Abnormal Security detects email attacks with behavioral AI on Databricks
Abnormal Security migrated from a legacy Hadoop system to the Databricks Data + AI Platform on AWS, using Delta Lake and Databricks SQL to stream threat signals from Kinesis Firehose and power behavioral AI models analyzing over 50,000 signals to detect email attacks, achieving a 20% reduction in successful email attacks, a 40% reduction in infrastructure costs, and a 30%+ increase in productivity.
Overview
Abnormal Security migrated from a legacy Hadoop system to the Databricks Data + AI Platform on AWS, using Delta Lake and Databricks SQL to stream threat signals from Kinesis Firehose and power behavioral AI models analyzing over 50,000 signals to detect email attacks, achieving a 20% reduction in successful email attacks, a 40% reduction in infrastructure costs, and a 30%+ increase in productivity.
This entry has 12 published fields tied to exact passages in an immutable source capture.
Inspect the highlighted sourceThe challenge
Abnormal Security's legacy Hadoop system with long-running AWS EMR clusters wasn't going to scale efficiently with rapidly increasing demand, and engineers were spending too much time managing Spark infrastructure instead of building pipelines that would make the product better; a shared Jupyter notebook server also slowed processing for everyone when heavy applications ran.
The solution
Abnormal Security migrated to the Databricks Data + AI Platform on AWS, using Delta Lake to stream threat signals from Kinesis Firehose into near real-time storage and Databricks SQL for dashboards, powering behavioral AI models that analyze over 50,000 signals to detect and remediate email attacks.
Reported business value
Abnormal Security achieved a 20% reduction in successful email attacks, a 40% reduction in infrastructure costs, and 30%+ productivity gains for its data science and data engineering teams, while processing thousands of emails per second.
Sources
Open any source and check the claim yourself — that is the point of the register.
This record was researched and written with AI assistance, and its claims were checked against the sources above. (EU AI Act art. 50 transparency notice.)
Other cybersecurity entries in the register.
Vega's cyber defense platform returns 67% of analysts' time with Claude
Vega, an agentic cyber defense platform used by Fortune 200 companies, global banks and healthcare providers, built an agentic detection-triage-investigation-optimization loop that runs Claude directly on security data where it lives, avoiding costly SIEM ingestion, delivered via Amazon Bedrock including an EU-resident deployment in Frankfurt for GDPR compliance. Across production deployments, customers reclaim roughly 67% of analyst time, complete investigations up to 44 times faster at 82% lower cost than legacy SIEMs, and one Fortune 500 insurer cut mean time to triage from 25 minutes to under 3 minutes.
CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%
CyberArk redesigned its technical support pipeline using AWS Fargate, PyIceberg and Amazon Bedrock (Claude 3.7 Sonnet) to auto-generate grok patterns for parsing diverse vendor log formats into Iceberg tables, and built autonomous AI agents that query Athena and CyberArk's knowledge base to perform root-cause analysis from natural-language questions. The system cut case resolution time by up to 95% (complex cases from up to 15 days to 2-4 hours), let engineers handle up to 4x more cases per day (from 2-3 to 8-12), and made logs queryable within minutes instead of hours or days.
Cyera scales agentic AI across 1,500 employees with Claude Enterprise
Cyera, an AI data security platform, rolled out Claude Cowork company-wide to all 1,500 employees in 17 days, connecting it to 40 tools including Slack, Salesforce, Asana, Google Drive and Notion, plus a governed Snowflake semantic layer of 40 documented tables built by its data engineering team. Weekly active usage of Claude reached 88% across the company. A scheduled task now triages Cyera's internal Ask Claude Slack channel, cutting daily triage from five-to-six hours to about 30 minutes, and the legal team launched a Cowork plugin with 20 playbooks that pre-reviews inbound vendor NDAs against Cyera's negotiating positions.
Barracuda Networks Protects With AI
Barracuda Networks unified customer and product telemetry data using Databricks and AI to power BarracudaONE, an AI-powered platform delivering real-time threat detection and automated response by combining signals across attack vectors, securing hundreds of thousands of businesses worldwide.
Was this helpful?
Your feedback helps us improve our use case database
