Abnormal
Abnormal markets a security platform that uses behavioral signals to detect threats across email and identity systems. Its scope includes phishing, fraud, social engineering, compromised accounts, and AI-related access. The product is aimed at enterprise security teams rather than individual inbox cleanup.
Examine email in its working context
Abnormal describes learning what normal activity looks like for people and their relationships. Email security covers phishing, fraud, and social engineering. The proposed value is context about a sender and activity, rather than evaluating message text alone.
The platform also presents an Identity Trust Graph covering people and non-human identities such as agents, service accounts, and cloud resources. That broader scope matters when access involves an application or credential rather than a person signing into an inbox. Treat detection and prevention claims as the vendor's descriptions; Franklin has not independently tested their effectiveness.
Connect the services that hold the signals
The company says it ingests thousands of behavioral signals through APIs. Its homepage lists integrations including Microsoft 365, Google Workspace, and enterprise identity and cloud services. Confirm the actual permissions and coverage for your environment before assuming every listed service provides the same protection.
Abnormal's company overview describes API deployment without MX changes. That avoids one particular email-routing change, but it does not remove access review or rollout planning. Ask which accounts, messages, and events the integration reads and which actions it may take.
Review the evidence behind responses
The publisher describes investigation and response alongside evidence explaining the action. Identity protection covers detecting compromise and addressing insider risk, while AI security concerns governance of AI-related activity.
A useful evaluation should include your team's normal workflows and exceptional cases. Check how analysts inspect alerts, reverse an incorrect action, and limit automated responses during deployment. Review audit records and data-handling terms with the people responsible for security administration. Promotional efficiency figures on a homepage do not establish performance on your organization's traffic, and Franklin has not reproduced the company's benchmark claims.
