Abnormal now gives security teams a more detailed behavioral profile for identities in their environment, surfacing sign-in patterns, activity history, and identity relationships.
What's new:
- Overview tab: A single-screen view of sign-in patterns, network locations, and device/browser/OS/app usage for any identity, so analysts can immediately see what normal looks like for that person.
- Activity feed: A complete, filterable history of sign-in events for each identity. Filter by anomalies, suspicious events, or threats, with a direct link to the associated case.
- Identity Graph*: An interactive map of a person's identities, group memberships, and roles across platforms, showing the full blast radius of a given account.
- Non-Human Identity ownership*: Visibility into the service principals, credentials, and OAuth grants tied to each person, connecting human identity risk to non-human identity risk in a single profile.
Together, these updates consolidate identity investigation into one filterable feed, so analysts no longer have to jump between tools to build context on a suspicious identity.

Availability:
- Full visibility of device/browser/OS/app usage requires Microsoft and/or Okta sign-in ingestion.
- *Identity Graph and NHI Identity coverage requires Identity Threat Protection module
