Calendar invites have become a new phishing vector. Abnormal now automatically removes malicious or unwanted events linked to remediated emails, helping organizations maintain clean, trusted calendars.
Through guided setup, customers grant Graph API and PowerShell permissions for both deletion and restoration, enabling recovery if a message is later marked safe.
With this release:
Automatic Removal of Malicious Calendar Invites
Detects and deletes .ics and embedded calendar events tied to remediated messages
Removes malicious and unwanted calendar invites from end-user calendars
New Calendar Invite Attack Insight
Surfaces calendar-based attack activity directly in the Threat Log for faster investigation
By extending remediation to calendar events, Abnormal closes a common phishing gap and ensures Microsoft 365 environments stay safer and easier to manage.

