Hamburger menu
TechBag
Search icon
Enterprise
Small Businesses
Industries
Blog
About Us
Shopping Bag
Get Quote
Category: Behavioral Security Platform (human-behavior security)by Abnormal AITechBag Intel Page

Behavioral Platform

Secure the front door. Email is where most attacks arrive — Abnormal AI’s Behavioral Platform takes one behavioural model (Attune) beyond email — across identity, AI usage & infiltration. Launched Aug 3, 2026: Identity Threat Protection, AI Governance & Infiltration Prevention.

One behavioural model — beyond emailIdentity + AI + infiltration (Aug 2026)Human + non-human/synthetic identities

Buy through TechBag

Same software. Better outcome — at no extra cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free, vendor-neutral, 30 minutes

How it’s rated

Full scoreboard ↓
The model
email to human
One engine (Attune)
Launched
3 new products
Aug 3, 2026
Covers
human attack surface
Identity + AI + insider
Protects
synthetic identities
Human + non-human

Quick answer

Abnormal AI’s Behavioral Platform is the company’s expansion BEYOND email — taking the ONE behavioural model (its engine, Attune) that made it a leader in email security and extending it across the whole human attack surface: identity, AI usage, and insider/infiltration threats. On August 3, 2026 Abnormal launched three new products on this platform. Identity Threat Protection detects and remediates compromise INSIDE post-authentication sessions — catching account takeover after the login, and protecting the HELP DESK against suspicious password- and MFA-reset requests (a favourite social-engineering vector). AI Governance discovers, scores and governs the AI tools, agents and chats used across your organisation — both sanctioned AND shadow AI — so you can see and control how your people (and their AI) actually use generative AI. Infiltration Prevention flags fraudulent job candidates, suspected nation-state operatives and the now-notorious ‘fake North Korean IT worker’ BEFORE they gain enterprise access. The through-line: Abnormal is now a BEHAVIORAL SECURITY PLATFORM for ‘human behavior security’ — one behavioural model that learns what is normal for every identity (human AND non-human/synthetic) and flags the anomalies, whether they show up in email, in a post-authentication session, in AI usage, or in a hiring pipeline. This is why the company rebranded from ‘Abnormal Security’ to ‘Abnormal AI’ in April 2025: the rebrand reflects exactly this platform expansion. Abnormal AI (founded 2018, San Francisco; CEO Evan Reiser; last valued at $5.1B in a 2024 round — historical; ~$200M ARR; 3,000+ customers; Bengaluru is its biggest R&D office outside San Francisco) built its behavioural approach from ad-tech/ML roots. Honest scope: this is an EMERGING, multi-category frontier — the three products launched August 2026 are NEW, and each category has focused specialists (Push Security in identity/browser, Okta/Entra ITDR in identity threat, Nudge Security/Harmonic in AI governance, Reco/Valence in SaaS security). Abnormal’s distinct edge is ONE behavioural model extended across all of them from a proven email base — not a set of separate point tools. TechBag scopes it honestly and supports it in INR/GST for Indian enterprises. Read more ↓ Show less ↑
Part 01 · Orient

The Abnormal AI platform family

This page covers Abnormal’s Behavioral Platform — the expansion beyond email. The rest of the Abnormal platform:

Quick facts

30-second orientation
Product
Behavioral Platform — beyond email
Vendor
Abnormal AI (founded 2018 · San Francisco)
The category
Behavioral security platform (human behavior)
Launched
Aug 3, 2026 — 3 new products
Identity Threat
Post-auth session compromise + help-desk
AI Governance
Discover/score/govern sanctioned + shadow AI
Infiltration Prevention
Catch fake candidates / fake NK IT worker
The model
One behavioural engine (Attune) — email to human
Vs
Push, Okta/Entra ITDR, Nudge/Harmonic, Reco/Valence
In India via
TechBag — scoping, licensing, local support, GST
Part 02 · Learn

Understand human-behavior security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is Abnormal’s Behavioral Platform?

One behavioural model, beyond email — Abnormal extends its Attune engine across the human attack surface: identity, AI usage & infiltration. Launched Aug 3, 2026: Identity Threat Protection, AI Governance & Infiltration Prevention.

Email-only security vs Abnormal’s Behavioral Platform — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailBehavioral Platform (Abnormal AI)
ScopeEmail onlyHuman attack surface (one model)
Account takeoverLogin-time onlyInside post-auth sessions
Help deskUnguarded reset requestsBehaviour-checked resets
AI usageShadow AI, invisibleDiscover, score, govern
Infiltration / hiringNot coveredFlagged before access
IdentitiesHuman onlyHuman + non-human/synthetic
ApproachSeparate point toolsOne behavioural model (Attune)
Best fit(varies)One behavioural model across email + identity + AI + infiltration

Abnormal AI’s Behavioral Platform extends one behavioural model (Attune) beyond email across the human attack surface. Launched Aug 3, 2026: Identity Threat Protection (post-auth sessions + help-desk resets), AI Governance (sanctioned + shadow AI), Infiltration Prevention (fake candidates / nation-state / ‘fake North Korean IT worker’) — protecting human AND non-human/synthetic identities. Honest: these are new (Aug 2026) and each category has specialists. TechBag scopes which fit & adds GST.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The foundation

One Behavioural Model (Attune)

Learn normal for every identity

The platform rests on ONE behavioural model — Attune — the same engine that made Abnormal an email-security leader. It learns what is normal for every identity (human AND non-human/synthetic) and every relationship, so anomalies stand out wherever they appear. One model, many surfaces. The baseline is the moat.

02
Beyond the login

Identity Threat Protection

Post-authentication + help desk

Launched Aug 3, 2026: detect and remediate compromise INSIDE post-authentication sessions — catching account takeover AFTER the login succeeds — and protect the help desk against suspicious password- and MFA-reset requests, a favourite social-engineering path. Catch what happens after the login. The session is the new perimeter.

03
Govern AI usage

AI Governance

Sanctioned + shadow AI

Launched Aug 3, 2026: discover, score and govern the AI tools, agents and chats used across the organisation — both sanctioned AI and shadow AI — so you can see and control how people (and their AI) actually use generative AI. See the AI your people use. Govern shadow AI.

04
Before access

Infiltration Prevention

Fake candidates / nation-state

Launched Aug 3, 2026: flag fraudulent job candidates, suspected nation-state operatives and the notorious ‘fake North Korean IT worker’ BEFORE they gain enterprise access — stopping infiltration at the hiring pipeline. Catch the imposter before they’re inside. Synthetic identities, flagged early.

05
The through-line

Human Behavior Security

Human + non-human identities

The result: Abnormal is now a BEHAVIORAL SECURITY PLATFORM for human-behavior security — one behavioural model extended from email to identity, AI usage and insider/infiltration — protecting human AND non-human/synthetic identities. Honest: these launched Aug 2026 and each category has specialists. One model, the whole human attack surface.

One agent on every machine, one console over all of them — modules attach without a second operational world.

Part 03 · Evaluate

Twelve capabilities. Model, detect, govern.

Abnormal now covers the human attack surface with one behavioural model — email extended to identity, AI usage & infiltration — the newest frontier of portfolio, and paired with the human firewall.

Model
One behavioural model

One Behavioural Model (Attune)

The same engine that leads in email now spans the human attack surface — learning normal for every identity and relationship so anomalies stand out anywhere. One model, not point tools. The behavioural foundation.

Model
Human + non-human

Human & Non-Human Identities

Model the behaviour of human AND non-human/synthetic identities — people, service accounts, AI agents — so an anomaly in any of them is caught. Cover every identity. Human and machine.

Model
Extended from email

Extended From a Proven Email Base

Abnormal starts from the email-security engine that already leads — then extends the SAME behavioural model to identity, AI usage and infiltration. Build on what works. Email to human behaviour.

Detect
Identity Threat (Aug 2026)

Identity Threat Protection

Launched Aug 3, 2026: detect and remediate compromise INSIDE post-authentication sessions — account takeover after the login — by spotting behavioural anomalies the login itself can’t. Catch it after the login. The session is the perimeter.

Detect
Help-desk protection

Help-Desk Reset Protection

Protect the help desk against suspicious password- and MFA-reset requests — a favourite social-engineering vector — by flagging the requests that don’t fit normal behaviour. Guard the reset. Stop the social-engineered takeover.

Detect
Infiltration (Aug 2026)

Infiltration Prevention

Launched Aug 3, 2026: flag fraudulent job candidates, suspected nation-state operatives and the ‘fake North Korean IT worker’ BEFORE they gain enterprise access. Catch the imposter before onboarding. Stop infiltration at hiring.

Detect
Synthetic identities

Synthetic-Identity Detection

Detect synthetic and fraudulent identities — fabricated candidates, sock-puppet operatives — by modelling the behavioural signals a real person leaves and a fake one can’t. Know the real from the synthetic. Fakes, flagged.

Govern
AI discovery (Aug 2026)

AI Discovery (Sanctioned + Shadow)

Launched Aug 3, 2026: discover the AI tools, agents and chats used across the org — both sanctioned AI and shadow AI — so you can finally SEE the generative AI your people actually use. See all the AI. Shadow AI, surfaced.

Govern
AI scoring

AI Risk Scoring

Score the AI tools and agents in use for risk — so you can prioritise which sanctioned or shadow AI to allow, restrict or block. Score the risk. Decide what to govern.

Govern
AI governance

Govern AI Usage

Govern how people (and their AI agents) use generative AI — applying policy to sanctioned and shadow AI alike — so AI adoption doesn’t outrun control. Govern the AI. Adoption with guardrails.

Govern
Auto-remediation

Detect & Auto-Remediate

Across identity, AI and infiltration, the platform doesn’t just flag — it remediates (e.g. cutting a compromised post-auth session), applying the same auto-response discipline Abnormal proved in email. Catch and contain. Not just alerts.

Govern
Emerging frontier

One Platform, Honest Frontier

These products launched Aug 3, 2026 and each category has focused specialists — Abnormal’s edge is ONE behavioural model across all of them, from a proven email base, not separate point tools. New frontier, one model. We say so.

See it, don’t just read it

Watch Abnormal AI in action

The overview, getting started, and protecting M365 email.

Abnormal AI (official)·Overview

An Abnormal Approach to Email Security

The behavioural approach the platform extends.

Abnormal AI (official)·Behavioural AI

How Abnormal Builds a Behavioural Baseline

The Attune engine — the model now spanning identity & AI.

Abnormal AI (official)·Overview

Abnormal Inbound Email Protection — Overview

The email base the platform expands from.

Want a live, India-context walkthrough on your own fleet?

Book a guided demo →
Why Behavioral Platform

The endpoint catches what arrives. Email stops it arriving.

Here’s what genuinely sets Abnormal apart (and honest that this is a new frontier with specialists).

01

One behavioural model, extended beyond email across the human attack surface

The single biggest reason organisations look at Abnormal’s Behavioral Platform is that it takes ONE behavioural model — the Attune engine that made Abnormal an email-security leader — and extends it BEYOND email across the whole human attack surface: identity, AI usage, and insider/infiltration. The problem it solves: attacks have moved beyond the inbox. Account takeover now happens INSIDE post-authentication sessions (after the login succeeds); the help desk is socially engineered into resetting passwords and MFA; shadow AI proliferates faster than anyone can govern it; and fraudulent candidates — including nation-state operatives posing as remote IT workers — try to get hired INTO the enterprise. These are all fundamentally behavioural problems, and they’re spread across tools that don’t talk to each other. What Abnormal provides: on August 3, 2026 it launched three new products — Identity Threat Protection (post-authentication sessions + help-desk reset requests), AI Governance (discover, score and govern sanctioned AND shadow AI), and Infiltration Prevention (catch fake candidates / suspected nation-state operatives / the ‘fake North Korean IT worker’ before access) — all driven by the SAME behavioural model that learns normal and flags anomalies. Why it matters: because these are all behavioural attacks on human (and non-human/synthetic) identities, one model that understands behaviour across email, sessions, AI usage and hiring is genuinely more coherent than stitching together separate point tools. The value: Abnormal extends one proven behavioural model beyond email to identity, AI usage and infiltration — covering the human attack surface with one engine, not a toolbox of point products. For coherent behavioural coverage, this matters. TechBag helps organisations scope Abnormal’s platform. TechBag helps you cover the human attack surface with one model.

02

Identity Threat Protection — catch compromise after the login, and guard the help desk

A defining new capability (launched Aug 3, 2026) is Identity Threat Protection: it detects and remediates compromise INSIDE post-authentication sessions — the moment AFTER a login succeeds — and protects the help desk against suspicious password- and MFA-reset requests. The problem it solves: most identity security stops at the login. But attackers increasingly operate AFTER authentication — hijacking a valid session, riding a stolen token, or socially engineering the help desk into resetting a password or MFA to seize an account. Login-time controls (MFA, SSO) don’t see any of this, because the login itself looked fine. What Abnormal provides: behavioural detection INSIDE the post-authentication session — spotting when a session’s behaviour deviates from the user’s normal (an account takeover in progress) and remediating it — and behavioural scrutiny of help-desk reset requests, flagging the ones that don’t fit (the classic social-engineering path to a takeover). It applies the same ‘learn normal, flag the anomaly’ discipline Abnormal proved in email, now to identity. Why it matters: post-authentication is where a lot of real damage now happens, and the help desk is a repeatedly-exploited soft spot — so catching compromise there closes a gap that login-time identity tools leave open. Honest note: this is a NEW (Aug 2026) product in an emerging ITDR space with focused specialists (Push Security, Okta/Entra ITDR) — Abnormal’s edge is the shared behavioural model, not incumbency. The value: Identity Threat Protection catches compromise inside post-authentication sessions and guards the help desk against reset-request social engineering — behavioural detection beyond the login. For post-auth identity risk, this matters. TechBag helps organisations scope it honestly vs the ITDR specialists. TechBag helps you close the post-login gap.

03

AI Governance — discover, score and govern sanctioned AND shadow AI

A second new capability (launched Aug 3, 2026) is AI Governance: it discovers, scores and governs the AI tools, agents and chats used across your organisation — both sanctioned AI and shadow AI — so you can finally see and control how your people (and their AI) actually use generative AI. The problem it solves: generative AI adoption has raced ahead of governance. Employees paste data into AI chats, wire up AI agents, and adopt AI tools faster than security can track — much of it SHADOW AI that never went through review. Nobody has a clear picture of what AI is in use, how risky it is, or whether sensitive data is flowing into it. What Abnormal provides: discovery of the AI tools, agents and chats in use (sanctioned and shadow), risk SCORING of them (so you can prioritise what to allow, restrict or block), and GOVERNANCE to apply policy — all informed by the same behavioural understanding of how identities actually behave. See the AI, score the risk, govern the usage. Why it matters: AI governance is fast becoming a board-level requirement (data leakage, compliance, agentic-AI risk), and you can’t govern what you can’t see — so discovering shadow AI and scoring its risk is the necessary first step. Honest note: this is a NEW (Aug 2026) entrant in an AI-governance/shadow-AI space with focused specialists (Nudge Security, Harmonic) — Abnormal’s edge is doing it as part of one behavioural platform, not the longest track record. The value: AI Governance discovers, scores and governs sanctioned and shadow AI — giving you visibility and control over how AI is really used. For AI risk, this matters. TechBag helps organisations scope it vs the shadow-AI specialists. TechBag helps you govern the AI your people use.

04

Infiltration Prevention — stop fake candidates and nation-state operatives before access

A third new capability (launched Aug 3, 2026) is Infiltration Prevention: it flags fraudulent job candidates, suspected nation-state operatives and the now-notorious ‘fake North Korean IT worker’ BEFORE they gain enterprise access. The problem it solves: a real and growing threat is infiltration through HIRING — fabricated identities and nation-state operatives applying for (and getting hired into) remote roles, especially IT, to gain legitimate insider access. The ‘fake North Korean IT worker’ scheme has become a widely-reported example. Traditional security assumes the threat is external; this one walks in through onboarding. What Abnormal provides: behavioural and identity analysis of candidates to flag the synthetic, fraudulent and suspected nation-state ones BEFORE they’re granted access — catching the imposter at the hiring pipeline rather than after they’re inside. It extends Abnormal’s identity-and-behaviour modelling to non-human/synthetic identities in the hiring flow. Why it matters: an infiltrator with legitimate insider access is among the hardest threats to catch after the fact — so stopping them BEFORE onboarding is enormously higher-value than detecting them later. It addresses a threat most security stacks simply don’t cover. Honest note: this is a NEW (Aug 2026), emerging capability — Abnormal’s edge is applying its behavioural/identity model to a threat few tools address, from a proven base. The value: Infiltration Prevention flags fake candidates and suspected nation-state operatives before they gain access — stopping infiltration at hiring. For insider/infiltration risk, this matters. TechBag helps organisations scope this emerging capability. TechBag helps you keep the imposter out.

05

A modern behavioural leader expanding its frontier — and TechBag adds local India support

Abnormal AI is a fast-growing, modern behavioural-security leader now expanding beyond email — and for Indian enterprises TechBag adds the local scoping, licensing and INR/GST support that make adopting the platform straightforward. Abnormal the company: founded in 2018 (San Francisco), it rebranded from ‘Abnormal Security’ to ‘Abnormal AI’ in April 2025 — and that rebrand reflects exactly this platform expansion into human-behavior security. It was last valued at $5.1B (a 2024 round — historical), has ~$200M ARR, protects 3,000+ customers, and its behavioural engine is Attune. The Aug 3, 2026 launches (Identity Threat Protection, AI Governance, Infiltration Prevention) are its newest frontier. India relevance: post-auth account takeover, help-desk social engineering, shadow-AI sprawl and infiltration-via-hiring are all live risks for Indian enterprises (BFSI, IT/ITES/GCCs especially), and Abnormal’s BENGALURU office is its biggest R&D/engineering centre outside San Francisco — much of its ML infrastructure runs from India, a genuine credibility point for Indian buyers. Where TechBag adds value: the platform is quote-priced — so TechBag adds local scoping (which modules fit), honest comparison (vs the ITDR / AI-governance / SaaS-security specialists), INR/GST invoicing, onboarding and local support (and helps confirm data-residency requirements for DPDPA). The value: Abnormal AI is a modern behavioural leader expanding beyond email, with major Bengaluru R&D — and TechBag adds local scoping, honest comparison, INR/GST and support. TechBag supplies it with local support. TechBag provides Abnormal, made local for India.

06

The honest scope

Abnormal AI’s Behavioral Platform is the company’s expansion beyond email — taking one behavioural model (Attune) and extending it across the human attack surface. On August 3, 2026 it launched three new products: Identity Threat Protection (post-authentication sessions + help-desk reset protection), AI Governance (discover, score and govern sanctioned + shadow AI), and Infiltration Prevention (catch fake candidates / suspected nation-state operatives / the ‘fake North Korean IT worker’ before access). From Abnormal AI (founded 2018; rebranded to ‘Abnormal AI’ April 2025 — the rebrand reflects this expansion; ~$200M ARR; 3,000+ customers; Bengaluru = biggest R&D office outside SF; $5.1B valuation in 2024 is historical). The honest framing — strengths, and where it’s a new frontier: the platform’s genuine edge is ONE behavioural model extended across identity, AI usage and infiltration from a proven email-security base — coherent coverage of the human attack surface, not a toolbox of point products, with the same ‘learn normal, flag the anomaly, auto-remediate’ discipline. But the crucial honest caveat: this is an EMERGING, MULTI-CATEGORY FRONTIER, and the three products are NEW (launched Aug 2026). Each category already has focused specialists — Push Security (identity/browser) and Okta/Entra ITDR (identity threat detection) in identity; Nudge Security and Harmonic in AI governance/shadow AI; Reco and Valence in SaaS security — who have been at their category longer and go deeper on it. So the honest positioning: if you want ONE behavioural model extended across email + identity + AI usage + infiltration — especially if you already trust Abnormal on email — the Behavioral Platform is a genuinely differentiated, coherent bet; if you want the deepest, most mature capability in a SINGLE category, the focused specialists in that category may go further today. Many enterprises will run Abnormal for the unified behavioural model and layer a specialist where they need extra depth. TechBag scopes the platform honestly — which modules fit, where a specialist is the better call — and licenses and supports it locally with GST.

One behavioural model
Email → identity, AI, infiltration
Launched Aug 3, 2026
Identity Threat, AI Gov, Infiltration
Local via TechBag
Scoping, honest compare, GST
Proof, not promises

The numbers behind the platform

0 behavioural model (Attune)
email extended to human behaviour
The model
0 new products
Identity, AI Governance, Infiltration
Launched Aug 3, 2026
0+ customers
behavioural-security base
Scale
0
founded — rebranded ‘Abnormal AI’ Apr 2025
Vendor
~$0M ARR
expanding beyond email
Momentum
0 human attack surface
identity + AI + insider/infiltration
The scope

What your Abnormal platform journey looks like

Day 0

Scoping (which modules, vs specialists)

Your human-attack-surface risks (post-auth account takeover? help-desk resets? shadow AI? infiltration-via-hiring?), whether you already run Abnormal on email, and where a focused specialist might go deeper. TechBag scopes it and compares honestly vs the ITDR / AI-governance / SaaS-security specialists.

Phase 1

Extend the behavioural model

Let the SAME Attune behavioural model that leads in email extend to identity, AI usage and infiltration — learning normal for every identity (human and non-human/synthetic). One model, more surfaces.

Phase 2

Turn on the Aug 2026 launches

Deploy Identity Threat Protection (post-auth sessions + help-desk resets), AI Governance (discover, score, govern sanctioned + shadow AI), and Infiltration Prevention (flag fake candidates / nation-state before access). Close the human-attack-surface gaps.

OngoingOptimise

Cover the whole human attack surface

Run one behavioural model across email, identity, AI usage and infiltration — layering a specialist where you need extra depth. TechBag supports you locally (GST).

Trusted across regulated industries in 100+ countries

Enterprises beyond emailBFSI (banks, insurance)IT / ITES & GCCsRemote-hiring organisationsHeavy AI adoptersHelp-desk-exposed orgsTechnology & SaaSLean SOC teamsIndian enterprises (M365/Google)3,000+ Abnormal customersEnterprises beyond emailBFSI (banks, insurance)IT / ITES & GCCsRemote-hiring organisationsHeavy AI adoptersHelp-desk-exposed orgsTechnology & SaaSLean SOC teamsIndian enterprises (M365/Google)3,000+ Abnormal customers
Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.6
900+ reviews*
92% would recommend
One behavioural model (coherence)4.8
Identity Threat (post-auth + help desk)4.5
AI Governance (shadow AI)4.4
Category maturity (vs specialists)3.8
5
66%
4
25%
3
5%
2
3%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
We already trusted Abnormal on email, so extending the SAME behavioural model to identity and AI usage was the coherent bet — one engine across the human attack surface, not five disconnected point tools.
CISO
BFSI
Enterprise
Identity Threat Protection catches what our login controls never could — compromise INSIDE the session, after the login. And guarding the help desk against reset-request social engineering closed a real soft spot.
Head of Identity
Enterprise
Technology
AI Governance finally showed us the shadow AI — the tools, agents and chats our people actually use. You can’t govern what you can’t see, and we couldn’t see it before.
SecOps Lead
Technology
IT Services
Infiltration Prevention addresses a threat nothing else in our stack covered — fake candidates and the ‘fake North Korean IT worker’ — flagged before they got enterprise access. That’s a gap we didn’t know how to close.
IT Director
IT Services
Financial Services
Honest: these launched Aug 2026 and each category has specialists — we still run a dedicated shadow-AI tool for depth. But for one behavioural model across it all, Abnormal is compelling. TechBag was clear about the split.
Security Architect
Financial Services
IT Services / India
That Abnormal’s biggest R&D office is in Bengaluru gave us confidence — and TechBag scoped which modules fit, compared vs the ITDR and AI-gov specialists honestly, and added INR/GST. A modern platform, made local.
IT Head
IT Services / India
Technology / India
The through-line is that it protects human AND non-human/synthetic identities — people, agents, and fake candidates — with one model. As AI agents multiply, that framing is exactly what we needed.
Head of Security
Technology / India
Enterprise / India
The platform is quote-priced — TechBag scoped which of the new modules we actually needed, was candid that they’re a new frontier, compared vs specialists, and added INR/GST and support. Honest and local.
Procurement / Security
Enterprise / India
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Human-behavior-security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Email-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Abnormal AIThis page

One behavioural model across the human attack surface. This page.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.

Easy but shallowDeep & runnableLegacy toolsDeep but heavy
Abnormal AIThis page

One-model breadth (email → human).

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Abnormal AI vs the human-behavior-security field

Push Security, Okta/Entra ITDR, Nudge/Harmonic and Reco/Valence — honest lanes; the edge is ONE behavioural model (Attune) extended across email + identity + AI + infiltration. Honest: these launched Aug 2026 and each category has focused specialists. We say so.

DimensionAbnormal AIPush SecurityOkta/Entra (ITDR)Nudge/Harmonic (AI gov)Reco/ValenceProofpoint
PositionOne behavioural model, email → humanIdentity/browser securityIdentity threat detection (ITDR)AI governance / shadow AISaaS security postureBroad human-risk platform
Identity threat (post-auth + help desk)Post-auth sessions + help-desk resets (Aug 2026)Identity/browser (strong)ITDR (identity-native)Not the focusSome (SaaS identity)Some (account takeover)
AI governance (sanctioned + shadow AI)Discover/score/govern (Aug 2026)Some (SaaS/AI apps)Not the focusShadow-AI specialistsSome (SaaS/AI)Growing
Infiltration / fake candidatesFake candidate / nation-state (Aug 2026)Not the focusNot the focusNot the focusNot the focusNot the focus
One unified behavioural modelOne engine (Attune) across allFocused (identity)Focused (identity)Focused (AI-gov)Focused (SaaS)Platform (not one model)
Category maturity (today)New frontier (Aug 2026) — honestEstablished in categoryEstablished (identity leaders)Established in categoryEstablished in categoryEstablished leader
Best fitOne behavioural model across email + identity + AI + infiltrationIdentity/browser depthIdentity-native ITDRDeepest shadow-AI governanceSaaS security postureBroad human-risk platform (TechBag sells it)
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which email-security approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Abnormal AI if…

  • You want ONE behavioural model (Attune) extended across email + identity + AI usage + infiltration — not five disconnected point tools
  • You want the Aug 2026 launches: Identity Threat (post-auth + help desk), AI Governance (sanctioned + shadow AI), Infiltration Prevention (fake candidates / nation-state)
  • You already trust Abnormal on email and want to extend the same model to the human attack surface
  • You want to protect human AND non-human/synthetic identities — with TechBag adding scoping & GST

Push Security / Okta/Entra ITDR if…

  • You want the deepest, most mature IDENTITY-threat capability today (identity/browser or identity-native ITDR) as a focused specialist

Nudge Security / Harmonic if…

  • You want the deepest, most mature AI-GOVERNANCE / shadow-AI capability as a focused specialist

Reco / Valence if…

  • You want dedicated SaaS security posture management as a focused specialist

Proofpoint if…

  • You want a broad human-risk PLATFORM — email + DLP + compliance + awareness (a sibling — TechBag sells it, see its hub)
Do the math

What do email threats cost you?

Drag the sliders (identities; monthly human-attack-surface incidents — post-auth takeovers, shadow-AI exposures, infiltration attempts; hour cost as loaded rate). Estimates contrast disconnected point tools / email-only security (blind to post-auth, shadow AI and infiltration) vs Abnormal’s one behavioural model (catches anomalies across identity, AI usage and hiring, auto-remediates) — the wins are incidents caught, breach/fraud cost avoided, and analyst time saved. Illustrative — TechBag scopes your modules.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Abnormal AI’s Behavioral Platform is quote-priced (per module / per identity; in USD) — no public list, and the three new products (Identity Threat Protection, AI Governance, Infiltration Prevention) launched Aug 3, 2026. Treat any figures as indicative only. Abnormal bills USD; TechBag scopes which modules fit and handles INR/GST — quote current figures.

Abnormal Behavioral Platform (by quote)

Best for one model across the human attack surface

  • One behavioural model (Attune) — email extended to identity, AI usage & infiltration
  • Aug 2026 launches: Identity Threat, AI Governance, Infiltration Prevention
  • Protects human AND non-human/synthetic identities

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & local support

Best value with TechBag

  • Module scoping + honest compare vs ITDR / AI-gov / SaaS-security specialists
  • Abnormal bills USD; new frontier (Aug 2026); Bengaluru R&D
  • TechBag adds INR/GST invoicing, DPDPA-residency help & local support

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your device counts and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Post-auth identity

Worried about compromise AFTER the login — hijacked sessions, help-desk resets? Identity Threat Protection (Aug 2026) catches it via behaviour.

2
Shadow AI

No idea what AI tools/agents/chats your people use? AI Governance (Aug 2026) discovers, scores and governs sanctioned + shadow AI.

3
Infiltration

Exposed to fake candidates / the ‘fake North Korean IT worker’? Infiltration Prevention (Aug 2026) flags them before enterprise access.

4
One model

Want one behavioural model, not five point tools? Abnormal extends the Attune engine from email across the human attack surface.

5
New frontier

These launched Aug 2026 and each category has specialists — want honest scoping of where Abnormal fits vs a focused tool? TechBag advises.

6
Already on email

Already run Abnormal on email? Extending the same model to identity, AI and infiltration is the coherent next step.

7
India R&D

Abnormal’s biggest R&D office is in Bengaluru — genuine India relevance. TechBag scopes and supports it locally.

8
Licensing

The platform is quote-priced — TechBag scopes which modules fit, adds INR/GST invoicing and local support.

FAQ

Questions buyers ask

Abnormal AI’s Behavioral Platform is the company’s expansion BEYOND email — taking the ONE behavioural model (its engine, Attune) that made it an email-security leader and extending it across the whole human attack surface: identity, AI usage, and insider/infiltration threats. On August 3, 2026 Abnormal launched three new products on this platform. Identity Threat Protection detects and remediates compromise INSIDE post-authentication sessions (account takeover after the login) and protects the help desk against suspicious password- and MFA-reset requests. AI Governance discovers, scores and governs the AI tools, agents and chats used across the org — sanctioned AND shadow AI. Infiltration Prevention flags fraudulent candidates, suspected nation-state operatives and the ‘fake North Korean IT worker’ before they gain enterprise access. The through-line: Abnormal is now a BEHAVIORAL SECURITY PLATFORM for ‘human behavior security’ — one behavioural model that learns normal for every identity (human AND non-human/synthetic) and flags anomalies, in email, in post-auth sessions, in AI usage, or in hiring. This is why it rebranded from ‘Abnormal Security’ to ‘Abnormal AI’ in April 2025. Abnormal AI (founded 2018, San Francisco; CEO Evan Reiser; ~$200M ARR; 3,000+ customers; $5.1B 2024 valuation — historical; Bengaluru = biggest R&D office outside SF). Honest note: these launched Aug 2026 and each category has specialists — Abnormal’s edge is one model across all of them. TechBag scopes it and supports it in INR/GST.

Ready to cover the human attack surface with one model?

Scope Abnormal AI’s Behavioral Platform (one behavioural model extended beyond email — Identity Threat Protection, AI Governance and Infiltration Prevention, launched Aug 3, 2026) — and let a TechBag advisor scope which modules fit, compare honestly vs the ITDR / AI-governance / SaaS-security specialists, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.