Abnormal is designed to analyze inbound email via API integration, ensuring broad behavioral analysis coverage across your email traffic.
Modern email attacks rarely contain known-bad indicators of compromise that traditional threat detection relies on. Instead, cybercriminals are exploiting trust, legitimate infrastructure, and security blind spots through socially engineered attacks. Abnormal has witnessed threat actors:

Our Behavioral AI works by:

Mimecast claims to offer behavioral analysis—but their approach is fundamentally different:

Read more about how Abnormal detected invoice and vendor fraud attempts that Mimecast missed.
Abnormal is designed to detect and remediate these attacks by:

Abnormal is designed to detect these attacks through:

Onboarding
Mimecast SEG
Typically multi-week setup with PS assistance
Mimecast Cloud Integrated (CI)
Typically 30-60 minutes setup (basic transport rules)
Abnormal AI
Deploys typically in under 30 seconds via API
Threat Detection
Mimecast SEG
Static rules, reputation checks, malware scans
Mimecast Cloud Integrated (CI)
Same engines as SEG; NLP applied post-CyberGraph
Abnormal AI
Behavioral AI is designed to analyze 100% of messages against dynamic user/vendor baselines
ATO Protection
Mimecast SEG
Limited; no identity signal integration
Mimecast Cloud Integrated (CI)
No detection of login anomalies or MFA changes
Abnormal AI
Behavioral AI helps detect and remediate ATOs
VEC Protection
Mimecast SEG
Spoofed domain detection via DMARC
Mimecast Cloud Integrated (CI)
Header analysis only; lacks behavioral insight
Abnormal AI
Detects compromised vendors with VendorBase™ across 3,000+ orgs
Maintenance
Mimecast SEG
Requires ongoing policy tuning
Mimecast Cloud Integrated (CI)
Minimal tuning, limited configuration
Abnormal AI
Self-learning; no rule-writing or tuning required