Advanced detection at Abnormal
Leading attachment-based threat detection for email security — catching QR, link, OCR, and brand-impersonation attacks across 15+ file types with ML models and AI agents.
Problem
Email attacks outgrew classic gateway signals. Sophisticated campaigns hid payloads in attachments, QR codes, images, and lookalike brands, so detection needed richer payload understanding across email and connected SaaS surfaces.
Approach
- Set up and lead the Advanced Detection & Extended Threats team within the core email security product.
- Built smarter signals covering credential phishing, TOAD/callback attacks, brand impersonations, and payload/link-based threats.
Outcomes
- 01Attachment service catches sophisticated attacks leveraging QR codes, links, OCR, and brand detection
- 02Coverage expanded to 15+ file types — images, docs, PDF, ICS, and more
- 03Control layer selectively processes emails, enabling targeted rules for high-value attacks
- 04Launched Abnormal's first attachment-based ML models — text and visual
- 05AI agents analyze attack misses and recommend detections for similar future attacks
The work, chapter by chapter
Standing up Advanced Detection & Extended Threats
Led and set up the team inside the core email security product, focused on building smarter signals for email and various SaaS attacks.
Attachment service
A service that inspects attachments for sophisticated attacks — QR codes, links, OCR-extracted text, and brand detection signals.
- Catch attack patterns that pure text analysis misses: malicious QR codes, hidden links, image-based phishing, and brand impersonation assets.
- Expanded coverage to 15+ file types including images, documents, PDFs, and calendar invites (.ics).
- Built the control layer that selectively processes emails, enabling targeted rules for catching high-value attacks without blanket processing.
First attachment-based ML models
Launched Abnormal's first machine-learning models working on attachments — both text and visual modalities.
AI agents for detection quality
Agents and tooling that analyze attack misses and power a recommendation system to catch similar attacks going forward.
Developer productivity: Agent Fleet
Built Agent Fleet — easily manage and work across multiple Claude Code sessions covering PR info, CI support, skill invocation, work summaries, and advisor capabilities.
- Multiple skill contributions around testing and dev workflows: review, approval tracking, CI.