tools
Abnormal Account Takeover Protection
AI security service that detects compromised email and SaaS accounts, investigates takeover activity, and automates account remediation.

Abnormal Account Takeover Protection learns normal sign-in, device, email, and user behavior, then detects deviations associated with credential theft, token abuse, MFA bypass, and lateral phishing.
It creates behavioral case timelines, correlates identity and email signals, and can revoke sessions, block access, force password resets, and move lateral phishing messages to hidden folders. It integrates with Microsoft 365, Google Workspace, Entra ID, Okta, and other cloud applications through APIs. The site does not list public pricing and directs buyers to request a demo.
Features
- Learns per-user sign-in, device, email, and behavior baselines
- Detects MFA bypass, token theft, credential stuffing, and lateral phishing
- Correlates identity, email, device, browser, and application signals
- Creates explainable behavioral case timelines for investigations
- Revokes sessions, blocks access, and forces password resets
- Moves lateral phishing messages from compromised accounts to hidden folders
- Connects to Microsoft 365 and Google Workspace through APIs
- Correlates recurring IP activity and cross-customer intelligence
Use cases
- Detect compromised employee and partner accounts after valid authentication
- Investigate suspicious sign-ins, MFA changes, mail rules, and email activity
- Automatically eject attackers by revoking sessions and forcing password resets
- Contain phishing messages sent internally from hijacked accounts
- Monitor account takeover risk across Microsoft 365, Google Workspace, and SaaS apps