🧪 Community ✓ Claude Code ✓ Claude Desktop • Abnormal

Abnormal Security

Abnormal Security - AI-powered email security, phishing detection, account takeover prevention

Installation

Install this plugin individually:

/plugin marketplace add wyre-technology/msp-claude-plugins --plugin abnormal-security

Or install all MSP plugins at once:

/plugin marketplace add wyre-technology/msp-claude-plugins

Features

  • Account Takeover
  • Cases
  • Messages
  • Threats
  • Vendors

Skills

This plugin provides 6 skills that teach Claude about Abnormal Security:

Skill Description
account-takeover Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators.
cases Use this skill when working with Abnormal Security abuse mailbox cases - user-reported emails, case triage, remediation actions, case lifecycle, and phishing simulation management.
messages Use this skill when working with Abnormal Security message analysis - email headers, attachments, sender reputation, delivery context, authentication results (SPF/DKIM/DMARC), and message metadata.
threats Use this skill when working with Abnormal Security threat detection and analysis - BEC, phishing, malware, socially-engineered attacks, spam, graymail, and credential theft.
vendors Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain email threat monitoring.
api-patterns Use this skill when working with the Abnormal Security REST API - Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, error handling, and common API patterns.

Commands

Available slash commands:

Command Description
/account-audit Audit for account takeover indicators and suspicious sign-ins in Abnormal Security
/case-review Review and triage abuse mailbox cases in Abnormal Security
/search-threats Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords
/threat-triage Triage recent email threats detected by Abnormal Security by severity and attack type
/vendor-risk Check vendor risk scores and compromised vendor activity in Abnormal Security VendorBase

API Reference

Base URL
Authentication
Rate Limit
Documentation

Example Usage

Audit for account takeover indicators and suspicious sign-ins in Abnormal Security

/account-audit

Review and triage abuse mailbox cases in Abnormal Security

/case-review

Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords

/search-threats

Triage recent email threats detected by Abnormal Security by severity and attack type

/threat-triage

Check vendor risk scores and compromised vendor activity in Abnormal Security VendorBase

/vendor-risk

Using Skills

/skill abnormal-security:account-takeover

Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators.