Ir para o conteúdo principal
Abnormal Extends Behavioral AI to Identity and AI SecurityLearn more

Jul 28, 2026

The Behavioral Security Era is Here: Securing Identity, AI, and the Human Perimeter

Today marks a new era for Abnormal AI.

When we started Abnormal, we made a contrarian bet that behavior (not threat intelligence) would become the most valuable source of security insight for defenders. At that time, most of the market was pouring money into perimeter and endpoint defenses, tighter policies and better credential hygiene. Instead, we bet on something harder to build and easy to dismiss; that behavior, not credentials or signatures, was the signal worth investing in. Underlying this bet was a vision for the future: that if we got good enough at analyzing behavior in email, we could apply it everywhere, extending our foundation as an email security platform into a behavioral security platform capable of stopping the most sophisticated attacks.

Eight years later, 4500+ customers trust us to make one billion autonomous decisions daily1, and stop attacks and that others can’t2. Behavioral data, from email telemetry and communication patterns to sign-in signals and training outcomes, underpins every decision Abnormal's behavioral AI makes.

And today, with the launch of multiple new products spanning Identity Security, AI Security, and Insider Threat, our vision of behavioral security is coming true.

 

 

I’m excited to announce that we’re extending our capabilities to solve the most complicated and dangerous identity threats as part of our Behavioral Security Platform. Email security continues to be one of those problems, but our customers have told us they're facing more challenges beyond the inbox:

  • Attacker tactics have evolved: Attackers are no longer breaking in but rather blending in b bypassing authentication entirely to compromise identities and breach organizations.

  • AI transformation is widening the attack surface: Companies are using AI tools and agents in greater numbers by the day, outpacing the ability of security teams to govern it.

  • Malicious actors are attempting to make their way into organizations: Nation-state adversaries are using social engineering to architect fraudulent identities that pass as legitimate IT workers.

  • The volume of identities has exploded: This encompasses both human and non-human identities. In fact, non-human identities (NHIs) outpace humans 45 to 1 in enterprise environments.

All of these risks are tied to two things: identity and behavior. Traditional defenses often cannot scale to address modern identity threats, because traditional solutions lack the ability to analyze behavior in the first place.

Those solutions rely on policies and the ability to satisfy credentials, but AI-powered attackers can easily fool those systems, then disappear into the crowd. Worse yet, NHIs like service accounts or AI agents are often inherently trusted or not visible at all, so once they start behaving abnormally, there’s often nothing watching to catch it.

To close that gap, we're extending our behavioral AI to identity threats, AI risks, and the onboarding pipeline. Today, we’re announcing three new products and one new platform feature to easily activate Abnormal products:

  • Identity Threat Protection: Protection from newsworthy identity breaches.

  • AI Governance: Visibility and control to secure AI transformation.

  • Infiltration Prevention: Prevention from malicious actors becoming insiders.

  • AI App Store: A single location within our platform for activating our new security products.

Catching Identity Breaches Before They’re Headlines

Screenshot 2026 07 27 at 4 36 52 PM 1

Authentication can be bypassed and legitimacy can be faked, but attackers struggle to mimic normal behavior through every step of their attacks. When a real, trusted identity, whether a person, a service account, or an OAuth app, suddenly stops acting normally, most tools won’t notice. If that identity is properly authenticated and is operating within a valid session, then traditional tools have already stopped watching.

Attackers know this. They can remain relatively silent, behave like a legitimate user, and compromise valuable systems and assets. For example, phishing-as-a-service platforms like VENOM avoid the login, instead opting to capture valid authentication tokens or register new MFA devices without ever entering a username and password.

Identity Threat Protection is built to understand the established behavioral patterns for each identity in your organization and take action when deviations from those patterns occur.

Abnormal's own threat intelligence powers a dynamic Threat Library that maps coverage against known identity attacks while identity posture insights surface the weaknesses (accounts without MFA, overprivileged service accounts) attackers commonly exploit, prioritized by attack susceptibility, and recommend ways to reduce exposure. Beyond proactive hardening, Identity Threat Protection correlates IdP activity, SaaS events, and email-origin signals, like the initial phishing email that causes a breach. From there, the solution remediates threats and removes the rogue MFA devices and malicious mailbox rules attackers use to maintain persistence.

It also helps protect the helpdesk, a critical surface area attackers exploit to embed themselves further into the organization through credential reset. The Adaptive Identity Reset capability flags suspicious users and requires additional verification through behavioral challenge questions.

Learn more about Identity Threat Protection

Secure AI Transformation Spanning Tools and Agents

Screenshot 2026 07 27 at 4 36 36 PM 1

From the moment a user installs an AI tool, that tool presents both a benefit and a risk. Users, whether they are using sanctioned or unsanctioned tools, have the ability to access corporate data, run critical functions, scale agents or actions to tremendous levels, and more. Users and their tools can access systems, see data they shouldn’t, or spin up agents security teams have no ability to control. Meanwhile, costs can skyrocket as employees tinker and build in inefficient ways.

AI Governance was built to secure AI transformation and adoption. Just like it does for email and identity, Abnormal's behavioral AI first learns what's normal for how your organization uses AI, then it discovers, scores, and governs your AI tools, and discovers the AI agents, and AI chat activity across your environment, both sanctioned and unsanctioned. By combining signals like sign-up emails from unsanctioned tools, OAuth grants, identity events, and telemetry from AI platforms like AWS Bedrock and Azure AI Foundry, Abnormal can quickly surface and act on risk across your AI environment.

Learn more about AI Governance

Stopping Nation-State Infiltrators From Becoming Insiders

Screenshot 2026 07 27 at 4 37 45 PM 1

Foreign operatives, primarily from North Korea, are posing as IT workers in an effort to infiltrate organizations. In one well-documented example, a network of at least 20 threat actors had applied to almost 160,000 roles before being caught.

These threat actors rely on social engineering and the implicit trust organizations place in jobseekers. Your applicant tracking system (ATS) isn’t somewhere you expect to find danger, but these attackers are savvy. They know security teams don’t often monitor these systems.

A fake LinkedIn profile and an AI headshot may fool a human, but it is far harder to slip past a true behavioral security platform.

Infiltration Prevention is a security solution built to identify and correlate the behaviors associated with fabricated identities created by nation-state threat actors (e.g. VoIP burner numbers, VPN-masked locations, and the same identity resurfacing in Abnormal's threat intelligence). It integrates directly with Greenhouse and Workday to detect attackers the moment they enter the system but before they're ever provisioned. This behavioral understanding is then used to not only identify individual operatives but also large-scale campaigns and threat actor networks, building detailed evidence briefs SOC teams can use to take action.

Importantly, this is not a tool meant to recommend hiring decisions. It does not replace your existing HR and screening processes.

Learn more about Infiltration Prevention

Meet the AI App Store: Activate Abnormal Products in Minutes

Group 2087328392

AI has quickened the pace at which threat actors can invent and execute never-before-seen attack tactics. That puts pressure on us to deliver new products and capabilities just as fast.

To rise to this challenge, Abnormal is releasing the AI App Store, a central interface in the Abnormal Customer Portal to browse and activate Abnormal products. For the first time, our customers can activate and deploy new Abnormal products to trial themselves at their pace.

The AI App Store will go live on August 3, 2026. Identity Threat Protection, AI Governance, and Infiltration Prevention will be available to activate.

Learn more about the AI App Store

Activate These New Products on August 3rd

The threats that matter most now don't look like threats at all. A trusted identity is taken over and moves through a valid session like a real employee would. An otherwise benign AI agent codes its way into a sensitive database. A nation-state actor masquerades as an adjunct Ivy League professor looking for a career change.

Each one looks different, yet each gives itself away in the same way: behavior. That is what Abnormal sees. Our approach with behavioral AI, grounded in a wide range of email signals, enables more powerful outcomes across these new products. These signals allow us to better understand normal activity for users, discover shadow AI tools and spend, and protect critical infrastructure like the helpdesk.

After nearly a decade in behavioral AI security, it not only made sense but was imperative that we expand and launch these new solutions, and we're not stopping here. This is just the beginning of our new normal.

We invite you to meet us at our Black Hat USA booth to see a demo, ask questions, and learn how Abnormal can protect your normal.

Book at meeting at Black Hat USA or request access to our new products now.


1 Based on an internal analysis of emails and account sign-ins processed and analyzed from January 1, 2025 – December 31, 2025.

2 Based on Abnormal’s analysis of documented attack campaigns, customer evaluations, and publicly available research regarding the limitations of traditional email security approaches, including attack types with no known signature or industry classification at the time of detection.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.