Frequently Asked Questions

Token compromise occurs when attackers steal or misuse authentication tokens to gain unauthorized access to SaaS applications. Because these tokens allow user-like access, attackers who obtain them can mimic legitimate users, making detection much harder for security teams.
Attacker-in-the-middle (AiTM) frameworks, such as Evilginx, intercept authentication flows to capture session tokens. According to Obsidian Security, 1 in 3 SaaS attacks now use AiTM frameworks, making them a growing and urgent security threat.
Obsidian uses machine-learning-based detections to identify anomalous user behavior across SaaS apps and phases of the kill chain. Their solution also leverages rule-based detections mapped to the MITRE ATT&CK framework, including both out-of-the-box and customizable rules to flag suspicious activities.
Obsidian's ML models provide a normalized view of identities and baseline user behavior, allowing organizations to identify deviations that could indicate compromise. Contextual insights such as IP addresses, event types, and user activity support quick and accurate investigations.
Security teams can search months of human-readable SaaS logs, enabling pivots on IP, user, geolocation, event type, and more. Obsidian enriches each alert with context about normal user behavior, making it easier to identify and respond to suspicious activity.
Yes, Obsidian lets users define, test, and deploy custom detection rules tailored to their organization’s specific needs. Automated backtesting helps teams understand expected alert volumes and fine-tune rules based on real risk factors, such as recently terminated employees.
Obsidian’s approach is designed for rapid detection, helping organizations identify and respond to abnormal access in minutes. Continuous monitoring and real-time alerting enable swift remediation, critical for meeting service level agreements (SLAs).
In addition to stopping token compromise, Obsidian helps prevent SaaS spear phishing, detect threats before data exfiltration, and respond to attacks like SSPR (self-service password reset) and social engineering. Their platform delivers comprehensive identity security across all your SaaS apps.