Incident response consultant at a tech vendor with 10,001+ employees
Real User
Top 10
Jun 29, 2026
Obsidian Security's main use case is to support incident response investigations. Once my company takes on an investigation, we deploy Obsidian Security and first assess whether clients use Software as a Service applications and if those applications are supported by Obsidian Security. If they are, we use that solution and deploy it in the client's environment to perform an assessment. We primarily use it to assist with clients that use Microsoft 365 in their environment. One of the main focuses is when business email compromise investigations are ongoing, and we deploy Obsidian Security to supplement any form of logs that we have collected so that it can provide us with actionable insights, ongoing alerting, and recommendations on how to harden their environment. One of the most recent situations I can recall involves a business email compromise where a threat actor used a phishing campaign to compromise an email account or an M365 account and gain access to the client's environment. Once we deployed Obsidian Security in the environment, we quickly assessed the available log data and identified alerts such as impossible travel, suspicious users, and users with the highest anomalous activity. We gained great insights into how they compromised those user accounts and were able to pivot using that information. Finally, with almost every case where there is a business email compromise, if the client has M365 or a similar supported Software as a Service application, we use Obsidian Security's recommendations for hardening their environment. This way, we add value to our investigation and report to the client by helping them shore their defenses and ensure a more secured environment.
Insider Risk Management addresses threats originating from within an organization, providing solutions to detect, assess, and mitigate risks posed by insiders.Insider Risk Management solutions are essential for organizations seeking to safeguard sensitive data and maintain compliance. These solutions use advanced analytics and machine learning to identify potential threats. They offer capabilities like user behavior analytics, alerting systems, and data protection mechanisms. Companies can...
Obsidian Security's main use case is to support incident response investigations. Once my company takes on an investigation, we deploy Obsidian Security and first assess whether clients use Software as a Service applications and if those applications are supported by Obsidian Security. If they are, we use that solution and deploy it in the client's environment to perform an assessment. We primarily use it to assist with clients that use Microsoft 365 in their environment. One of the main focuses is when business email compromise investigations are ongoing, and we deploy Obsidian Security to supplement any form of logs that we have collected so that it can provide us with actionable insights, ongoing alerting, and recommendations on how to harden their environment. One of the most recent situations I can recall involves a business email compromise where a threat actor used a phishing campaign to compromise an email account or an M365 account and gain access to the client's environment. Once we deployed Obsidian Security in the environment, we quickly assessed the available log data and identified alerts such as impossible travel, suspicious users, and users with the highest anomalous activity. We gained great insights into how they compromised those user accounts and were able to pivot using that information. Finally, with almost every case where there is a business email compromise, if the client has M365 or a similar supported Software as a Service application, we use Obsidian Security's recommendations for hardening their environment. This way, we add value to our investigation and report to the client by helping them shore their defenses and ensure a more secured environment.