Meet [**Mobot**](/content/help/docs/search/mobot/index.html), our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.

The Sumo Logic app for Abnormal Security offers robust monitoring of email security threats. It includes dashboards for an overview of total threats, detailed email threat analysis, and case management by severity and time trends. Key features highlight the threat types, attack vectors, and geolocation of senders, thereby aiding security teams in effectively identifying and responding to incidents. This app helps security teams to effectively monitor, identify, and respond to email-based threats, ensuring robust email security management. It offers actionable insights and visualizations to prioritize and mitigate security incidents efficiently.

## Log type

This app uses the Abnormal Security Source to collect [threat logs](https://app.swaggerhub.com/apis-docs/abnormal-security/abx/1.4.1#/Threats/get_threats__threatId_) and [case logs](https://app.swaggerhub.com/apis-docs/abnormal-security/abx/1.4.1#/Cases/get_cases) from the Abnormal Security platform.

### Sample log messages

**Threat Logs**

```json
{
    "abxMessageId": -569518315069455395,
    "abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-569518315069455395",
    "attachmentCount": 0,
    "attachmentNames": [],
    "attackStrategy": "Unknown Sender",
    "attackType": "Phishing: Credential",
    "attackVector": "Link",
    "attackedParty": "Employee (Other)",
    "autoRemediated": false,
    "fromAddress": "info@emails.buzzfeed.com",
    "fromName": "tasty",
    "impersonatedParty": "None / Others",
    "internetMessageId": "<91.AF.47440.222B2646@hg.mta2vrest.cc.prd.sparkpost>",
    "isRead": false,
    "postRemediated": false,
    "receivedTime": "2023-05-15T22:29:01Z",
    "recipientAddress": "aletheato@abnormalpartner.com",
    "remediationStatus": "Marked Safe",
    "remediationTimestamp": "2023-05-31T07:53:25.319365Z",
    "sentTime": "2023-05-15T22:28:50Z",
    "subject": "An Alternative To Avocado Toast",
    "threatId": "882c2ea0-5e31-59d8-080f-cb885ba11972",
    "toAddresses": [
        "aletheato@abnormalpartner.com"
    ],
    "ccEmails": [],
    "replyToEmails": [
        "newsletters@buzzfeed.com"
    ],
    "returnPath": "bounces+aletheatoh=abnormalpartner.com@emails.buzzfeed.com",
    "senderDomain": "emails.buzzfeed.com",
    "senderIpAddress": null,
    "summaryInsights": [
        "Invisible characters found in Email",
        "Suspicious Link",
        "Unusual Sender",
        "Unusual Sender Domain",
        "Unusual Reply To"
    ],
    "urlCount": 39,
    "urls": [
        "https://e.emails.tasty.co/c2/1446:645d40c949dbfe2c590e61d3"
    ]
}
```

**Case Logs**

```json
{
    "cases": [
        {
            "caseId": 1063272,
            "description": "Account Compromised",
            "severity_level": "HIGH",
            "last_modified": "2022-09-06T23:13:58Z"
        }
    ],
    "pageNumber": 1,
    "total": 1
}
```

### Sample queries

**Threats Over Time by Attack Type**

```sumo
_sourceCategory="Labs/AbnormalSecurity" attackType

| json "abxMessageId", "attackType", "attackedParty", "attackStrategy", "attackVector", "autoRemediated", "postRemediated", "remediationStatus" as message_id, attack_type, attacked_party, attack_strategy, attack_vector, auto_remediated, post_remediated, remediation_status nodrop

| where !isBlank(attack_type)
| timeslice 1d
| count by _timeslice, attack_type
| fillmissing timeslice, values all in attack_type
| transpose row _timeslice column attack_type
```

**Cases Over Time by Severity**

```sumo
_sourceCategory="Labs/AbnormalSecurity" caseId severity_level

| json "severity_level", "caseId", "description" as severity, case_id, description nodrop

| where !isBlank(severity)
| timeslice 1h
| count by _timeslice, severity
| fillmissing timeslice, values all in severity
| transpose row _timeslice column severity
```

### Collection configuration and app installation

Depending on the set up collection method, you can configure and install the app in three ways:

- **Create a new collector and install the app**.
- **Use an existing collector and install the app**.
- **Use existing source and install the app**.

### Abnormal Security dashboards

All dashboards have a set of filters that you can apply to the entire dashboard. Use these filters to drill down and examine the data to a granular level.

### Overview

The **Abnormal Security - Overview** dashboard provides detailed insights into email threats, highlighting total threats, phishing and malware attacks, and trends over time. It categorizes threats by type, vector, and attack party, and tracks the severity and progression of cases.

### Emails

The **Abnormal Security - Emails** dashboard provides insights into email threat management. It shows the counts of remediated emails, top threat senders and receivers, and email threat activity over time.

### Cases

The **Abnormal Security - Cases** dashboard provides an overview of security cases, showing their severity levels, trends over time, and detailed information on recent cases.

### Abnormal Security alerts

| Name | Description | Trigger Type | Alert Condition |
| --- | --- | --- | --- |
| `Email Activity Detected from Embargoed Locations` | This alert is triggered when an email activity is detected from a location identified as high-risk. | Critical | Count > 0 |
| `High Severity Case Detected` | This alert indicates a high-impact threat that requires immediate investigation. | Critical | Count > 0 |
| `Malware Detected` | This alert indicates a high-impact malware requiring prompt attention. | Critical | Count > 0 |
| `Multiple Threat Detections on Single Attacked Party` | This alert assists in identifying high-risk users quickly. | Critical | Count > 0 |
| `Threat With High Score Detected` | This alert identifies high-impact threats needing immediate investigation. | Critical | Count > 0 |
