Skip to main content
Abnormal Extends Behavioral AI to Identity and AI SecurityLearn more

Jul 28, 2026

Identity Threat Protection: Prevent Newsworthy Breaches

The same behavioral AI that already protects your inbox now extends to protecting identity in your organization.

On August 3, Abnormal is launching Identity Threat Protection, extending the same behavioral AI that already protects 4,500+ organizations to the identity layer. It correlates email, IdP, and SaaS signals, and is built to prevent, detect, and remediate identity breaches that traditional identity tools can miss.

For nearly a decade, Abnormal built its behavioral AI around a single surface: email. Identity Threat Protection is one of three new products extending that platform beyond the inbox, using behavioral AI to correlate identity, email, and SaaS signals into one model, built to catch what each signal alone might miss. It's a fundamentally larger scope of protection than anything Abnormal has offered before.

The modern identity attack surface opens the door to multi-channel attacks that can target an organization's sensitive data and systems. In the past year, the attacks executed by the Scattered Spider threat group served as powerful examples that demonstrated the limits of existing identity defenses, as attackers often spend days or weeks inside environments undetected. Attacks like these look like normal identities doing normal things, which is why ITDR tools are deployed by 85% of organizations, yet 55% of them still experienced an identity compromise in the last 12 months.

Abnormal is applying its behavioral AI to defend against identity threats that expose organizations. The result is an understanding of attacks end-to-end and ultimately shifting security left to prioritize risks before a breach occurs.

Note: Identity Threat Protection will officially go GA at Black Hat USA 2026 on August 3, 2026. This blog serves as a preview of those capabilities.

Inside Identity Threat Protection

Identity Threat Protection is designed to prevent, detect, and remediate identity threats that a rules engine or static risk score can miss, drawing on seven years of behavioral analysis that started with Abnormal's original account takeover protection in 2019.

Rather than evaluating identity activity discretely across a collection of different tools, Identity Threat Protection combines email, IdP, and SaaS signals into one picture. A login might check out on its own. An email might read like a normal message between two coworkers. A sign-in location might look perfectly fine. But looked at together, those same signals can reveal an attack that each signal alone might miss.

Posture monitoring and detection run on that same combined view, so a real exposure can be flagged before attackers exploit it, and if something does get through, the detection points straight back to the gap that made it possible.

Identity Security Posture Management

Identity Security Posture Management surfaces identity misconfigurations, including missing MFA, dormant privileged accounts, and unmanaged device sign-ins, ranked by real attack susceptibility instead of policy severity alone, so teams can know exactly which gaps attackers would exploit and what to fix first.

For a security team drowning in thousands of theoretical findings, this turns a generic posture checklist into a short, defensible priority list to prevent risks from impacting an organization.

ITP Screenshots image 3

It can surface that a dormant admin account with no MFA and no login in six months ranks above a routine misconfiguration on an account no attacker would realistically target.

Threat Library

Identity Threat Protection provides a dynamic library detailing real identity attack scenarios aligned to the MITRE framework, including adversary-in-the-middle (AiTM) phishing, device code phishing, OAuth abuse, MFA fatigue, privilege escalation, and more, each mapped to the organization's environment. Behavioral detection across the full attack sequence provides contextual case timelines and remediation actions. This allows a CISO or SOC analyst to quickly verify whether they're vulnerable or protected against the latest identity threats they hear about in the news.

ITP Screenshots image 1

As opposed to correlating events across disparate systems, Identity Threat Protection detects Device Code Phishing attacks by correlating behavioral anomalies across the entire attack chain: the initial email masquerading as a virtual meeting invite, the authentication via threat-actor-generated device code, and finally the new MFA device registration and mailbox access, while also mapping the specific posture gaps that allowed the attack to succeed in the first place.

Identity Graph and Visibility

Identity Threat Protection visualizes human and non-human identities, including service accounts, their access, and what their normal behaviors and relationships are. This includes flagging orphaned identities and long-lived credentials needing rotation. Identity teams can now turn invisible machine identities into something ownable.

ITP Screenshots image 4

Security teams often can't see how far a single privileged identity actually reaches, but Identity Graph shows the service accounts that an identity owns, revealing the blast radius in one view instead of piecing it together account by account after a breach.

Adaptive Identity Reset

The helpdesk is hardened against social engineering by evaluating every password and MFA reset request against behavioral patterns before granting access. Users will be challenged in escalating levels of scrutiny, starting with knowledge-based questions.

Scattered Spider helpdesk impersonation techniques work precisely because agents have no reliable way to verify the person on the other end of the call. Adaptive Identity Reset helps close that gap by verifying identity before an agent ever has to, so a convincing voice and a stolen employee ID number should no longer be enough to get inside. This enables Helpdesk teams to be more efficient, processing fewer manual verification tickets as low-risk requests clear automatically.

ITP Screenshots image 2

Adaptive Identity Reset can flag an MFA reset request that comes from the right person's usual city but the wrong device and browser, while a routine password reset from someone's known device and location clears without friction.

Identity Defense that Connects the Dots

Identity security has spent years hardening the login and relying on a collection of tools to monitor identity, but that's no longer enough.

By correlating email, IdP, and SaaS signals through one behavioral model, Abnormal Identity Threat Protection catches what point tools often miss: attacks that look legitimate at every step, because typically, no step is ever checked against the others.

For CISOs, that means confidence that their team is covered against identity threats they read about in the news, and a clear, defensible answer when the board asks whether the organization is exposed. For SOC teams, it means one case with a clear timeline and a direct remediation path, instead of chasing an attacker across four consoles. For identity and IT teams, it means the invisible half of the identity estate—orphaned accounts, dormant admins, unmanaged service accounts—finally becomes visible and ownable.

With Identity Threat Protection, Abnormal extends nearly a decade of behavioral modeling beyond the inbox, applying it to the identity layer, meeting identity threats with the same intelligence that already protects you from the attacks that start them.

To learn how Identity Threat Protection can help your organization reduce identity risk, connect with your Abnormal team or request inside access.

Request Inside Access

The above is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Abnormal AI’s products remains at the sole discretion of Abnormal AI and is subject to change.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.