Key Insights
Picture this: your CEO emails you. He needs gift cards, fast—and he's traveling, so don't call. The email is one line of text, in the CEO's usual style. No links, no attachments, nothing for a scanner to flag. Just a familiar name and the pressure to act.
In 2018, that email beat every email security tool on the market. It beat human judgment too. Back then, people trusted email completely, and nobody stopped to question a message that read exactly like it came from their boss. Cyber incidents were big, expensive news, but the industry was so busy trying to predict what the next zero-day attack would look like, it had overlooked something far more basic: attackers weren't hacking in—they were logging in. And the next compromise wasn't going to look like an attack at all.
Built by AI Insiders, Thinking Like Outsiders
None of us set out to work in cybersecurity. Our founding engineers came from Teleport, an ad-targeting company acquired by Twitter, where we built behavioral models to predict how users would act on bidding platforms. Security wasn't on our radar until one of Teleport's early investors brought us an interesting challenge. A malicious actor had nearly scammed the fund out of millions of dollars by impersonating a partner over email and asking staff to move money out. No one had clicked anything malicious. The attacker stole an identity to sneak inside an inbox and blend in.
Looking closer, we noticed Twitter and email shared the same basic vulnerability. Both let anyone talk to anyone, and both assumed a level of authenticity that couldn’t always be trusted.
At the time, investment was flowing into signature-based defenses: malicious links, attachments, code bases, phrases, or known-bad domains were learned once and matched forever after to prevent previously seen attacks from occurring again. That approach broke the moment attackers started automating. You can pour all the money into perimeter and endpoint detection, but there’s no signature for a never-seen-before attack variant spun up overnight.
Seven of us felt we could translate the technology we’d built for ad targeting into the cybersecurity space. We founded Abnormal on the maverick bet that behavior, not signatures or credentials, was key to email security. We didn’t know for sure if the behavioral models we'd built for adtech could be inverted into email defense, but we had a hypothesis: if we could model what “normal” communication looked like for a business, and analyze all incoming email against that baseline in real time, we could catch novel attacks by spotting what didn't belong.
Fast-forward to today, and frontier AI has put expert-quality, machine-speed social engineering in attackers’ hands. Reconnaissance and lures that used to take weeks can now be produced in minutes, at massive scale.
Email remains a natural target for these attacks because it’s open by design. AI-assisted attackers can imitate CEOs, executives, and vendors convincingly to put themselves inside real, authenticated inboxes, exploiting relationships the target organization already trusts to bypass the usual controls. To the recipient, these emails look exactly like normal business activity. The only thing that gives the compromise away is behavior that doesn't match the person it belongs to.
Profiling “Normal”
When a customer onboards, Abnormal runs a historical download of their environment and ingests millions of signals across email, network, and cloud activity. Behavioral AI builds a profile of how employees communicate. It looks at who they email, their typical login times, which terms and topics they use, their message cadence with a given sender, what device the sender typically uses, and so on. Together, these signals create a unique behavioral “DNA” profile for every single user, role, and tenant. Profiles are stored as privacy-preserving hashed features that never expose raw content.
When a sender acts outside their established baseline—like using a different device—the anomaly is flagged because it deviates from their historical norm. No individual signal is proof of anything. But a concentration of anomalies against a sender's own history produces a high-confidence verdict. AI excels at analyzing thousands of diverse signals across identity and content. As a result, it makes faster and more accurate judgments than humans ever could.
It’s this learned understanding of what is and isn’t “normal” that allows behavioral AI to spot the truly “unknown unknowns.” Vendor impersonation fraud is notoriously difficult to catch, for example, because fake messages often slide into months-long email chains and have no payload signals. We train models to establish the entire context and evaluate the likelihood of fake billing and invoice fraud scenarios to determine whether an email is legitimate or a phishing attempt.
Taking a Load Off Security Teams
False positives have dogged cybersecurity since the industry began. Every product generates alerts, someone has to triage them, and headcount has never kept pace with alert volume. Individually, email false positives seem trivial, which makes clearing them feel like low-value work. However, email has to keep flowing, so dealing with false positives is still essential. For years, that trade-off meant organizations parking entire teams on the least interesting, lowest-return work in the SOC just to keep inboxes moving.
Rules engines make the problem worse. A rule that flags every SharePoint link as suspicious floods the SOC with low-value notifications and wrecks the experience of employees using SharePoint in their daily routines. A rule that treats every invoice as suspicious punishes an accounts payable team that, by definition, handles more invoices than anyone else in the company. You can't blanket-block without breaking the business behind the mailbox.
There’s a high cost of getting alert sensitivity wrong. Undertune and attacks get through. Overtune and you've stopped a legitimate business process in its tracks, and that disruption often costs more than the false positive itself.
Behavioral AI still treats an anomalous invoice or link as suspicious. However, it weighs that suspicion against how often the person in question normally deals with invoices or links, so routine work doesn't get flagged as frequently as work that's out of pattern. The same precision that lets Abnormal catch more also lets it flag less, eliminating much of the downstream investigation and remediation work that plagues SOC teams.
My advice to CISOs evaluating vendors on their signal-to-noise ratio, detection thresholds, and the operational cost of alert fatigue: don’t take a vendor's word for it. Test the product against live data, and hold the vendor accountable for reporting precision. Watch what happens when a false positive does slip through, and whether the vendor steps in to help resolve it or leaves the SOC to sort it out alone. Abnormal samples and labels its own detections continually. It also tracks precision per customer and pushes automatic tuning the moment a rate drifts, working toward what we think of as a “set-and-forget” standard.
Self-learning Attacks Demand Self-learning Defenses
Abnormal catches a lot of threats, but not all of them—no detection engine does. However, the way the system responds to a missed threat is another way we deliver value. Abnormal auto-threat-hunts and works out what happened, then pushes a patch. The same data flows back into how we train our core models, weighting the signals we missed more heavily so the model gets nudged toward catching them in the future.
The harder work is building entirely new detection capability. We used to do that by hand, combing the data, forming a hypothesis, building a feature, training a model, then starting over. Now our own automated pipeline takes every false negative we log and generates a pull request from it, closing the loop from missed attack straight to new detection feature without an engineer writing the initial boilerplate.
Abnormal’s vendor compromise detection is the example we're proudest of. We treat vendor compromise as an identity problem, anchored to one specific person's history, so if a colleague emails you, the model judging that email is trained on their specific sending patterns. Building that kind of narrow, tailored model used to take a machine-learning engineer weeks of manual data work. Increasingly, an AI agent proposes it, builds the dataset, and trains the model itself.
While AI has helped threat actors make attacks faster and more convincing, it has also created opportunities for us to build better detection systems and deliver better outcomes. Today, we’re applying AI agents in new ways, including investigating suspicious traffic in the detection path and automating the work of our machine-learning engineers.
In the detection path, we send slices of suspicious traffic to agents for in-depth review, helping us produce higher-efficacy outcomes for customers. Meanwhile, on the engineering side, agents can now handle much of the manual work involved in training better models. As we’re seeing with vendor compromise detection, we can now hand an AI agent the job of proposing a model, building a dataset, and training itself.
Naturally, that agent is only as good as the tools, environments, and evaluations wrapped around it. This is what we call the “agent harness.” Most agent failures blamed on the model are actually failures of context or tooling. With threat intelligence, behavioral history, and prior logs to hand, agents have a greater probability of reaching high-quality decision capability. The best analogy is a human accountant who has plenty of raw intelligence about how numbers work, but only an abacus to work with. The tool limits their potential—imagine what they could do with Excel!
Abnormal builds the harness once, centrally, so testing a new detection agent never means rebuilding a sandbox and logging pipeline from scratch. Models change constantly. Because the harness remains fixed, a new model can be swapped in without rebuilding anything around it, and the same evaluation suite immediately shows how it performs.
When we started in 2018, email security still operated on the assumption that past threats predict tomorrow's attacks. Today’s attackers, supercharged by AI, now move too fast for that assumption to hold. Behavioral AI meets that speed at a scale of billions of emails, without slowing anything down. The work now is in closing that loop autonomously, before attackers can open a new front door.

