Threat hunting platform

Know exactly what
you would catch.

Most security teams cannot prove which attacks they would stop. Obsera measures your real detection coverage, tests it against live adversary behaviour, and turns every blind spot into a tracked piece of work.

697Techniques and sub-techniques tracked
1,736Ready to run attack tests
15ATT&CK v19 tactics mapped end to end
9Console modules, one platform
16SIEM connectors

The platform

Everything a hunting team needs, in one console

No spreadsheets, no scattered scripts. Hypothesis to evidence to detection, tracked in a single place.

Threat hunting workspace

Turn intelligence into testable hypotheses, run them to a verdict, and keep every finding and decision as evidence. Nothing lives in a spreadsheet or a private script.

ATT&CK coverage and adversary focus

See which techniques you can detect, which you cannot, and how you measure up against the specific groups that target your sector.

Purple team operations

Tabletop exercises, adversary emulation and live simulation in one place, with red actions and blue outcomes on a single timeline.

Endpoint telemetry

A lightweight signed agent for Windows, Linux and macOS streams the process, network and identity signal your hunts depend on.

Log visibility scoring

Grade every log source against the techniques it should reveal, and find the silent gaps before an attacker does.

Reporting and maturity

Board ready reports in one click, and a maturity benchmark that shows leadership measurable progress quarter over quarter.

Starting points

Six ways to start a hunt

A hunt never starts from a blank page. Pick the angle that fits what you know today.

01MITRE ATT&CK

Hunt based on a specific TTP, technique or tactic.

02Simulation profile

Hunt based on a simulation profile you have already run.

03Hypothesis

Hunt based on a threat hypothesis or behavioural pattern.

04APT group

Hunt for the indicators and TTPs of a specific adversary.

05Custom query

Hunt using your own search logic against your own data.

06Haseen Hunt

Hunt from an intelligence report. Upload the files and Obsera turns them into a live hunt.

How it works

A closed loop, not a one off assessment

Obsera runs the same cycle continuously, so coverage improves every sprint instead of every audit.

01

Connect

Point Obsera at your SIEM and roll out the endpoint agent. Data stays in your environment.

02

Measure

Coverage is scored against ATT&CK using your real log sources and detection rules.

03

Validate

Run a tabletop or a live simulation and confirm what alerts, what only logs, and what passes silently.

04

Close the gap

Ship the missing detections, re-run the simulation, and watch the coverage number move.

Purple team

Red actions and blue outcomes, on one timeline

Obsera runs the whole purple team programme: discussion based tabletop exercises, technical adversary emulation, and continuous simulation against live endpoints. Every exercise ends with evidence, not opinions.

Four ways to exercise the SOC

Test decisions and playbooks, or test detections. Both run from the same scenario library, mapped to MITRE ATT&CK.

TTX
Tabletop exercises Scenario driven, discussion based sessions for SOC, IR and leadership. Inject by inject, with decisions, response times and playbook gaps captured as you go.
EMU
Adversary emulation Replay the full technique chain of a named APT group against a scoped set of hosts, in the order that group actually operates.
SIM
Attack simulation A built in library of 1,736 ready to run attack tests across 327 techniques, executed safely on live endpoints by the agent.
BAS
Continuous validation Schedule simulations to re run weekly so detection drift, broken parsers and silent log outages surface within days, not at the next audit.
Purple team run: credential-access playbook Scope: 42 hosts, Finance OU
RUNNING
  • T1059
    Command and scripting interpreter
    Alerted
  • T1003
    OS credential dumping
    Alerted
  • T1055
    Process injection
    Logged only
  • T1071
    Application layer protocol
    No telemetry
  • T1053
    Scheduled task persistence
    Alerted
3 alerted, 1 logged only, 1 blind spot Detection gaps exported to the hunt backlog

Red and blue in the same room

The offensive action and the defensive response are recorded against the same clock, so debriefs argue about evidence rather than memory.

Safe on production

Every action is scoped, approved and reversible before it runs, with an automatic cleanup and integrity check after it. No destructive payloads, no surprises for the asset owner, a full audit trail either way.

Gaps become work items

Anything that logged silently or never appeared at all lands in the hunt backlog with the technique, host and log source already attached.

MITRE ATT&CK

One matrix. Two ways you covered it.

Built on Enterprise ATT&CK v19, including the split of Defense Evasion into Stealth and Defense Impairment. Every technique is tagged by how it is defended today: a live hunt, a purple team simulation, both, or nothing yet.

76%covered
Initial Access3/4
Execution3/4
Persistence3/4
Priv. Escalation2/4
Stealth2/3
Def. Impairment0/2
Credential Access3/3
Discovery3/4
Lateral Movement2/3
Command & Control2/3
Hunt + Simulation Hunt profile only Simulation only No coverage, in backlog

Haseen Hunt

Drop in the intelligence. Hunt the whole estate.

A national advisory, a vendor report, a bundle of rules from a partner. Upload the files exactly as you received them and Obsera turns them into a live hunt running across your endpoints and your SIEM at the same time. No analyst spends a day retyping indicators.

File and memory huntingThe rules you were given, run everywhere
Validated

Bring the rules exactly as they arrived. Obsera checks each one before anything reaches a host, then sweeps disk and memory across the estate, from a single folder to every machine you own.

Indicators that arrive with no rule attached are hunted too, so nothing in the package goes to waste.

Scanning the estateAll uploaded rules, every host in scope
Running
Hosts1,240
Files8.4M
Matches3
Elapsed04:12
HostPathRuleSev
WKS-4471C:\…\svc.tmpWiper_Generic_AHigh
SRV-DB02D:\…\up.datWiper_Generic_AHigh
WKS-1180C:\…\cache9Wiper_Generic_BMed
Matches come back with the host, the path and the severity already attached.
PDFDOCXHTML JSONCSVTXT YARASigmaIOC lists
1
Upload anything

Reports, rule files and indicator lists together, in whatever shape they arrived. No pre sorting, no reformatting, no manual extraction.

2
Checked before it runs

Everything is sorted and verified first. Broken or unsafe content is flagged and held back before it ever reaches an endpoint.

3
Hunted across the estate

Target by operating system, host group or a single machine, and get findings back with the evidence already attached.

Hunting window

Scan only during approved hours. If the window closes mid hunt it pauses and resumes the next night until every rule has run, with nobody watching the screen.

Resource limits

Cap what the scan may consume on each host before it starts. Business machines stay usable while the hunt runs across them.

Safe indicator handling

Live malicious indicators are neutralised on screen by default, and every rule and indicator carries a traffic light protocol marking your team controls.

Evidence on the way out

Rule matches, endpoint events and indicator hits export as one report, complete with the scope and settings that produced them.

Log visibility

Validate the baseline of every log source

A hunt is only as good as the data underneath it. Obsera checks continuously that every connected source is still reporting as it should, so a gap never goes unnoticed until an attacker uses it.

Obsera
Firewall
Email
Identity
Cloud
Security solutions
Web / WAF
MDM / EDR
Network solutions
1Point at your SIEM

Obsera reads from the platform you already run, with no new collectors to deploy.

2Discover every source

Firewall, network, endpoint, security tooling, web, cloud, identity and more.

3Establish what healthy looks like

Every source gets a baseline, so normal is a measured fact rather than an assumption.

4Validate continuously

Drops, parser breaks and missing fields surface the moment they appear, not at the next audit.

Integrations

Works with the stack you already run

Obsera queries your SIEM in place. No second data lake to fund, migrate to, or secure. Point it at what you already have and hunt in the dialect your team already writes.

  • Query in placeRuns against your existing indexes and retention.
  • Encrypted end to endAll traffic between the platform and your endpoints is encrypted.
  • Cross platformOne agent for Windows, Linux and macOS.
  • Role based accessAnalysts, leads and auditors each see their scope.

Detection content & frameworks

mapped to ATT&CK
AT
MITRE ATT&CKEnterprise v19
SG
Sigmarules
YR
YARAfile / memory

Deployment

Your data, your rules

Run Obsera as a managed cloud tenant or install it entirely inside your own perimeter.

Regulated environments

On premise

The full platform inside your network for sovereignty, residency or classification requirements.

  • Runs entirely within your perimeter
  • Signed releases with rollback safe updates
  • Hardware bound licensing and audit logging
  • Air gap friendly operating model
Talk to us

Compliance & assurance

Aligned with Saudi national regulation

Obsera helps regulated organisations in the Kingdom meet their obligations, mapping every hunt, simulation and piece of evidence to the controls your regulators and auditors expect.

NCA
National Cybersecurity Authority الهيئة الوطنية للأمن السيبراني
SAMA
Saudi Central Bank البنك المركزي السعودي
Data residency in-Kingdom On-premise & air-gapped deployment Full audit logging Role-based access & TLP handling

Product

See it in the console

Every module in one place, from the dashboard to the ATT&CK matrix and the live hunt.

Obsera Console: Dashboard

DashboardProgramme health, last 30 days

All sources connected
ATT&CK coverage68%+6
Open hunts12
Findings37
Endpoints1,480
Hunts closed per week+18%
Latest findings
  • Credential access on a finance host
  • Anomalous process lineage
  • Suspicious outbound channel
  • Unexpected service created on 3 hosts
  • Kerberos ticket request anomaly

Threat HuntingCredential access hunt, 1,480 endpoints in scope

Connected SIEM
HostSource processCountVerdict
FIN-WS-0412rundll32.exe14Malicious
FIN-WS-0387powershell.exe9Suspicious
HR-WS-0142taskmgr.exe6Benign
DC-01svchost.exe4Benign
ENG-WS-0921unknown.exe2Triaging

MITRE ATT&CKEnterprise v19, coverage by technique

68% covered
Initial Access
Phishing
Valid Accounts
Ext. Remote Svc
Drive-by
Supply Chain
Execution
PowerShell
WMI
Scheduled Task
Native API
Service Exec
Persistence
Registry Run
Services
Startup Folder
Boot Script
Create Account
Priv. Esc
Token Manip.
UAC Bypass
Process Inject
DLL Search
Exploit for PE
Stealth
Obfuscation
Masquerading
Indicator Rm.
Rootkit
BITS Jobs
Command & Ctrl
App Layer Proto
Web Service
Encrypted Chan.
DNS Tunnel
Proxy
Detection in place Partial or log only No coverage

Attack SimulationPurple team run: credential-access playbook, 42 hosts

Running
Techniques run18
Detected11
Blind spots4
IDTechniqueOutcome
T1059Command and scripting interpreterAlerted
T1003OS credential dumpingAlerted
T1055Process injectionLogged only
T1071Application layer protocolNo telemetry
T1053Scheduled task persistenceAlerted

Endpoints1,480 agents enrolled over an encrypted channel

98.4% healthy
Windows1,102
Linux318
macOS60
HostPlatformAgentStatus
FIN-WS-0412Windows 11v3.4.1Streaming
DC-01Windows Serverv3.4.1Streaming
APP-LNX-07Ubuntu 22.04v3.4.1Streaming
BUILD-MAC-02macOS 14v3.3.9Update ready
ENG-WS-0921Windows 11v3.4.1Offline 2h

Maturity & Log VisibilityHMM level 3, sources graded against ATT&CK

Q3 review
Log source visibilityScore
Process creation94%
Authentication88%
Network flow61%
DNS54%
Cloud control plane27%
Hunting maturity
  • HMM 0 Initial
  • HMM 1 Minimal
  • HMM 2 Procedural
  • HMM 3 Innovative
  • HMM 4 Leading
Product screens: Dashboard

Find out what you would actually catch

Thirty minutes against your own environment. You leave with an honest read on your coverage, the blind spots that matter most, and what it takes to close them. If we are not a fit we will tell you in the session.

Coverage baseline against ATT&CK Your highest risk blind spots A realistic path to close them

or email us at info@cyberbiz.sa