Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Abnormal

ASecurity

Expert agent for Abnormal Security. Covers API-based behavioral AI email protection, BEC detection, vendor email compromise, account takeover, and native M365/Google Workspace integration without MX changes. WHEN: \"Abnormal Security\", \"Abnormal AI\", \"behavioral email security\", \"BEC detection\", \"vendor email compromise\", \"VEC\", \"API email security\", \"account takeover email\", \"Abnormal SIEM\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
securityrustgonodeazuregitapisecurity

Works with

api

Security Analysis

A100/100

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill abnormal --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Abnormal?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Abnormal
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-abnormal/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-abnormal)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: abnormal
description: "Expert agent for Abnormal Security. Covers API-based behavioral AI email protection, BEC detection, vendor email compromise, account takeover, and native M365/Google Workspace integration without MX changes. WHEN: \"Abnormal Security\", \"Abnormal AI\", \"behavioral email security\", \"BEC detection\", \"vendor email compromise\", \"VEC\", \"API email security\", \"account takeover email\", \"Abnormal SIEM\"."
license: MIT
---

# Abnormal Security

This skill covers Abnormal Security's AI-native email security platform. Abnormal uses behavioral AI and API integration (no MX change required) to detect sophisticated attacks that evade traditional secure email gateways — primarily BEC, vendor email compromise, supply chain fraud, and account takeover.

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Deployment** — API integration, permissions, M365/Google setup
   - **BEC/VEC detection** — Behavioral AI, attack signals, detection tuning
   - **Account takeover (ATO)** — Detection, remediation, signals
   - **Investigation** — Case analysis, threat log review, SIEM integration
   - **Policy/configuration** — Detection thresholds, safe senders, remediation actions
   - **Reporting** — Attack briefings, SOC feed, executive reporting

2. **Identify the mail platform** — Abnormal supports Microsoft 365 and Google Workspace. Deployment and detection capabilities vary.

3. **Apply behavioral AI context** — Abnormal's core differentiation is behavioral modeling. Understanding the signals that drive its detections is key to investigation and tuning.

## Deployment Architecture

### No MX Change Required

Abnormal connects entirely via platform APIs — no MX record modification, no DNS change, no disruption to mail flow.

**Integration method:**
- **M365:** Microsoft Graph API (via Azure App Registration with admin consent)
- **Google Workspace:** Gmail API + Directory API (via Service Account with domain-wide delegation)

**Deployment time:** 30-60 minutes for initial connection; detection and baselining begin immediately; full behavioral model maturity in 7-14 days.

### M365 Integration (Microsoft Graph API)

**Required Azure App Registration permissions:**
```
Microsoft Graph - Application Permissions:
- Mail.ReadWrite            # Read and delete messages (for remediation)
- Mail.Read                 # Read message content for analysis
- MailboxSettings.Read      # Detect forwarding rules, OOF, delegates
- User.Read.All             # User directory, roles, attributes
- Group.Read.All            # Group membership (detect unusual recipients)
- AuditLog.Read.All         # Sign-in logs for ATO detection
- Directory.Read.All        # Org structure (reporting relationships)
- SecurityEvents.Read.All   # Microsoft security alerts correlation
- Policy.Read.All           # Conditional access, MFA status
```

**Data accessed:**
- Email messages (metadata + content for analysis)
- User sign-in logs (for ATO detection via impossible travel, new locations)
- Mailbox rules (detect suspicious forwarding rules post-compromise)
- Calendar, Teams (extended behavioral context for Abnormal's higher tiers)

### Google Workspace Integration

**Required Service Account scopes:**
```
https://www.googleapis.com/auth/gmail.readonly        # Read messages
https://www.googleapis.com/auth/gmail.modify          # Remediate messages
https://www.googleapis.com/auth/admin.directory.user.readonly  # User directory
https://www.googleapis.com/auth/admin.reports.audit.readonly   # Audit logs
```

**Domain-wide delegation** required — the service account must be authorized to act on behalf of all users in the organization.

## Behavioral AI Detection Model

### Identity Graph and Behavioral Baseline

Abnormal builds a unique behavioral profile for every identity in the organization (employees, contractors, vendors, third parties who email your users).

**Per-identity signals profiled:**
- Typical email communication patterns (who they email, frequency, times)
- Writing style (vocabulary, sentence structure, formality)
- Geographic sending locations
- Device and browser fingerprints
- Time-of-day patterns
- Communication relationship graph (have these two people emailed before?)
- Subject line patterns
- Link and attachment sending behaviors

**Organization-level signals:**
- Organizational hierarchy (reporting relationships from directory)
- Finance team members and roles
- Common payment/invoice processes
- Internal communication norms

**Baselining period:** Abnormal analyzes historical email to build baselines. New messages are scored against this model.

### BEC Detection Signals

Abnormal's BEC detection identifies attacks based on behavioral deviation, not signatures.

**Social engineering signals:**
- Urgency + secrecy combination ("please handle this before EOD, don't mention to others")
- Unusual action request (wire transfer, gift cards, invoice payment change)
- Financial keywords in context of unusual sender relationship
- Request to take action outside normal business processes

**Identity signals:**
- Sender's writing style deviates significantly from established baseline
- Message tone inconsistent with prior communication history
- Sender's normal patterns (location, time, device) not matching this message
- Reply-to address different from From address (common in CEO fraud)

**Relationship signals:**
- No prior communication between sender and recipient
- Low-frequency relationship suddenly sending high-importance financial request
- Message references a recent company event (acquisition, merger) — indicates targeted research

**Technical signals:**
- SPF/DKIM/DMARC failures (surface to detection model, though Abnormal also catches authenticated BEC)
- Domain lookalike (Abnormal includes character analysis of sender domain)
- Free email account impersonating executive (exec@gmail.com instead of exec@company.com)

### Vendor Email Compromise (VEC) Detection

VEC is among the hardest attacks to detect because the attacker has compromised a legitimate vendor's email account — DKIM passes, the domain is real, the sender is trusted.

**Abnormal's VEC approach:**

**Vendor profile baseline:**
Abnormal builds behavioral models for frequent external senders, not just internal identities. The model learns:
- How vendor X normally formats invoice emails
- What attachments they typically send
- Their normal account numbers and payment references
- Communication patterns with your AP team

**VEC attack signals:**
- Account number, routing number, or payment instructions changed from established pattern
- Request to update payment details (deviates from established vendor behavior)
- Message sent from a new geographic location or IP range
- Slight writing style change (attacker's style vs. victim's normal style)
- Request urgency or deadline unusual for this vendor relationship
- New email thread referencing invoice (not a reply to existing thread)

**VEC investigation flow:**
1. Abnormal flags message as VEC risk with explanation
2. Analyst reviews: What changed from established pattern?
3. Verify via out-of-band channel (phone vendor using known number)
4. If confirmed: Remediate message, alert AP team, notify vendor

### Account Takeover (ATO) Detection

Abnormal monitors post-authentication behaviors to detect when a legitimate account has been compromised.

**ATO trigger signals:**
- **Impossible travel:** Login from city A, then city B, within a timeframe impossible by travel (e.g., New York + London within 2 hours)
- **New country:** Login from a country the user has never accessed from
- **New ASN/IP:** Access from an ISP or IP range not seen in user's history
- **Anonymous network:** Login through Tor exit node, known VPN exit IP, or datacenter IP
- **MFA bypass patterns:** Conditional access policy change, legacy authentication enabled
- **Unusual session properties:** Unusual user agent, new device fingerprint

**Post-compromise indicators:**
- Inbox rule created: Forward all email to external address
- Inbox rule created: Delete messages containing "phish", "fraud", "security", "unusual" (attacker hiding evidence)
- Delegate access granted to external account
- Mass email sent to external recipients
- OAuth app granted mail access permissions
- Password change or MFA device added

**Abnormal's ATO response:**
- Alert generated with full compromise chain (login signals + behavioral changes)
- Recommended actions: Disable user session, force password reset, review inbox rules
- Integration with identity providers (Entra ID, Okta) for automated account suspension

## Attack Analysis and Case Management

### Abnormal Portal — Case Review

Each detected attack creates a case in the Abnormal portal with:

**Attack summary:**
- Attack type (BEC, VEC, ATO, phishing, malware, etc.)
- Reason for detection (which signals triggered)
- Confidence score
- Remediation status

**Why Abnormal flagged it:**
Abnormal provides plain-language explanation of detection reasoning:
> "This message was flagged because the sender 'CEO Name' has never previously emailed the recipient 'AP Manager', the request involves a wire transfer of $47,000, and the reply-to address (attacker@gmail.com) differs from the From address."

**Message details:**
- Full email content (headers, body, attachments)
- Authentication results (SPF/DKIM/DMARC)
- Sender behavioral profile deviation
- Similar historical messages from sender for comparison

**Timeline view:**
Multi-stage attacks (e.g., initial reconnaissance, then wire transfer request) shown in a unified timeline.

### Remediation Actions

**Automatic remediation:**
Abnormal can automatically move detected attacks to junk or delete them, configurable by attack type and confidence threshold.

```
High-confidence BEC (score > 90): Auto-move to junk
High-confidence phishing with malware: Auto-delete
Medium-confidence: Hold for analyst review
```

**Manual remediation:**
From the case, analysts can:
- Move message to junk or delete
- Add sender to blocklist
- Trigger user notification
- Initiate ATO response workflow

**Remediation API:**
```
POST /v1/cases/{caseId}/actions/remediate
Authorization: Bearer {api_key}
Body: {"action": "move_to_junk"}
```

## SIEM and SOAR Integration

### Abnormal Security API

REST API for integration with SIEM/SOAR platforms.

**Authentication:**
```
Authorization: Bearer {api_key}
```
API keys generated in Abnormal portal under Settings → Integrations.

**Key endpoints:**
```
GET  /v1/cases                          # List attack cases
GET  /v1/cases/{caseId}                # Case details
GET  /v1/cases/{caseId}/messages        # Messages in case
POST /v1/cases/{caseId}/actions         # Remediate case
GET  /v1/threats                        # Threat feed
GET  /v1/employee_change_events         # ATO-related identity events
```

**Webhooks:**
Abnormal supports webhooks for real-time alert delivery to SIEM:
```
POST {webhook_url}
Payload: {case_id, attack_type, severity, detection_time, remediation_status}
```

**SIEM integrations (native):**
- Splunk (Abnormal App for Splunk)
- Microsoft Sentinel (Abnormal connector)
- Palo Alto Cortex XSOAR (playbook integration)
- ServiceNow (ticket creation)

### SOC Email Threat Feed

Abnormal provides a SOC-level threat feed with:
- All detected attacks with full context
- IOCs (sender IPs, domains, URLs, file hashes)
- MITRE ATT&CK tactic mapping for each attack
- Time to detect and time to remediate metrics

**Splunk integration example:**
```
index=abnormal_security source="abnormal:cases"
| where attack_type="BEC"
| stats count by sender_domain
| sort -count
```

## Reporting and Executive Visibility

### Attack Briefings

Abnormal generates automated attack briefings (daily/weekly) showing:
- Total attacks detected and remediated
- BEC attacks by type (wire fraud, gift cards, credential phishing)
- Estimated financial risk prevented (calculated from attack context)
- Top targeted employees
- Attack trend vs. previous period

### CISO Dashboard

Board-ready metrics:
- Email risk posture score
- BEC risk by department
- Top 10 most targeted employees
- Vendor ecosystem risk (VEC exposure)
- ATO events detected

## Abnormal vs. SEG Comparison

| Capability | SEG (Proofpoint/Mimecast) | Abnormal |
|---|---|---|
| Deployment | MX record change required | API only, no MX change |
| Detection method | Signature + heuristics + sandbox | Behavioral AI |
| BEC (display name) | Rule-based, limited | Behavioral — catches sophisticated variants |
| Vendor email compromise | Limited (sender is legitimate) | Core strength |
| Account takeover | Cannot detect | Detects via behavioral + sign-in analysis |
| Internal email scanning | No (only processes inbound via MX) | Yes (full internal visibility via API) |
| URL rewriting | Yes | No (post-delivery model) |
| Pre-delivery blocking | Yes | No (post-delivery detection + remediation) |
| On-prem Exchange support | Yes | No (requires M365 or Google Workspace API) |

**Best practice:** Deploy Abnormal alongside EOP/Defender for O365 (or alongside a SEG). The layers complement each other — SEG handles bulk spam, malware, and signature-based phishing; Abnormal handles behavioral BEC, VEC, and ATO that evades signature-based tools.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes
View all in security →