Abnormal Security
Abnormal Security (operating under the abnormal.ai brand) is an AI-native email and SaaS security platform that uses behavioral AI to model normal communication and identity behavior, then detect socially engineered email attacks, business email compromise, vendor email compromise, and account takeovers across Microsoft 365, Google Workspace, Slack, Zoom, and Microsoft Teams. The Behavior Platform is paired with AI Security Agents (AI Security Mailbox, AI Phishing Coach, AI Data Analyst) and exposes a gated REST API at api.abnormalplatform.com for SOC, SIEM, SOAR, and ticketing integrations. 4,500+ customers including 25% of the Fortune 500; named a 2024 Gartner Magic Quadrant Leader for Email Security Platforms.
Abnormal Security publishes 1 API on the APIs.io network. Tagged areas include Cybersecurity, Email Security, Account Takeover, Behavioral AI, and SaaS Security.
Abnormal Security’s developer surface includes developer portal, documentation, engineering blog, and 8 more developer resources.
APIs
Abnormal Security Platform API
The Abnormal Security Platform REST API at api.abnormalplatform.com gives customers and integration partners programmatic access to detected threats, attack cases, abuse mailbox...
Features
AI-native platform that models normal email and identity behavior to detect socially engineered attacks
Autonomous AI defense against phishing, BEC, vendor email compromise, and other inbound email attacks
Detection and mitigation of account takeovers across email and identity platforms
Detection of Microsoft 365 misconfigurations before attackers can exploit them
Personalized graymail filtering to reduce inbox noise without compromising security
Detect and prevent emails sent to the wrong recipient before data is exposed
AI agent that responds to user-reported emails and coaches users at superhuman speed
Hyper-personalized security training that reduces phishing susceptibility
Natural-language security reporting that produces board-ready insights
Account takeover protection for SaaS applications such as Slack and Zoom
Detection of malicious content inside Microsoft Teams
Use Cases
Stop business email compromise, phishing, and vendor email compromise on Microsoft 365 and Google Workspace
Detect and respond to compromised email and SaaS accounts in near-real time
Use AI Security Agents to triage user-reported emails and automate SOC workflows
Continuously identify and remediate Microsoft 365 misconfigurations
Use the AI Data Analyst to deliver board-ready security reporting through natural-language queries
Integrations
Native API-based integration with Microsoft 365 for email and identity protection
Native API-based integration with Google Workspace email and identity surfaces
Messaging security integration with Microsoft Teams
SaaS account takeover protection for Slack workspaces
SaaS account takeover protection for Zoom accounts
REST API forwarding of detected threats and cases into Splunk, Sentinel, Chronicle, and similar SIEMs
Bidirectional integrations with Cortex XSOAR, Splunk SOAR, Tines, and other SOAR platforms
Ticketing integrations with ServiceNow, Jira, and other ITSM tools