🧪 Community ✓ Claude Code ✓ Claude Desktop • Abnormal
Abnormal Security
Abnormal Security - AI-powered email security, phishing detection, account takeover prevention
Installation
Install this plugin individually:
/plugin marketplace add wyre-technology/msp-claude-plugins --plugin abnormal-security Or install all MSP plugins at once:
/plugin marketplace add wyre-technology/msp-claude-plugins Features
- Account Takeover
- Cases
- Messages
- Threats
- Vendors
Skills
This plugin provides 6 skills that teach Claude about Abnormal Security:
| Skill | Description |
|---|---|
account-takeover | Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators. |
cases | Use this skill when working with Abnormal Security abuse mailbox cases - user-reported emails, case triage, remediation actions, case lifecycle, and phishing simulation management. |
messages | Use this skill when working with Abnormal Security message analysis - email headers, attachments, sender reputation, delivery context, authentication results (SPF/DKIM/DMARC), and message metadata. |
threats | Use this skill when working with Abnormal Security threat detection and analysis - BEC, phishing, malware, socially-engineered attacks, spam, graymail, and credential theft. |
vendors | Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain email threat monitoring. |
api-patterns | Use this skill when working with the Abnormal Security REST API - Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, error handling, and common API patterns. |
Commands
Available slash commands:
| Command | Description |
|---|---|
/account-audit | Audit for account takeover indicators and suspicious sign-ins in Abnormal Security |
/case-review | Review and triage abuse mailbox cases in Abnormal Security |
/search-threats | Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords |
/threat-triage | Triage recent email threats detected by Abnormal Security by severity and attack type |
/vendor-risk | Check vendor risk scores and compromised vendor activity in Abnormal Security VendorBase |
API Reference
| Base URL | |
| Authentication | |
| Rate Limit | |
| Documentation |
Example Usage
Audit for account takeover indicators and suspicious sign-ins in Abnormal Security
/account-audit Review and triage abuse mailbox cases in Abnormal Security
/case-review Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords
/search-threats Triage recent email threats detected by Abnormal Security by severity and attack type
/threat-triage Check vendor risk scores and compromised vendor activity in Abnormal Security VendorBase
/vendor-risk Using Skills
/skill abnormal-security:account-takeover
Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators.