Abnormal Security
Abnormal Security detects the whole spectrum of email attacks, from vendor email compromise and spear-phishing to unwanted email spam and graymail. To stop these advanced attacks, Abnormal leverages the industry’s most advanced behavioral data science to baseline known good behavior and detects anomalies.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- AbnormalSecurity
Configuration parameters
- url — Server URL (e.g. https://api.abnormalplatform.com/v1) (required)
- api_key — API Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- max_fetch — Maximum incidents to fetch.
- fetch_threats — Fetch Threats
- fetch_abuse_campaigns — Fetch Abuse Campaigns
- fetch_account_takeover_cases — Fetch Account Takeover Cases
- first_fetch — First fetch time
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- polling_lag — Polling Lag Time (in minutes)
- max_page_number — Maximum incidents pages to fetch
Commands (31)
- abnormal-security-check-case-action-status — Check the status of an action requested on a case.
- abnormal-security-check-threat-action-status — Check the status of an action requested on a threat.
- abnormal-security-download-message-attachment — Download an attachment from a message found in search results. All required parameters can be obtained from the abnormal-security-search-messages command output.
- abnormal-security-download-message-eml — Download a message in RFC822 EML format for forensic analysis. For quarantine messages, both quarantine_identity and recipient_mailbox parameters are required.
- abnormal-security-download-threat-log-csv — Download data from Threat Log in .csv format.
- abnormal-security-get-abnormal-case — Get details of an Abnormal case.
- abnormal-security-get-abuse-mailbox-campaign — Get details of an Abuse Mailbox campaign.
- abnormal-security-get-activity-status — Get the status and details of a specific activity log entry.
- abnormal-security-get-case-analysis-and-timeline — Provides the analysis and timeline details of a case.
- abnormal-security-get-employee-identity-analysis — Get employee identity analysis (Genome) data.
- abnormal-security-get-employee-information — Get employee information.
- abnormal-security-get-employee-last-30-days-login-csv — Get employee login information for last 30 days in csv format.
- abnormal-security-get-latest-threat-intel-feed — Get the latest threat intel feed.
- abnormal-security-get-threat — Get details of a threat.
- abnormal-security-get-vendor-activity — Get the activity for a specific vendor.
- abnormal-security-get-vendor-case-details — Get the details of a vendor case.
- abnormal-security-get-vendor-details — Get the details of a specific vendor.
- abnormal-security-list-abnormal-cases — Get a list of Abnormal cases identified by Abnormal Security.
- abnormal-security-list-abuse-mailbox-campaigns — Get a list of campaigns submitted to Abuse Mailbox.
- abnormal-security-list-activities — Get a list of activity logs for message search and remediation operations.
- abnormal-security-list-threats — Get a list of threats.
- abnormal-security-list-unanalyzed-abuse-mailbox-campaigns — Get a list of unanalyzed abuse mailbox campaigns.
- abnormal-security-list-vendor-cases — Get a list of vendor cases.
- abnormal-security-list-vendors — Get a list of vendors.
- abnormal-security-manage-abnormal-case — Manage an Abnormal Case.
- abnormal-security-manage-threat — Manage a Threat identified by Abnormal Security.
- abnormal-security-remediate-messages — Remediate messages by performing actions like delete, move, or submit to Detection360.
- abnormal-security-search-messages — Search for messages using filters across abnormal or quarantine sources.
- abnormal-security-submit-false-negative-report — Submit a False Negative Report.
- abnormal-security-submit-false-positive-report — Submit a False Positive Report.
- abnormal-security-submit-inquiry-to-request-a-report-on-misjudgement — Submit an Inquiry to request a report on misjudgement by Abnormal Security.