Combining the Power of Behavioral AI with Industry-Leading XDR Capabilities
CrowdStrike and Abnormal share a common mission to prevent cybercrime and make the connected cloud a safer place for business.
Benefits
Faster, More Effective Response with Abnormal and CrowdStrike
How It Works
Integration Features
Discover and Remediate Compromised Email Accounts and Endpoints
When CrowdStrike detects a potential incident, such as a privileged user with failed authentication attempts signing in from a new location, CrowdStrike will trigger Abnormal to generate an Account Takeover (ATO) case for further investigation.
Enrich CrowdStrike Detection with Email Account Takeover Signals
When Abnormal detects a potentially compromised email account, CrowdStrike will automatically add the account to a Watched Users list. Security analysts may configure Falcon Fusion workflows for Watched Users that automate response actions to mitigate downstream risk of email account takeovers, such as enforcing multifactor authentication.
Enhance Threat Detections with XDR Ingestion
Seamlessly ingest Abnormal's advanced email attack detections into the CrowdStrike platform to improve cross-domain visibility of email-based attacks. This integration ingests key indicators about Abnormal attack detections from Threat Log, alerts of new, potentially compromised vendors in Vendor Cases, and user-reported phishing emails within Abuse Mailbox Automation.
Discover and Remediate Compromised Email Accounts and Endpoints
Only Abnormal and CrowdStrike can tie together a consolidated view of employee behavior across endpoint, Active Directory, and email solutions—empowering high-fidelity, cross-functional security investigations.

Customer Impact
What Security Leaders Say
“Abnormal's automation gives our analysts time back to work on other projects, and the fact that it's API-based gives us flexibility to tie in other applications and their data.”
John Roeser
Senior Manager, Information Security, Domino's
“Our goals are to get away from being so reliant on human judgment and leverage AI to be proactive. Abnormal helps us with those goals.”
Corey Kaemming
Senior Director, Information Security, Valvoline
AbnormalはFortune 500の25%以上を含む4,500社以上のお客様にご利用いただいています。
Related Resources
See the Integration in Action
Unify your email and endpoint security with bi-directional threat intelligence.



