Windows 10 / 11
Standard endpoint agent
Integrations
Most small and mid-market businesses already run a handful of security and IT tools. Obsidian Ridge does not ask you to rip and replace — we connect to your existing stack, ingest the signals, and have the SOC review them. Below is a complete picture of what we plug into today.
Category
Where the Managed EDR agent runs. Light, signed, and deployable across mixed fleets.
Standard endpoint agent
Includes Domain Controllers
Apple Silicon and Intel
Server workloads
Agent push via Intune policies
Agent push for managed Macs
Agent push for Apple fleets
Agent push for Apple fleets
Category
Where Managed ITDR watches for the patterns that show up before account takeover.
Full identity threat detection
Full identity threat detection
Log forwarding and posture monitoring
Available in Complete tier scope
Category
Cloud workloads ingested into Managed SIEM for unified detection across your stack.
Sentinel logs, Defender for Cloud
CloudTrail, GuardDuty, S3 access logs
Cloud Audit Logs, SCC findings
WAF events, Zero Trust logs
Category
Firewall, DNS, and VPN telemetry feeding Managed SIEM correlation.
Syslog ingestion
Syslog and Cortex XDR
Syslog ingestion
Syslog and event API
DNS security telemetry
Activity logs
Category
We don't ask you to rip and replace. Existing security tools become signal sources for the SOC.
Coexists with our endpoint agent
Alert ingestion and correlation
Alert ingestion and correlation
Alert ingestion and correlation
Category
Audit-relevant SaaS log sources for compliance and threat detection.
Audit log forwarding
Audit log and security event ingestion
Audit log forwarding
Available in Complete tier scope
Activity log forwarding
FAQ
GA (generally available) means the integration is fully productized and works out of the box on the relevant tier. Supported means we can connect it during onboarding with light configuration work. Roadmap means we can scope it as a custom integration in the Complete tier — typically a one-time setup fee.
Probably yes. The Managed SIEM in the Complete tier accepts standard log formats (Syslog, JSON, Webhook, S3 bucket forwarding). If your tool has any kind of log export, we can usually wire it in. Tell us during the briefing.
We need read-only or scoped admin access to ingest logs and see alerts. For most tools, that means a service account with audit-log read permissions — not a global admin. We document exactly what's needed before deployment.
No. Most integrations are log-forwarding (one-way), not in-line traffic inspection. The endpoint agent itself is light — under 50 MB of memory, no kernel hooks, signed by Microsoft.
Don't see your tool?
The Managed SIEM in the Complete tier accepts standard log formats (Syslog, JSON, Webhook, S3 forwarding). If your tool can export logs, we can usually ingest them.