Abnormal AI, recognized for its contributions to AI-native behavioral security, has unveiled Attune 1.0, a new behavioral foundation model that promises to enhance cybersecurity capabilities.
This model, trained on an impressive dataset exceeding one billion behavioral signals, now facilitates 85% of detections across the Abnormal Behavior Platform, laying the groundwork for the company's expanding security solutions.
Addressing Evolving Threat Landscapes
As cyber attacks become increasingly sophisticated due to AI's ability to craft highly personalized campaigns, traditional security measures that rely on static rules and threat intelligence are becoming less effective. Attune 1.0 consolidates Abnormal's eight years of behavioral insights into a single, coherent model that better handles these challenges.
"Attackers are leveraging AI to imitate trusted Behavior so convincingly that static rules and threat feeds struggle in the era of AI-driven attacks," stated Evan Reiser, CEO and Co-Founder of Abnormal AI. Attune 1.0 fills this gap by capturing normal organizational communication patterns and distinguishing them from malicious activities, enhancing the capabilities of the Abnormal Behavior Platform.
Unified Approach to Detection
Abnormal swiftly identifies and mitigates novel AI-driven threats upon detection of behavioral anomalies
Differentiating itself from previous systems that treated identity, Behavior, and content as distinct signals, Attune 1.0 adopts a unified multimodal architecture.
This approach enables the model to perceive and learn from the interplay of various signals, uncovering hidden patterns that attackers try their best to conceal. With a foundational focus on identifying normal patterns within client environments, Abnormal swiftly identifies and mitigates novel AI-driven threats upon detection of behavioral anomalies.
Key Achievements and Features
In terms of efficacy, Attune 1.0 is already charting significant milestones. It identifies roughly 150,000 more attack campaigns weekly compared to its predecessors, successfully detecting complex threats that often went unnoticed.
The model's precision has increased by 50%, thanks to its training on a broad spectrum of data. Additionally, Attune has demonstrated its proficiency by intercepting a new Microsoft Teams OAuth phishing attack well before it was officially acknowledged. The model, which is operational across the entire Abnormal Behavior Platform, effectively secures email, identity, and account takeover protections, thereby enhancing overall cybersecurity posture.
Enhanced Control and Visibility
The release of Attune 1.0 reinforces Abnormal's commitment to delivering advanced AI solutions
The release of Attune 1.0 reinforces Abnormal's commitment to delivering advanced AI solutions that meet modern security demands.
The platform now offers enhanced visibility and control features for users, such as Detection 360 Insights, which provides detailed explanations behind each AI-triggered alert. Meanwhile, the release of Custom AI Models in early access enables users to personalize AI responses by defining unique environmental patterns through straightforward natural language instructions.
Innovations in Security Training
Abnormal is also revolutionizing security training with updates to its AI Phishing Coach program. By moving away from generic compliance training, the system now employs AI-driven personalized coaching based on actual threat simulations.
This includes Phishing Risk Scoring, which offers real-time assessments of phishing readiness, and new simulation types—BEC and VEC—that utilize data from Abnormal's relationship graph to replicate interactions with managers, colleagues, and vendors for realistic training scenarios.
Abnormal AI, the pioneer in AI-native behavioral security, announces the launch of Attune 1.0, a behavioral foundation model for cybersecurity. Trained on more than one billion derived behavioral signals, Attune now powers 85%1 of detections across the Abnormal Behavior Platform and establishes a shared intelligence layer for the company’s expanding security portfolio.
Communication is how organizations build trust. Today, that trust is being weaponised by attackers using AI to launch campaigns that are highly personalized for each and every target. This evolution requires defenders to assume that every attack is a novel attack.
Static threat intelligence
Traditional security tools, which rely on rules and static threat intelligence, are struggling to keep pace with this shift. Attune 1.0 addresses this by bringing together Abnormal’s eight years of behavioral understanding into a single, unified model that is easier to manage and improve.
"Attackers are leveraging AI to imitate trusted Behavior so convincingly that static rules and threat feeds struggle in the era of AI-driven attacks," said Evan Reiser, CEO and Co-Founder of Abnormal AI. "Attune 1.0 is how we close that gap—with a behavioral foundation model that understands normal organizational communication patterns. It gives customers a single intelligence layer that understands known good Behavior, catches what isn’t, and strengthens every product we ship as part of the Abnormal Behavior Platform.”
Unified multimodal architecture
Unlike earlier detection systems that treated identity, Behavior, and content as separate signals, Attune 1.0 utilizes a unified multimodal architecture.
By learning these modalities jointly, the model better understands how signals reinforce or contradict one another to reveal patterns that attackers work hardest to hide. From inception, Abnormal has focused on knowing what’s normal in customers’ environments, enabling it to detect and block novel, AI-driven attacks when a deviation in Behavior is found.
Key milestones of the Attune 1.0 milestone include:
- Efficacy Gains at Scale: Trained on large-scale behavioral signals, Attune is already detecting approximately 150,000 more attack campaigns per week than earlier systems, catching highly sophisticated messages that were previously undetectable.
- Higher Precision: By training on a larger volume of diverse data, the model delivers 50% higher precision compared to earlier systems.
- Stopping Novel Attack Campaigns: Attune recently identified and blocked a novel Microsoft Teams OAuth phishing campaign two months before it was publicly documented.
- Platform-Wide Intelligence: Attune already powers 85% of detections across the Abnormal Behavior Platform, providing higher precision and fewer false positives. This foundation establishes a shared behavioral layer across email, identity, and account takeover protection, catching more lateral attacks to better secure the entire employee lifecycle. Attune 1.0 is Generally Available today.
Natural language descriptions
With the release of Attune 1.0, Abnormal continues on its promise of delivering a powerful, automated AI engine designed to prevent modern email-based attacks. Alongside this automation, Abnormal is delivering greater visibility and control, so customers can understand the platform’s autonomous detections and fine-tune them when needed:
- Detection 360 Insights (GA): Provides visibility into the behavioral reasoning behind every AI determination, helping analysts understand exactly why a message was flagged.
- Custom AI Models (Early Access): Enables security teams to influence and control the AI by defining environment-specific patterns using simple natural language descriptions. This allows users to influence and augment the AI specific to their environment.
Actual simulation interactions
Abnormal is also delivering updates for AI Phishing Coach, transforming how organizations manage the human element of security and best train their employees. Abnormal is replacing one-size-fits-all compliance training with an automated, AI-driven system that helps turn real-world threats into personalized coaching. As the underlying behavioral layer within Abnormal improves, our ability to train on those results also improves:
- Phishing Risk Scoring (GA): Provides a continuously updated phishing-readiness signal based on actual simulation interactions, reporting activity, and training outcomes.
- BEC and VEC Simulations (GA): New simulation types, with data from the Abnormal relationship graph, mirror manager, colleague, and vendor interactions.