Behavioral AI that stops email attacks humans can't see

Abnormal AI (rebranded from Abnormal Security in April 2025) is a Las Vegas-based AI-native human behavior security platform founded in 2018 by former Twitter engineer Evan Reiser. Where traditional secure email gateways rely on known threat signatures and static rules, Abnormal builds a behavioral baseline for every employee and vendor by analyzing 45–60 days of email history — then flags deviations that pattern-match the subtle signals of business email compromise, account takeover, phishing, and supply chain attacks, rather than searching for malicious payloads. It deploys in minutes via native API integration with Microsoft 365 or Google Workspace (no MX record changes required), and claims to reduce SOC triage workload by 95% through autonomous remediation. Abnormal has been named a Gartner Magic Quadrant Leader for Email Security for two consecutive years (2024–2025), positioned furthest on the Vision axis, and achieved FedRAMP Moderate authorization in 2025.

Compliance

FedRAMP GDPR ISO 27001 SOC 2

Visit Abnormal AI

Key Features

  • Behavioral AI detection engine (Attune): Builds per-user and per-vendor behavioral models across 45–60 days of historical email, detecting anomalies — unusual sender-recipient pairs, off-hours wire transfer requests, newly registered look-alike domains — that rules-based tools structurally cannot flag.
  • AI Security Mailbox: Automates the triage and investigation of user-reported phishing emails, generating AI responses to reporters and removing true threats across all mailboxes without analyst intervention — replacing hours of per-email SOC work.
  • AI Phishing Coach: Provides real-time, personalized security awareness coaching to employees who interact with suspicious emails, triggered at the moment of risk rather than on a fixed training schedule.
  • Security Posture Management: Continuously monitors Microsoft 365 configurations, surfacing misconfigurations, excessive permissions, and risky settings before attackers exploit them — launched in 2025.
  • Calendar Invite Remediation: Detects and removes malicious Outlook calendar events associated with remediated phishing emails, closing an increasingly exploited bypass vector that traditional email filters do not cover.
  • API-native, zero-maintenance deployment: Connects via OAuth to Microsoft 365 (Graph API) or Google Workspace with no MX record changes, no rules to maintain, and no professional services required; behavioral models self-adapt to organizational changes.

Use Cases

  • For enterprises replacing legacy SEGs: A large organization removes its third-party secure email gateway and deploys Abnormal alongside native Microsoft Defender, covering payload-based and behavioral threats without MX disruption.
  • For SOC teams drowning in phishing reports: A security team routes user-reported phishing to Abnormal’s AI Security Mailbox, which automatically triages and remediates — eliminating a workflow that previously consumed hours of analyst time daily.
  • For regulated industries requiring FedRAMP: A U.S. federal agency or contractor deploys Abnormal under its FedRAMP Moderate authorization to protect government email infrastructure.

Pricing MODELS

Enterprise

Pricing Summary

Enterprise-only, custom-quoted pricing on a per-mailbox basis. No self-serve or published list pricing.

Company Size Fit

Enterprise Mid-market

Technical Snapshot

API Available

Yes

LLM Provider

Proprietary

Open Source

No

Deployment Options

Cloud Saas