Loading

Abnormal Security

Version 1.8.1 (View all)
Compatible Kibana version(s) 8.17.0 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

Abnormal Security is a behavioral AI-based email security platform that learns the behavior of every identity in a cloud email environment and analyzes the risk of every event to block even the most sophisticated attacks.

The Abnormal Security integration collects data for AI Security Mailbox (formerly known as Abuse Mailbox), Audit, Case, and Threat logs using REST API.

The Abnormal Security integration collects six types of logs:

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions.

  • Retrieve your authentication token. This token will be used further in the Elastic integration setup to authenticate and access different Abnormal Security Logs.
  • Abnormal Security requires you to restrict API access based on source IP. So in order for the integration to work, user needs to update the IP allowlisting to include the external source IP of the endpoint running the integration via Elastic Agent.
  1. In Kibana navigate to Management > Integrations.
  2. In "Search for integrations" top bar, search for Abnormal Security.
  3. Select the "Abnormal Security" integration from the search results.
  4. Select "Add Abnormal Security" to add the integration.
  5. Add all the required integration configuration parameters, including Access Token, Interval, Initial Interval and Page Size to enable data collection.
  6. Select "Save and continue" to save the integration.
Note

By default, the URL is set to https://api.abnormalplatform.com. We have observed that Abnormal Security Base URL changes based on location so find your own base URL.

Introduced in version 1.8.0, the Abnormal Security integration includes a new option called Enable Attachments and Links enrichment for the Threat data stream. When enabled, this feature enriches incoming threat events with additional details about any attachments and links included in the original message.

This is the ai_security_mailbox dataset.

This is the ai_security_mailbox_not_analyzed dataset.

This is the audit dataset.

This is the case dataset.

This is the vendor_case dataset.

This is the threat dataset.