Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

About the Device

Abnormal Inbound Email Security stops advanced attacks with a fundamentally different approach. Abnormal uses behavioral AI and ML models to stop the full spectrum of email attacks.

  1. Baselines known good behavior across employees and vendors with an AI-based anomaly detection engine.

  2. Offers explainable attack insights with in-depth reviews referencing email forensics like the location and timing, frequency of communication, topic and tone, and intent of the email attack.

  3. Deploys in minutes via API. No configuration or policies required.

  4. Monitors each vendor for risk indicators and automatically adapts protection to block attacks from compromised partners.

Device Information

 Entity

Particulars

Vendor Name

Abormal Security

Product Name

Inbound Email Security

Type of Device

Cloud

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol

Log Collection Method

Data Source

Abnormal Security

 ABNORMAL_SECURITY

API-Pull

CyberHub

https://app.swaggerhub.com/apis/abnormal-security/abx/1.4.0

Device Configuration

Complete these integration steps to get your API access token:

  1. Log in to the Abnormal Portal.

  2. Click Settings in the left navigation menu.

  3. Click Integrations in the settings menu.

image-20231120-103946.png
  1. Scroll down to the Additional Integrations section and click Connect on the Abnormal REST API card to display an integration page for your organization.

image-20231120-104017.png
  1. The integration page displays a unique API access token. Please copy and share it with AMxDR.

image-20231120-104126.png
  1. In the IP Safelist field, enter the <CYBERHUB_IP> Address from where API call are being made.

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

URL

https://api.abnormalplatform.com

Common URL for all customer

Customer Name

<EMPTY>

Name of the Customer to identify Origin

API Token

<EMPTY>

API Token provided by customer in device configuration

  • No labels