovereignty, residency or classification requirements.
Compliance & assurance
Obsera helps regulated organisations in the Kingdom meet their obligations, mapping every hunt, simulation and piece of evidence to the controls your regulators and auditors expect.
Product
Every module in one place, from the dashboard to the ATT&CK matrix and the live hunt.
| Host | Source process | Count | Verdict |
|---|---|---|---|
| FIN-WS-0412 | rundll32.exe | 14 | Malicious |
| FIN-WS-0387 | powershell.exe | 9 | Suspicious |
| HR-WS-0142 | taskmgr.exe | 6 | Benign |
| DC-01 | svchost.exe | 4 | Benign |
| ENG-WS-0921 | unknown.exe | 2 | Triaging |
| ID | Technique | Outcome |
|---|---|---|
| T1059 | Command and scripting interpreter | Alerted |
| T1003 | OS credential dumping | Alerted |
| T1055 | Process injection | Logged only |
| T1071 | Application layer protocol | No telemetry |
| T1053 | Scheduled task persistence | Alerted |
| Host | Platform | Agent | Status |
|---|---|---|---|
| FIN-WS-0412 | Windows 11 | v3.4.1 | Streaming |
| DC-01 | Windows Server | v3.4.1 | Streaming |
| APP-LNX-07 | Ubuntu 22.04 | v3.4.1 | Streaming |
| BUILD-MAC-02 | macOS 14 | v3.3.9 | Update ready |
| ENG-WS-0921 | Windows 11 | v3.4.1 | Offline 2h |
Thirty minutes against your own environment. You leave with an honest read on your coverage, the blind spots that matter most, and what it takes to close them. If we are not a fit we will tell you in the session.
or email us at info@cyberbiz.sa