Solution: AbnormalSecurity
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Abnormal Security |
| Support Tier | Partner |
| Support Link | https://abnormalsecurity.com/contact |
| Categories | Security - Threat Protection |
| Version | 3.0.0 |
| Author | AbnormalSecurity - support@abnormalsecurity.com |
| First Published | 2021-10-20 |
| Last Updated | 2026-06-25 |
| Solution Folder | AbnormalSecurity |
| Marketplace | Azure Marketplace · Popularity: 🟢 High (81%) |
The Abnormal Security solution provides real-time security event ingestion from Abnormal's cloud email security platform into Microsoft Sentinel. Supports both push-based (CCF Push) and pull-based (Azure Functions) connectors. The push connector routes events to per-event-type tables (threats, cases, audit logs, abuse mailbox, posture changes, ATO cases, remediations, vendor cases) using the Codeless Connector Framework.
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 11 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
ABNORMAL_CASES_CL |
AbnormalSecurity | - |
ABNORMAL_SECURITY_ABUSE_MAILBOX_CL 🔶 |
Abnormal Security (Push) | Analytics, Hunting, Workbooks |
ABNORMAL_SECURITY_ATO_CASE_CL 🔶 |
Abnormal Security (Push) | Analytics, Workbooks |
ABNORMAL_SECURITY_AUDIT_LOG_CL 🔶 |
Abnormal Security (Push) | - |
ABNORMAL_SECURITY_CASE_CL 🔶 |
Abnormal Security (Push) | - |
ABNORMAL_SECURITY_LOGS_CL 🔶 |
Abnormal Security (Push) | - |
ABNORMAL_SECURITY_POSTURE_CHANGE_CL 🔶 |
Abnormal Security (Push) | - |
ABNORMAL_SECURITY_REMEDIATION_CL 🔶 |
Abnormal Security (Push) | - |
ABNORMAL_SECURITY_THREAT_LOG_CL 🔶 |
Abnormal Security (Push) | Analytics, Hunting, Workbooks |
ABNORMAL_SECURITY_VENDOR_CASE_CL 🔶 |
Abnormal Security (Push) | Analytics, Hunting, Workbooks |
ABNORMAL_THREAT_MESSAGES_CL 🔶 |
AbnormalSecurity | - |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 14 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 4 |
| Hunting Queries | 4 |
| Parsers | 4 |
| Workbooks | 1 |
| Playbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Abnormal Security - Account Takeover case opened | High | InitialAccess, CredentialAccess | ABNORMAL_SECURITY_ATO_CASE_CL |
| Abnormal Security - High-risk email attack detected | High | InitialAccess | ABNORMAL_SECURITY_THREAT_LOG_CL |
| Abnormal Security - User-reported email judged malicious | Medium | InitialAccess | ABNORMAL_SECURITY_ABUSE_MAILBOX_CL |
| Abnormal Security - Vendor compromise case detected | Medium | InitialAccess | ABNORMAL_SECURITY_VENDOR_CASE_CL |
| Name | Tactics | Tables Used |
|---|---|---|
| Abnormal Security - Most-targeted recipients | InitialAccess, Reconnaissance | ABNORMAL_SECURITY_THREAT_LOG_CL |
| Abnormal Security - Newly observed vendor domains | InitialAccess | ABNORMAL_SECURITY_VENDOR_CASE_CL |
| Abnormal Security - Threats still in the mailbox | InitialAccess | ABNORMAL_SECURITY_THREAT_LOG_CL |
| Abnormal Security - User-reported email campaigns | InitialAccess | ABNORMAL_SECURITY_ABUSE_MAILBOX_CL |
| Name | Tables Used |
|---|---|
| AbnormalSecurityOverview | ABNORMAL_SECURITY_ABUSE_MAILBOX_CLABNORMAL_SECURITY_ATO_CASE_CLABNORMAL_SECURITY_THREAT_LOG_CLABNORMAL_SECURITY_VENDOR_CASE_CL |
| Name | Description | Tables Used |
|---|---|---|
| Abnormal Security - Add Incident Comment | This playbook is triggered when a Microsoft Sentinel incident is created. It adds a comment to the i... | - |
| Name | Description | Tables Used |
|---|---|---|
| AbnormalSecurityAbuseMailbox | - | ABNORMAL_SECURITY_ABUSE_MAILBOX_CL (read) |
| AbnormalSecurityAtoCases | - | ABNORMAL_SECURITY_ATO_CASE_CL (read) |
| AbnormalSecurityThreatLog | - | ABNORMAL_SECURITY_THREAT_LOG_CL (read) |
| AbnormalSecurityVendorCases | - | ABNORMAL_SECURITY_VENDOR_CASE_CL (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.1.0 | 05-06-2026 | Added Microsoft Sentinel content for the CCF Push connector to meet MISA integration criteria: four scheduled Analytic Rules (high-risk email attack, account takeover, user-reported malicious email, vendor compromise) with entity mappings and MITRE ATT&CK techniques; four Hunting Queries; four Parsers normalizing the per-event-type tables to friendly column names; an Abnormal Security Overview Workbook; and an incident-comment Playbook. |
| 3.0.0 | 08-05-2026 | Added CCF Push connector with multi-table routing (9 tables), DeployPushConnectorButton, and OAuth 2.0 authentication. Legacy Azure Functions connector retained for backward compatibility. Full MLA column parity: renamed abx_body_* columns to abx_body_abx_body_, added abx_body_abx_metadata_ columns across all 9 streams. Fixed DCR transforms with explicit tostring(abx_body) and tostring(abx_metadata) conversions. Fixed fallback stream to Custom-ABNORMAL_SECURITY_LOGS_CL. Added top-level workspace/tables resources in mainTemplate for direct ARM deployment. |
| 2.0.1 | 29-06-2023 | Renaming Azure Function to Azure Functions in Data Connector Description and Updated the python runtime version to 3.11 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊