Linking Abnormal Security as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
Sync your Abnormal Security (Abnormal AI) threat campaigns, account takeover cases, and vendor cases into the PostHog data warehouse.
Adding a data source
- Go to the sources tab of the data pipeline section in PostHog.
- Click + New source and then click Link next to Abnormal Security (Abnormal AI).
- In Abnormal Security, go to Settings → Integrations → Abnormal REST API and create an API token. If your account restricts API access by IP, allow PostHog's outbound IP addresses.
- Back in PostHog, enter your API token, select your Region (US or EU), then click Next.
- Select the tables you want to sync, set the sync method and frequency, then click Import.
Once the syncs are complete, you can start using Abnormal Security data in PostHog.
Available tables
| Table | Description | Sync method |
|---|---|---|
threats | Email threat campaigns with recipient counts and a sample of messages | Full refresh |
cases | Account takeover cases | Incremental or full refresh |
vendor_cases | Vendor cases with security insights and a timeline of events | Incremental or full refresh |
Incremental tables sync only new or updated records on each run. Full refresh tables reload all data on each sync.
The threats table contains one row per campaign, including recipient counts and up to 10 sample messages as returned by the API. Threats use full refresh because campaign details have no reliable timestamp for incremental syncing.
The cases and vendor_cases tables are disabled by default. Enable them from the table selection step during setup. Both tables require an Account Takeover license from Abnormal Security.
Regions
Abnormal Security supports US and EU regions. Select your region when configuring the source. Dedicated account hosts are not supported.
Configuration
| Option | Type | Required |
|---|---|---|
API token | password | Yes |
Region | select | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
threats | Email threat campaigns detected by Abnormal, with recipient counts and a limited sample of messages. | Full refresh | — | — |
cases | Account takeover cases detected by Abnormal. This table requires an Account Takeover license. | Incremental, Full refresh | last_modified | — |
vendor_cases | Vendor cases with security insights and a timeline of related events. | Incremental, Full refresh | lastModifiedTime | — |