Windows 10 / 11
Standard endpoint agent
Integrations
Most small and mid-market businesses already run a handful of security and IT tools. Obsidian Ridge does not ask you to rip and replace — we connect to your existing stack, ingest the signals, and have the SOC review them. Below is a complete picture of what we plug into today.
Category
Where the Managed EDR agent runs. Light, signed, and deployable across mixed fleets.
Standard endpoint agent
Includes Domain Controllers
Apple Silicon and Intel
Server workloads
Agent push via Intune policies
Agent push for managed Macs
Agent push for Apple fleets
Agent push for Apple fleets
Category
Where Managed ITDR watches for the patterns that show up before account takeover.
Full identity threat detection
Full identity threat detection
Log forwarding and posture monitoring
Category
Cloud workloads ingested into Managed SIEM for unified detection across your stack.
Sentinel logs, Defender for Cloud
CloudTrail, GuardDuty, S3 access logs
Cloud Audit Logs, SCC findings
WAF events, Zero Trust logs
Category
Firewall, DNS, and VPN telemetry feeding Managed SIEM correlation.
Syslog ingestion
Syslog and Cortex XDR
Syslog ingestion
Syslog and event API
DNS security telemetry
Activity logs
Category
We don't ask you to rip and replace. Existing security tools become signal sources for the SOC.
Deploy it to the endpoints first, or nothing flows. Then it coexists with our agent.
Alert ingestion and correlation
Alert ingestion and correlation
Alert ingestion and correlation
Category
Audit-relevant SaaS log sources for compliance and threat detection.
Audit log forwarding
Audit log and security event ingestion
Audit log forwarding
Activity log forwarding
FAQ
Available now means the integration is fully productized and works out of the box on the relevant tier. Configurable means we can connect it during onboarding with light configuration work — typically log forwarding or a scoped service account.
Probably yes. The Managed SIEM in the Complete tier accepts standard log formats (Syslog, JSON, Webhook, S3 bucket forwarding). If your tool has any kind of log export, we can usually wire it in. Tell us during the briefing.
We need read-only or scoped admin access to ingest logs and see alerts. For most tools, that means a service account with audit-log read permissions — not a global admin. We document exactly what's needed before deployment.
No. Most integrations are log-forwarding (one-way), not in-line traffic inspection. The endpoint agent itself is light — under 50 MB of memory, no kernel hooks, signed by Microsoft.
Don't see your tool?
The Managed SIEM in the Complete tier accepts standard log formats (Syslog, JSON, Webhook, S3 forwarding). If your tool can export logs, we can usually ingest them.