Hamburger menu
TechBag
Search icon
Enterprise
Small Businesses
Industries
Blog
About Us
Shopping Bag
Get Quote
Vendor hubEmail · ATO · AI Agents · Posture · PlatformTechBag Intel Hub

Abnormal AI

The AI-native behavioural security company — it catches the socially-engineered attacks (BEC, phishing, VEC) that gateways miss, using behavioural AI, and is expanding beyond email to identity & AI governance. This hub is your complete intel file.

5 intel pages insideBehavioural AI · minutes to deployBengaluru R&D · local via TechBag

Buy through TechBag

Same software. Better outcome — at no extra cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free, vendor-neutral, 30 minutes

The company, at a glance

Founded2018 · San Francisco
RebrandAbnormal AI (2025)
Scale3,000+ customers
EngineAttune (behavioural AI)
India R&DBengaluru (biggest ex-SF)

Quick answer

Abnormal AI is an AI-native behavioural security company — it protects organisations from the socially-engineered attacks that target human behaviour, starting with email (the #1 attack vector) and now extending across identity, AI usage and insider threats. Its core idea: instead of signatures and reputation lists, Abnormal uses BEHAVIOURAL AI (its engine, Attune) to learn the normal behaviour of every identity and relationship in your organisation — who emails whom, tone, timing, financial-request norms, sign-in patterns — and flags the ANOMALIES that signal an attack (an out-of-pattern invoice request, an unusual login, a novel vendor thread). Its flagship, Inbound Email Security, is an ICES (Integrated Cloud Email Security) solution that API-integrates with Microsoft 365 or Google Workspace — deploying in MINUTES with no MX-record change — and catches the business email compromise (BEC), advanced phishing, account takeover and vendor email compromise (VEC) that traditional gateways AND native defences miss. Founded in 2018 (San Francisco; CEO Evan Reiser; the founders came from ad-tech/behavioural-ML, applying those techniques to detecting social engineering), the company rebranded from ‘Abnormal Security’ to ‘Abnormal AI’ in 2025 to reflect its AI-native identity and platform expansion. It was last valued at $5.1B (2024), has ~$200M ARR at ~100% YoY growth, and protects 3,000+ customers including ~1 in 5 of the Fortune 500. TechBag presents five angles as full intel pages: Inbound Email Security (the flagship), Account Takeover Protection (detect compromised accounts via behaviour), AI Security Agents (autonomous AI that automates SOC triage, remediation and coaching), Email Productivity & Posture (graymail cleanup, posture management, misdirected-email prevention), and the Behavioral Platform (its 2026 expansion into identity threat protection, AI governance and infiltration prevention). Honest scope: Abnormal is email-first and NARROWER than a full platform like Proofpoint (which TechBag also sells) — it doesn’t match Proofpoint’s DLP, compliance, archiving or awareness-training depth — and it LAYERS ON Microsoft/Google native security rather than replacing the whole stack. Its edge is best-in-class behavioural detection and fast API deployment. Notably, Abnormal’s BENGALURU office is its largest R&D centre outside San Francisco. From Abnormal AI — behavioural AI that catches what gateways can’t. TechBag scopes it and supports it in INR/GST for Indian enterprises. Read more ↓ Show less ↑
The portfolio

Five intel pages. One behavioural model.

The complete Abnormal AI platform — every linked card is a full intel page, from the email-security flagship to the 2026 behavioral platform.

The flagshipIntel page →

Inbound Email Security

Catch what gateways miss.

The flagship — AI-native, behavioural email security that stops the advanced, socially-engineered attacks (BEC, credential phishing, account takeover, vendor email compromise) that traditional secure email gateways AND Microsoft/Google native defences miss. Its behavioural AI (Attune) learns your normal and flags anomalies; it’s API-integrated (deploys in MINUTES, no MX change), sitting behind native mail — so it augments (or replaces) your gateway without re-routing your mail.

Behavioural AI · minutes to deployExplore
Post-compromiseIntel page →

Account Takeover Protection

Catch the breached account.

Detect COMPROMISED internal accounts via behavioural anomalies — unusual logins, out-of-pattern sign-ins, malicious mail-rule changes, lateral movement — so a breached account doesn’t become an internal attack. This is cross-signal behavioural detection of accounts ALREADY compromised (not just blocking inbound), with auto-remediation — powered by the same behavioural model as the flagship. Catch the takeover, and stop it spreading.

Behavioural ATO detection + remediationExplore
Autonomous AIIntel page →

AI Security Agents

AI co-workers for your SOC.

Abnormal’s 2025–2026 bet — AUTONOMOUS AI agents that automate SOC tasks: AI Security Mailbox (an AI co-worker that triages user-reported emails 24/7, auto-remediates campaigns org-wide, and closes the loop with reporters via conversational GenAI — Forrester cited ~5,000 analyst hours saved/year); AI Phishing Coach (just-in-time, risk-adaptive training); and an AI Data Analyst. Autonomous agents that eliminate manual SOC work and handle volume humans can’t.

Autonomous SOC triage · ~5,000 hrs/yr savedExplore
Hygiene & configIntel page →

Email Productivity & Posture

Cleaner, safer, better-configured.

Beyond stopping attacks — three capabilities off the same behavioural model: Email Productivity (strip graymail/promotional noise, reclaim inbox time), Posture Management (continuous security posture — catch risky misconfigurations and config drift across your email/M365 platform), and Misdirected Email (prevent accidental data leakage from mis-addressed mail). Cleaner inboxes, hardened configuration, fewer accidental leaks.

Graymail + posture + misdirected emailExplore
New (2026)Intel page →

Behavioral Platform

Beyond email — one model.

Abnormal’s 2026 expansion (launched Aug 3, 2026) — one behavioural model, extended beyond email: Identity Threat Protection (detect/remediate compromise inside post-authentication sessions; protect the help desk against suspicious reset requests), AI Governance (discover, score and govern the AI tools and agents — sanctioned and shadow — across your org), and Infiltration Prevention (flag fraudulent candidates / suspected nation-state operatives before they gain access). Human-behaviour security, beyond the inbox.

Identity threat · AI governance · infiltrationExplore

One behavioural model — the Attune engine

Platform & engine

Everything Abnormal does runs on ONE behavioural AI engine — Attune — trained on billions of behavioural signals and rooted in the founders’ ad-tech/behavioural-ML background. It models identity, behaviour and relationships to detect the deviations that signal an attack, and the SAME model powers inbound email, account takeover, the AI security agents, posture, and (2026) identity threat, AI governance and infiltration prevention. One model, many applications — the moat that lets Abnormal extend across the human attack surface.

From ‘Abnormal Security’ to ‘Abnormal AI’ — the platform story

Platform & engine

The 2025 rebrand from ‘Abnormal Security’ to ‘Abnormal AI’ signalled two things: an AI-native identity (behavioural AI is the foundation, not a feature) and a platform expansion beyond email. In 2025–2026 Abnormal added autonomous AI security agents (automating SOC work) and, in August 2026, identity threat protection, AI governance and infiltration prevention — becoming a ‘Behavioral Security Platform’ protecting human AND non-human/synthetic identities. (Agentic and identity/AI-governance capabilities are new and evolving — validate for your environment.)

The thesis

Why “behavioural AI, catch what gateways miss” is the whole story

Signature-based gateways miss the payload-less social engineering that causes the biggest losses. Abnormal bet onbehavioural AI — model normal, flag the anomalies gateways can’t catch— behavioural AI (Attune) that models normal behaviour and flags the anomalies signature gateways can’t catch, API-integrated in minutes, layered on Microsoft/Google native security doubled down on it.

01
The foundation

Behavioural AI (Attune)

Instead of signatures, Abnormal models the NORMAL behaviour of every identity and relationship, and flags anomalies — catching the social engineering (BEC, impersonation) that signature-based tools miss. Behaviour beats signatures. Its genuine moat.

02
The architecture

API-Native (ICES)

API-integrated with Microsoft 365 / Google Workspace — deploy in minutes, no MX change, no mail re-routing — sitting behind native mail and analysing post-delivery. It layers onto your stack (augment or replace the gateway), frictionlessly.

03
The edge

Catch What Others Miss

The result: Abnormal catches the advanced, behavioural attacks — BEC, phishing, account takeover, VEC — that gateways and native defences let through, with high efficacy and low false positives. Best-in-class behavioural detection.

04
The expansion

Autonomous AI & the Platform

Beyond detection: autonomous AI security agents (automating SOC triage and remediation) and, in 2026, a broader behavioural platform (identity threat, AI governance, infiltration prevention) — one model, extended across the human attack surface.

05
The India layer

Fast-Growing & India-Rooted — Local via TechBag

A fast-growing modern leader (~$200M ARR, 100% YoY; $5.1B 2024 valuation) with its largest R&D office outside SF in BENGALURU — genuine India relevance. It’s quote-priced; TechBag adds scoping, honest comparison (vs Proofpoint/Microsoft), DPDPA-residency help, INR/GST and support.

Start with Inbound Email Security (catch what your gateway misses) — then add Account Takeover Protection, AI Security Agents, Email Productivity & Posture, and the 2026 Behavioral Platform. One behavioural model.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

The approach

AI-native behavioural

Attune — not signatures

The edge

Catch what gateways miss

BEC, VEC, phishing

Deployment

API — minutes, no MX

Layer on M365/Google

Autonomous AI

AI Security Agents

~5,000 SOC hrs/yr saved

Founded

2018 · San Francisco

CEO Evan Reiser

Momentum

~$200M ARR (100% YoY)

$5.1B valuation (2024)

Scale

3,000+ customers

~1 in 5 Fortune 500

India R&D

Bengaluru

Largest office outside SF

By the numbers

The company in six figures

0
founded — rebranded ‘Abnormal AI’ 2025
Vendor
0+ customers
~1 in 5 of the Fortune 500
Scale
0 intel pages
Inbound, ATO, AI Agents, Productivity, Platform
This hub
0 behavioural model (Attune)
email → identity → AI governance
The moat
0 minutes to deploy
API-integrated, no MX change
Architecture
~0 SOC hours saved/yr
via autonomous AI agents (Forrester)
AI agents

See the platform, hear the pitch

Abnormal AI (official)·Overview

An Abnormal Approach to Email Security

The behavioural approach, explained.

Abnormal AI (official)·Demo

Inbound Email Security — Product Demo

The flagship, walked through.

Trusted by 600,000+ organisations worldwide

Enterprises on M365 / GoogleBFSI (banks, insurance)IT / ITES & GCCsManufacturing (VEC-exposed)Healthcare & pharmaRetail & e-commerceTechnology & SaaSLean SOC teamsIndian enterprises (M365/Google)3,000+ Abnormal customersEnterprises on M365 / GoogleBFSI (banks, insurance)IT / ITES & GCCsManufacturing (VEC-exposed)Healthcare & pharmaRetail & e-commerceTechnology & SaaSLean SOC teamsIndian enterprises (M365/Google)3,000+ Abnormal customers
The market maps

Where Abnormal AI sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Abnormal AI Across Its Platform

Each dot is an Abnormal angle: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
Inbound Email SecurityAbnormal AI

The flagship — behavioural AI ICES.

Grid 02 · The industry

The Behavioural-Detection × Deploy-Speed Map

Behavioural detection & deploy speed vs the field — where Abnormal catches what gateways miss.

Signature nichesAI-native + behaviouralPoint playersBroad but signature-bound
Abnormal AIAbnormal AI

AI-native behavioural; catches what gateways miss.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Abnormal AI?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What’s your priority?

2. Which sentence sounds most like you?

3. What does success look like?

The acronym decoder

Every term on these pages, in one place
Abnormal AI
An AI-native behavioural security company — protect people from socially-engineered attacks (email, identity, AI usage). Founded 2018; rebranded from Abnormal Security in 2025.
Behavioural AI (Attune)
Abnormal’s engine — it models the normal behaviour of every identity and relationship and flags anomalies that signal an attack. The moat.
ICES
Integrated Cloud Email Security — API-integrated email security that sits behind native M365/Google mail (no MX change), analysing post-delivery. Abnormal’s model.
BEC
Business Email Compromise — payload-less, socially-engineered attacks (fake invoices, CEO fraud) that cause the biggest losses and that signature tools miss. Abnormal’s core catch.
VEC
Vendor Email Compromise — attacks via a compromised or impersonated vendor thread. Abnormal catches these by understanding your real vendor relationships.
Account Takeover (ATO)
When an attacker gains control of an internal account. Abnormal detects it via behavioural anomalies (odd logins, mail rules, lateral movement).
AI Security Mailbox
An autonomous AI agent that triages user-reported emails 24/7, auto-remediates campaigns, and closes the loop with reporters — saving SOC analyst hours.
Posture Management
Continuous detection of risky misconfigurations and config drift across your email/M365 platform — part of Email Productivity & Posture.
Identity Threat Protection
Abnormal’s 2026 capability — detect/remediate compromise inside post-authentication sessions and protect the help desk against suspicious reset requests.
AI Governance
Abnormal’s 2026 capability — discover, score and govern the AI tools and agents (sanctioned and shadow) used across your organisation.
The augment-or-replace model
Abnormal layers onto your Microsoft/Google native security to catch what it misses (augment), or can replace a legacy secure email gateway (SEG).
The India layer
Abnormal’s largest R&D office outside SF is in Bengaluru; TechBag adds scoping, honest comparison, DPDPA-residency help, INR/GST and support.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Scope (& augment vs replace)

Your mail platform (M365/Google), current email security (native? a gateway?), and needs. TechBag scopes whether Abnormal should AUGMENT your native security or REPLACE a legacy gateway — and compares honestly vs Proofpoint (platform) and Microsoft (bundled).

02

Connect via API (minutes)

Integrate Abnormal with Microsoft 365 or Google Workspace via API — no MX change, no re-routing — and let Attune learn your organisation’s normal behaviour. Protected in minutes.

03

Catch what native misses

Abnormal flags the behavioural anomalies — BEC, phishing, ATO, VEC — that your native/gateway security missed, and auto-remediates post-delivery. Add account-takeover protection. Close the gap.

04

Automate & extend

Turn on AI Security Agents (autonomous SOC triage, ~5,000 hours saved/yr), add Email Productivity & Posture, and — as you mature — the 2026 behavioural platform (identity, AI governance). One model, more coverage.

05

Compare honestly

Need a broad platform (DLP/compliance/awareness)? Proofpoint (a sibling — TechBag sells it). On M365 E5? Defender is bundled. Deep detection-engineering? Sublime. TechBag advises honestly.

06

Buy through the channel

Abnormal is quote-priced (per mailbox, USD) — TechBag adds scoping, INR/GST invoicing, DPDPA-residency help and local support.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
Inbound Email SecurityPer mailbox — by quoteBehavioural detection (BEC/phishing/VEC); API deployCatch what gateways miss
Account Takeover ProtectionPer mailbox / add-on — by quoteBehavioural ATO detection + remediationPost-compromise defence
AI Security AgentsBy quote / platformAI Security Mailbox, Phishing Coach, Data AnalystAutonomous SOC automation
Email Productivity & PostureAdd-on — by quoteGraymail, posture management, misdirected emailHygiene, config & accidental-leak
Behavioral Platform (2026)By quote (new)Identity threat, AI governance, infiltrationBeyond-email behavioural security

Per mailbox, quote-priced (in USD) — TechBag scopes the mailboxes, advises augment-vs-replace, compares vs Proofpoint/Microsoft, and handles INR/GST.

Five pitfalls that cost buyers quarters

1

Expecting a full platform (it’s email-first)

Abnormal is best-in-class at behavioural email detection — but it’s EMAIL-FIRST and narrower than a full human-risk platform. It doesn’t match Proofpoint’s DLP, compliance/archiving or security-awareness-training depth (Proofpoint is a Wave-C sibling TechBag also sells). If you need those, Abnormal is a LAYER, not the whole answer. Many enterprises run Abnormal FOR the behavioural detection alongside a broader platform. TechBag is candid about the split.

2

Thinking it replaces your whole mail stack

Abnormal is an ICES that LAYERS ON your Microsoft 365 / Google Workspace native security via API — it AUGMENTS native (catching what it misses) and can replace a legacy secure email gateway, but it does NOT replace your mail platform or your native security underneath. Understand the model: you keep Microsoft/Google, and Abnormal adds the behavioural layer. TechBag scopes augment-vs-replace for your stack.

3

Overlooking explainability/customisability trade-offs

Abnormal’s strength is a global behavioural model that ‘just works’ — but some advanced SOC teams note it offers LESS rule-level customisability and explainability than detection-engineering-focused rivals (e.g. Sublime Security). If your SOC wants deep, tunable, transparent detection rules, weigh that. For most, Abnormal’s low-tuning, high-efficacy model is a benefit. TechBag matches the approach to your team.

4

Treating the AI agents as fully proven

Abnormal’s autonomous AI security agents (AI Security Mailbox etc.) are genuinely ahead of most peers — but agentic AI is NEW and evolving, and the headline figures (e.g. ~5,000 SOC hours saved/year) are Abnormal’s/analyst claims that depend on your environment and volume. Deploy them thoughtfully with oversight, and validate the savings for your case. TechBag helps you adopt the agents with the right guardrails.

5

Missing the India R&D story (and residency question)

Abnormal’s largest R&D office outside San Francisco is in BENGALURU — genuine India relevance and engineering depth, a real credibility point often overlooked. On the flip side, for regulated deployments, data-residency requirements (DPDPA) should be confirmed with the vendor — don’t assume. TechBag surfaces both: the India R&D story, and the residency confirmation, and handles GST.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your device counts and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Abnormal AI

Abnormal AI is an AI-native behavioural security company — it protects organisations from the socially-engineered attacks that target human behaviour, starting with email (the #1 attack vector) and now extending across identity, AI usage and insider threats. Its core idea: instead of signatures and reputation lists, Abnormal uses BEHAVIOURAL AI (its engine, Attune) to learn the normal behaviour of every identity and relationship — who emails whom, tone, timing, financial-request norms, sign-in patterns — and flags the ANOMALIES that signal an attack. Its flagship, Inbound Email Security, is an ICES (Integrated Cloud Email Security) that API-integrates with Microsoft 365 or Google Workspace — deploying in MINUTES with no MX change — and catches the BEC, advanced phishing, account takeover and vendor email compromise (VEC) that gateways AND native defences miss. Founded in 2018 (San Francisco; CEO Evan Reiser; founders from ad-tech/behavioural-ML), the company rebranded from ‘Abnormal Security’ to ‘Abnormal AI’ in 2025. It was last valued at $5.1B (2024), has ~$200M ARR at ~100% YoY growth, and protects 3,000+ customers (~1 in 5 Fortune 500). TechBag presents five angles — Inbound Email Security (flagship), Account Takeover Protection, AI Security Agents (autonomous), Email Productivity & Posture, and the Behavioral Platform (2026: identity, AI governance, infiltration). Honest note: it’s email-first and narrower than a full platform like Proofpoint (which TechBag also sells), and it layers on Microsoft/Google native security. Notably, its largest R&D office outside SF is in Bengaluru. TechBag scopes it and supports it in INR/GST.

Ready to shortlist Abnormal AI?

Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — mailbox scoping, augment-vs-replace advice, honest Proofpoint/Microsoft comparison, GST invoicing and support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.