> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Abnormal

## Overview

Abnormal Security is an email security platform that protects organizations from targeted email attacks such as phishing and business email compromise. This guide walks through how to create an Abnormal connection and the access it requires to be used in Blink's Automated Case Management, primarily for **Ingestion** and **Enrichment** workflows (pulling email-threat cases and their context into Blink).

***

## Creating a Connection

<Card title="Abnormal Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/abnormal">
  Follow this guide to create an Abnormal connection
</Card>

***

## Required Access

Abnormal has no per-endpoint scope selection. Access is granted by the **API key** itself. The data available to Blink is determined by your Abnormal account and the key's associated privileges, configured on the Abnormal side.

| Setting | Value | Notes |
| - | - | - |
| Authentication | API Key | Passed by Blink as a Bearer token to the Abnormal REST API |
| Permissions | Defined by your Abnormal account | Abnormal does not expose granular API scopes; the key inherits the account's access |

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Ingests Abnormal email-threat cases as alerts (phishing use case) |
    | Enrichment | ✓ Yes | Adds email-threat context to cases |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.