Loading

Abnormal AI

Version 1.10.0 (View all)
Compatible Kibana version(s) 8.17.0 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

Abnormal AI is a behavioral AI-based email security platform that learns the behavior of every identity in a cloud email environment and analyzes the risk of every event to block even the most sophisticated attacks.

The Abnormal AI integration collects data for AI Security Mailbox (formerly known as Abuse Mailbox), Audit, Case, and Threat logs using REST API.

The Abnormal AI integration collects six types of logs:

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions.

  • Retrieve your authentication token. This token will be used further in the Elastic integration setup to authenticate and access different Abnormal AI Logs.
  • Abnormal AI requires you to restrict API access based on source IP. So in order for the integration to work, user needs to update the IP allowlisting to include the external source IP of the endpoint running the integration via Elastic Agent.
  1. In Kibana navigate to Management > Integrations.
  2. In "Search for integrations" top bar, search for Abnormal AI.
  3. Select the "Abnormal AI" integration from the search results.
  4. Select "Add Abnormal AI" to add the integration.
  5. Add all the required integration configuration parameters, including Access Token, Interval, Initial Interval and Page Size to enable data collection.
  6. Select "Save and continue" to save the integration.
Note

By default, the URL is set to https://api.abnormalplatform.com. We have observed that Abnormal AI Base URL changes based on location so find your own base URL.

Introduced in version 1.8.0, the Abnormal AI integration includes a new option called Enable Attachments and Links enrichment for the Threat data stream. When enabled, this feature enriches incoming threat events with additional details about any attachments and links included in the original message.

This is the ai_security_mailbox dataset.

This is the ai_security_mailbox_not_analyzed dataset.

This is the audit dataset.

This is the case dataset.

This is the vendor_case dataset.

This is the threat dataset.