Skip to content

Abnormal Inbound Email Security

You can integrate Abnormal Email Security with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Abnormal Email Security product overview

Abnormal Inbound Email Security is a behavioral-AI cloud email security product. It models the normal behavior of every employee and vendor to detect advanced inbound email threats, such as business email compromise (BEC), vendor email compromise (VEC), phishing, and impersonation, that rule-based defenses miss, and it integrates with Microsoft 365 and Google Workspace through an API.

What we ingest

Sophos XDR collects Abnormal Inbound Email Security data by calling the Abnormal API on a schedule, using an API access token you generate in Abnormal. The following log categories are collected:

  • Threats: Malicious email messages Abnormal detects and remediates.
  • Abuse campaigns: End-user-reported email campaigns from Abnormal's abuse mailbox (requires the Abnormal AI Security Mailbox subscription).

Event and data types

We ingest the following event and data types from Abnormal Email Security:

  • Threats: Malicious email messages Abnormal detects, including sender and recipient, subject, attack type, and remediation status. Normalized to email telemetry.
  • Abuse campaigns: End-user-reported email campaigns surfaced through Abnormal's abuse mailbox. Normalized to email telemetry.

Data provided by this integration

Data provided by Abnormal Email Security gets normalized to the following schemas:

  • email

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation