The Abnormal AI integration allows Expel to apply our detection strategy to your Abnormal AI alerts and pull them into the Workbench queue for investigation and remediation.
Prerequisites
- You must have the Organization Admin role in Workbench to set up this integration.
- You must have admin access in Abnormal AI to create an API token.
Quick Links
Setup includes the following steps (select any step for detailed instructions):
Step 1: Create an Access Token
To integrate the technology with Workbench, you need to create secure credentials to the API.
Note
Abnormal AI is requiring customers to migrate legacy REST API tokens to a new management system. Existing tokens are marked "Legacy" and continue to work during migration, but they cannot be rotated. For legacy tokens, you can only edit the IP safelist or revoke the token. All legacy tokens automatically expire on April 30, 2027. To maintain uninterrupted API access, create a new token using the steps below to replace each legacy token before the expiration date.
- Log in to Abnormal AI using an account with admin access.
- Navigate to Settings > Integrations.
- Scroll down to the API Token Management section and select Create New Token.
- Select REST API as the integration type, and select Next.
- Choose a token scope depending on your environment:
- Tenant (Single Tenant) - select this to isolate the integration to a single tenant.
- Customer (All Current and Future Tenants) - select this if your organization manages multiple tenants under a single Abnormal account.
- Select Next.
- Select Custom Access, and choose the following endpoints:
- Threats: Read Sensitive + Write (alert polling, health check, remediate/unremediate actions)
- Messages: Read Sensitive (attachment enrichment)
- Employees: Read Sensitive (user investigation actions)
-
Vendors: Read Sensitive (domain investigation actions)
Note
Read Sensitive (not Read) is required because threat details, attachments, and employee data are classified as sensitive by Abnormal. Access level is fixed at creation – an under-scoped token has to be recreated. Write is only needed for Expel email remediation actions.
- Select Next.
- Configure the following:
- Token Name - enter an Expel-identifiable name, like "Expel MDR".
- Description (optional) - note that this token is for the Expel integration.
- Token Expiry - we recommend 365 days, unless your organization's policy requires shorter. Note that the token must be rotated and updated on the Workbench device before expiration, or alerts will not be ingested.
- IP Safelist - add the listed IP addresses from Configure an IP Allow List.
- Select Next.
- Review your token information, then select Create Token.
-
Copy and save the token in a safe place for use in a later step. This token value will only be shown once.
- Select Done.
Step 2: Add Abnormal AI as a Security Device in Workbench
Now that you have an access token, you can configure the integration in Workbench.
- Log in to Workbench.
- In the side menu, navigate to Organization Settings > Security Devices.
- Select Add Security Device.
- In the search box, type “Abnormal” and then select the Abnormal AI integration.
- A configuration pane displays. Complete the fields as follows:
- Name - enter a name that might help you more easily identify this integration, such as “CompanyName Abnormal AI”; this name will display in Workbench under the Name column, and is a text string that you can filter on.
- Location - enter the location of your integration, for example “cloud.” This is also a text string that you can filter on, so we recommend being consistent with location naming across your Expel integrations.
-
Abnormal Security API endpoint URL - enter "
https://api.abnormalplatform.com". For EU-based tenants enter "https://eu.rest.abnormalsecurity.com" - Abnormal Security API authentication token - enter the API token you saved in Step 1.
- Select Save.
- Your device should be created successfully within a few seconds. A few reminders:
- After your connection is healthy, it will take some time for your device to begin polling and receiving data.
- To check on the status, select the downward arrow for your device in the first column and choose View details. You can then scroll to the Connection section to see if your device is fully connected.
Polling will happen first; data will be received after that. You must refresh the page to see updates. - If your device does not begin polling within 15 minutes, and does not begin receiving data within 30 minutes, contact our support team for help.
- To check if alerts are coming through, navigate to Dashboards > Alert Analysis. Scroll to the device you want to check, and select the Expel Alerts tab to reveal more alert information. It can take 36 to 72 hours for alerts to appear after setup, as we tune your device.