Abnormal Security | Sumo Logic Docs
Meet Mobot, our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.
The Sumo Logic app for Abnormal Security offers robust monitoring of email security threats. It includes dashboards for an overview of total threats, detailed email threat analysis, and case management by severity and time trends. Key features highlight the threat types, attack vectors, and geolocation of senders, thereby aiding security teams in effectively identifying and responding to incidents. This app helps security teams to effectively monitor, identify, and respond to email-based threats, ensuring robust email security management. It offers actionable insights and visualizations to prioritize and mitigate security incidents efficiently.
Log type
This app uses the Abnormal Security Source to collect threat logs and case logs from the Abnormal Security platform.
Sample log messages
Threat Logs
{
"abxMessageId": -569518315069455395,
"abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-569518315069455395",
"attachmentCount": 0,
"attachmentNames": [],
"attackStrategy": "Unknown Sender",
"attackType": "Phishing: Credential",
"attackVector": "Link",
"attackedParty": "Employee (Other)",
"autoRemediated": false,
"fromAddress": "info@emails.buzzfeed.com",
"fromName": "tasty",
"impersonatedParty": "None / Others",
"internetMessageId": "<91.AF.47440.222B2646@hg.mta2vrest.cc.prd.sparkpost>",
"isRead": false,
"postRemediated": false,
"receivedTime": "2023-05-15T22:29:01Z",
"recipientAddress": "aletheato@abnormalpartner.com",
"remediationStatus": "Marked Safe",
"remediationTimestamp": "2023-05-31T07:53:25.319365Z",
"sentTime": "2023-05-15T22:28:50Z",
"subject": "An Alternative To Avocado Toast",
"threatId": "882c2ea0-5e31-59d8-080f-cb885ba11972",
"toAddresses": [
"aletheato@abnormalpartner.com"
],
"ccEmails": [],
"replyToEmails": [
"newsletters@buzzfeed.com"
],
"returnPath": "bounces+aletheatoh=abnormalpartner.com@emails.buzzfeed.com",
"senderDomain": "emails.buzzfeed.com",
"senderIpAddress": null,
"summaryInsights": [
"Invisible characters found in Email",
"Suspicious Link",
"Unusual Sender",
"Unusual Sender Domain",
"Unusual Reply To"
],
"urlCount": 39,
"urls": [
"https://e.emails.tasty.co/c2/1446:645d40c949dbfe2c590e61d3"
]
}
Case Logs
{
"cases": [
{
"caseId": 1063272,
"description": "Account Compromised",
"severity_level": "HIGH",
"last_modified": "2022-09-06T23:13:58Z"
}
],
"pageNumber": 1,
"total": 1
}
Sample queries
Threats Over Time by Attack Type
_sourceCategory="Labs/AbnormalSecurity" attackType
| json "abxMessageId", "attackType", "attackedParty", "attackStrategy", "attackVector", "autoRemediated", "postRemediated", "remediationStatus" as message_id, attack_type, attacked_party, attack_strategy, attack_vector, auto_remediated, post_remediated, remediation_status nodrop
| where !isBlank(attack_type)
| timeslice 1d
| count by _timeslice, attack_type
| fillmissing timeslice, values all in attack_type
| transpose row _timeslice column attack_type
Cases Over Time by Severity
_sourceCategory="Labs/AbnormalSecurity" caseId severity_level
| json "severity_level", "caseId", "description" as severity, case_id, description nodrop
| where !isBlank(severity)
| timeslice 1h
| count by _timeslice, severity
| fillmissing timeslice, values all in severity
| transpose row _timeslice column severity
Collection configuration and app installation
Depending on the set up collection method, you can configure and install the app in three ways:
- Create a new collector and install the app.
- Use an existing collector and install the app.
- Use existing source and install the app.
Abnormal Security dashboards
All dashboards have a set of filters that you can apply to the entire dashboard. Use these filters to drill down and examine the data to a granular level.
Overview
The Abnormal Security - Overview dashboard provides detailed insights into email threats, highlighting total threats, phishing and malware attacks, and trends over time. It categorizes threats by type, vector, and attack party, and tracks the severity and progression of cases.
Emails
The Abnormal Security - Emails dashboard provides insights into email threat management. It shows the counts of remediated emails, top threat senders and receivers, and email threat activity over time.
Cases
The Abnormal Security - Cases dashboard provides an overview of security cases, showing their severity levels, trends over time, and detailed information on recent cases.
Abnormal Security alerts
| Name | Description | Trigger Type | Alert Condition |
|---|---|---|---|
Email Activity Detected from Embargoed Locations |
This alert is triggered when an email activity is detected from a location identified as high-risk. | Critical | Count > 0 |
High Severity Case Detected |
This alert indicates a high-impact threat that requires immediate investigation. | Critical | Count > 0 |
Malware Detected |
This alert indicates a high-impact malware requiring prompt attention. | Critical | Count > 0 |
Multiple Threat Detections on Single Attacked Party |
This alert assists in identifying high-risk users quickly. | Critical | Count > 0 |
Threat With High Score Detected |
This alert identifies high-impact threats needing immediate investigation. | Critical | Count > 0 |