Previously, we looked at the inside of the Account Takeover engine, which gave us insight into how it detects sophisticated identity attacks. The Anomaly Log lets users see what Abnormal Account Takeover is tracking and weighing. It's a live view into the events that the detection engine tracks across every identity in your environment, whether or not it ever becomes an account takeover case.
Continuous Triage of Events and Signals
Behind every account takeover case are thousands of signals and events: a sign-in from a new VPN, an unfamiliar device, a mail filter that looks slightly unusual, or a password reset that happened a little outside the norm. None of these prove a compromise on their own, and most of the time, the activity ends up being completely legitimate.
But each one still matters, because it's evidence of an ongoing evaluation. The Anomaly Log surfaces that evaluation directly, giving you visibility into the raw material behind every event the engine sees, including those that quietly resolve to "this is fine." You don't have to wait for a confirmed case to see what the engine is doing.
Three Layers of Checks Before Landing on Your Desk
Anomaly detection at Abnormal moves through three stages, and only the third one surfaces something for SOC teams to act on:
Baseline check. A single event, like a sign-in or a mail rule change, gets compared against a user’s own established behavioral baseline, rather than a generic rule or risk score. What counts as anomalous for one person, like a burst of sent emails or a login at an unusual hour, might be completely normal for someone else in a different role. If the event is a meaningful deviation from that individual's pattern, it's logged as an anomaly.
Correlation. Flagged anomalies are evaluated together, across multiple sources and systems, to see whether they add up to a pattern or stay isolated and explainable. Most anomalies stay isolated. A single new IP address or an unfamiliar login on its own usually isn't enough, and Abnormal is deliberately built to wait for corroborating signals rather than react to any one flag by itself.
Case creation. When correlated signals cross a confidence threshold, Abnormal creates an account takeover case, complete with a timeline and a plain-language summary of what happened and why.
Many identity tools stop at the first stage, surfacing every deviation as its own isolated alert and leaving it to a security team to manually connect a new device registration in one place to a mail rule change in another. Abnormal does that correlation work upstream, which is why the Cases tab for ATO stays high-fidelity: a small number of findings that have already surpassed a confidence threshold, built to be actionable and, where configured, auto-remediated without a person in the loop. The Anomaly Log makes that upstream evaluation visible, without requiring SOC teams to redo the correlation work themselves.
How to Use the Anomaly Log
Since Account Takeover is designed to be a high-fidelity solution that can perform in an automated fashion, the Anomaly Log is optional. It does not require a response, and most teams will never touch it on a normal day. The volume can look intimidating; a single week can easily surface thousands of entries. But that volume is the point: it's a sign the model is continuously monitoring every identity in your environment, not a queue you're expected to clear. That said, some analysts turn to it with a specific question in mind:
Spot-check that the lights are on. A quick look at anomaly volume and trends over the past week is a fast way to confirm the system is actively evaluating behavior, even during periods with zero open cases.
Zoom in on a user. If something about a specific employee's account feels worth a second look, even without an existing case, searching a specific user surfaces every anomalous signal tied to them in one place.
Zoom in on behavior. Filtering by event type—a first-time VPN connection, a newly created mail rule—narrows the feed to a single pattern, making it easy to compare across users.
The Anomaly Log gives analysts a direct look at the engine's ongoing evaluation: every signal it's weighing, all the time, whether or not any of it ever becomes an account takeover case.
See how Abnormal uses behavioral AI to expose coordinated account takeovers that traditional tools miss. Schedule a personalized demo.

