Linking Abnormal Security as a source

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog
Alpha release

This source is currently in alpha. The interface and available tables may change.

Sync your Abnormal Security (Abnormal AI) threat campaigns, account takeover cases, and vendor cases into the PostHog data warehouse.

Adding a data source

  1. Go to the sources tab of the data pipeline section in PostHog.
  2. Click + New source and then click Link next to Abnormal Security (Abnormal AI).
  3. In Abnormal Security, go to Settings → Integrations → Abnormal REST API and create an API token. If your account restricts API access by IP, allow PostHog's outbound IP addresses.
  4. Back in PostHog, enter your API token, select your Region (US or EU), then click Next.
  5. Select the tables you want to sync, set the sync method and frequency, then click Import.

Once the syncs are complete, you can start using Abnormal Security data in PostHog.

Available tables

TableDescriptionSync method
threatsEmail threat campaigns with recipient counts and a sample of messagesFull refresh
casesAccount takeover casesIncremental or full refresh
vendor_casesVendor cases with security insights and a timeline of eventsIncremental or full refresh

Incremental tables sync only new or updated records on each run. Full refresh tables reload all data on each sync.

The threats table contains one row per campaign, including recipient counts and up to 10 sample messages as returned by the API. Threats use full refresh because campaign details have no reliable timestamp for incremental syncing.

The cases and vendor_cases tables are disabled by default. Enable them from the table selection step during setup. Both tables require an Account Takeover license from Abnormal Security.

Regions

Abnormal Security supports US and EU regions. Select your region when configuring the source. Dedicated account hosts are not supported.

Configuration

OptionTypeRequired
API tokenpasswordYes
RegionselectYes

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
threats

Email threat campaigns detected by Abnormal, with recipient counts and a limited sample of messages.

Full refresh——
cases

Account takeover cases detected by Abnormal. This table requires an Account Takeover license.

Incremental, Full refreshlast_modified—
vendor_cases

Vendor cases with security insights and a timeline of related events.

Incremental, Full refreshlastModifiedTime—

Still have questions?

Was this page useful?