Key Insights
Meet Us at Fal.Con 2026: How to Connect with Abnormal AI
Email security used to be a one-directional problem: Stop what's coming in, but that's no longer the whole job. Attackers have gotten better at getting past inbound defenses, outbound data still leaks through DLP tools too noisy to act on, and security awareness training hasn't kept pace with the unique behaviors and risks of individual employees.
That’s the gap we’re closing. Abnormal AI is excited to showcase three new updates in person at Fal.Con 2026 in addition to connecting with security leaders in the space. If you're already running CrowdStrike, Fal.Con is a good time to see what the Abnormal integration and combined view looks like in practice.
Here's what we're bringing to Mandalay Bay, and where to find us.
The Abnormal AI Booth at #1302
Booth #1302 is where all of this comes to life on the show floor. Stop by for live demos of the Abnormal Behavior Platform running through real detections, along with a team ready to talk through how behavioral AI stops the business email compromise and account takeover attacks that legacy tools miss.
Booth hours:
Monday: 5:30–7:30 pm
Tuesday: 10:30 am–5:30 pm
Wednesday: 10:30 am–5 pm
If you want to have a deeper conversation, our executive team is on-site all week as well and available for scheduled 1:1 meetings in executive meeting rooms in the Expo Hub, along with a private suite at The W Hotel. Reach out ahead of the show to lock in time.
Meet Abnormal AI at Fal.Con
Expert Session on Legitimate Login, Malicious Outcome
Device-code login flows exist to make signing in easier. Attackers have found a way to turn that convenience into an opening.
Abnormal’s threat intel experts Piotr Wojtyla and Ryan Devendorf dissect EvilTokens, a technique that exploits device-code authentication to launch AI-driven BEC, and what security teams can do to close the gap before it becomes a breach.
Session: Legitimate Login, Malicious Outcome: How EvilTokens Turns Device Codes Into AI-Driven BEC
Speakers: Piotr Wojtyla and Ryan Devendorf, Abnormal AI
Date: Tuesday, September 1, 2026
Time: 2:30–2:50 pm
Location: Expo Hall Theater
GuidePoint Security Happy Hour at Rhythm and Riffs Lounge
On Tuesday evening, Abnormal is sponsoring the GuidePoint Security Happy Hour at Rhythm and Riffs Lounge inside Mandalay Bay, an easy way to connect with the team between sessions.
Date: Tuesday, September 1, 2026
Time: 6:00-8:00 pm
Location: Rhythm and Riffs Lounge, Mandalay Bay
An Invitation-Only Karaoke Night at The Barbershop
After three days of sessions, demos, and meetings, it's worth closing out the week differently.
Hack the Mic is Abnormal's invite-only karaoke night: live-band karaoke, an open bar, and light bites at The Barbershop, a speakeasy inside The Cosmopolitan. No booths, no pitches, just a chance for C-level security leaders to unwind together.
Date: Tuesday, September 1, 2026
Time: 8:30 pm
Location: The Barbershop, The Cosmopolitan Hotel, Las Vegas
Who's invited: Director-level security leaders and above
We hope you’ll join us, and we recommend requesting an invite ahead of time as space is limited.
Request an Invite
What's New: Control, Coverage, and Coaching That Adapts
We’re shipping three updates around Fal.Con week, each aimed at a different gap security teams have had to work around.
Control Center gives teams a new layer of visibility and control over inbound detection. Security teams can build custom AI models from a plain description of the pattern they're seeing, write explicit rules against more than 50 message attributes, and see exactly which layer, core AI, a custom model, or a rule, caught each detection. It's available now at no additional cost.
Email DLP Rules brings the same intelligence to outbound email. Teams define the policies that matter, and an AI agent reviews every match in context, sender, message, and rule intent, clearing false positives automatically before they ever reach a queue. It's the piece that's made traditional DLP tools so hard to run at scale, handled before a human has to look at it.
AI Phishing Coach rethinks security awareness training around behavior instead of a fixed schedule. It adjusts simulation frequency and difficulty to each employee's real-time risk score, lets administrators generate a themed attack scenario from a plain-language prompt, and automatically follows up with anyone who doesn't respond to the first simulation. Training that used to run on a calendar now runs on how people actually behave.
Together, the three updates reflect the same idea: legacy tools are straining at both ends of the mailbox, and the fix isn't more alerts, it's AI that can explain its reasoning and adapt to how people and organizations actually work.
See You at Fal.Con at Booth #1302
Whether you want to see how Control Center changes what you can see and shape in your own environment, or you're trying to eliminate the BEC attacks legacy tools miss altogether, Fal.Con 2026 is the place to have that conversation.
Abnormal AI is the behavioral AI platform that protects enterprises by understanding what normal looks like for every identity in your organization, then catching what deviates from it, including attacks no one has seen before.
Book a Meeting at Fal.Con

