Abnormal Security | Sumo Logic Docs

Meet Mobot, our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.

The Sumo Logic app for Abnormal Security offers robust monitoring of email security threats. It includes dashboards for an overview of total threats, detailed email threat analysis, and case management by severity and time trends. Key features highlight the threat types, attack vectors, and geolocation of senders, thereby aiding security teams in effectively identifying and responding to incidents. This app helps security teams to effectively monitor, identify, and respond to email-based threats, ensuring robust email security management. It offers actionable insights and visualizations to prioritize and mitigate security incidents efficiently.

Log type

This app uses the Abnormal Security Source to collect threat logs and case logs from the Abnormal Security platform.

Sample log messages

Threat Logs

{
    "abxMessageId": -569518315069455395,
    "abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-569518315069455395",
    "attachmentCount": 0,
    "attachmentNames": [],
    "attackStrategy": "Unknown Sender",
    "attackType": "Phishing: Credential",
    "attackVector": "Link",
    "attackedParty": "Employee (Other)",
    "autoRemediated": false,
    "fromAddress": "info@emails.buzzfeed.com",
    "fromName": "tasty",
    "impersonatedParty": "None / Others",
    "internetMessageId": "<91.AF.47440.222B2646@hg.mta2vrest.cc.prd.sparkpost>",
    "isRead": false,
    "postRemediated": false,
    "receivedTime": "2023-05-15T22:29:01Z",
    "recipientAddress": "aletheato@abnormalpartner.com",
    "remediationStatus": "Marked Safe",
    "remediationTimestamp": "2023-05-31T07:53:25.319365Z",
    "sentTime": "2023-05-15T22:28:50Z",
    "subject": "An Alternative To Avocado Toast",
    "threatId": "882c2ea0-5e31-59d8-080f-cb885ba11972",
    "toAddresses": [
        "aletheato@abnormalpartner.com"
    ],
    "ccEmails": [],
    "replyToEmails": [
        "newsletters@buzzfeed.com"
    ],
    "returnPath": "bounces+aletheatoh=abnormalpartner.com@emails.buzzfeed.com",
    "senderDomain": "emails.buzzfeed.com",
    "senderIpAddress": null,
    "summaryInsights": [
        "Invisible characters found in Email",
        "Suspicious Link",
        "Unusual Sender",
        "Unusual Sender Domain",
        "Unusual Reply To"
    ],
    "urlCount": 39,
    "urls": [
        "https://e.emails.tasty.co/c2/1446:645d40c949dbfe2c590e61d3"
    ]
}

Case Logs

{
    "cases": [
        {
            "caseId": 1063272,
            "description": "Account Compromised",
            "severity_level": "HIGH",
            "last_modified": "2022-09-06T23:13:58Z"
        }
    ],
    "pageNumber": 1,
    "total": 1
}

Sample queries

Threats Over Time by Attack Type

_sourceCategory="Labs/AbnormalSecurity" attackType

| json "abxMessageId", "attackType", "attackedParty", "attackStrategy", "attackVector", "autoRemediated", "postRemediated", "remediationStatus" as message_id, attack_type, attacked_party, attack_strategy, attack_vector, auto_remediated, post_remediated, remediation_status nodrop

| where !isBlank(attack_type)
| timeslice 1d
| count by _timeslice, attack_type
| fillmissing timeslice, values all in attack_type
| transpose row _timeslice column attack_type

Cases Over Time by Severity

_sourceCategory="Labs/AbnormalSecurity" caseId severity_level

| json "severity_level", "caseId", "description" as severity, case_id, description nodrop

| where !isBlank(severity)
| timeslice 1h
| count by _timeslice, severity
| fillmissing timeslice, values all in severity
| transpose row _timeslice column severity

Collection configuration and app installation

Depending on the set up collection method, you can configure and install the app in three ways:

Abnormal Security dashboards

All dashboards have a set of filters that you can apply to the entire dashboard. Use these filters to drill down and examine the data to a granular level.

Overview

The Abnormal Security - Overview dashboard provides detailed insights into email threats, highlighting total threats, phishing and malware attacks, and trends over time. It categorizes threats by type, vector, and attack party, and tracks the severity and progression of cases.

Emails

The Abnormal Security - Emails dashboard provides insights into email threat management. It shows the counts of remediated emails, top threat senders and receivers, and email threat activity over time.

Cases

The Abnormal Security - Cases dashboard provides an overview of security cases, showing their severity levels, trends over time, and detailed information on recent cases.

Abnormal Security alerts

Name Description Trigger Type Alert Condition
Email Activity Detected from Embargoed Locations This alert is triggered when an email activity is detected from a location identified as high-risk. Critical Count > 0
High Severity Case Detected This alert indicates a high-impact threat that requires immediate investigation. Critical Count > 0
Malware Detected This alert indicates a high-impact malware requiring prompt attention. Critical Count > 0
Multiple Threat Detections on Single Attacked Party This alert assists in identifying high-risk users quickly. Critical Count > 0
Threat With High Score Detected This alert identifies high-impact threats needing immediate investigation. Critical Count > 0