Introducing Search and Respond: Find and Remediate Messages with Ease

August 25, 2021

Finding messages and purging them within a few clicks is a top priority for many of our customers. We’re pleased to announce that our new Search and Respond feature, designed to solve for this use case, is now available.

These search and respond capabilities are particularly helpful for security investigations and compliance purposes. For example, if an employee accidentally sent a sensitive message internally, if an employee is wondering where a message is, or in the rare situations when an attack or spam message is not blocked by security tools, Search and Respond will allow you to find the message and remediate it immediately.

How to Use Search and Respond

You can search by fields like sender, recipient, and subject, and then see a list of messages that were sent, as well as associated metadata, including the email location. Then, you can either click a message to view message bodies and headers, or directly remediate messages to the recoverable deleted items folder where employees cannot interact with them.

Message discovery

Key Benefits of Search and Respond

Additional benefits to our customers include:

  • Lightning fast search for the past 30 days. For recent messages received within the past 30 days, Abnormal offers Quick Search—a fast and reliable solution built using APIs and Abnormal infrastructure. Quick Search works in seconds and supports both Office 365 and Google Workspace tenants.
  • Full search for messages older than 30 days. For Office 365 customers interested in searching for older messages, Abnormal offers Full Search, which is built as an integration with Microsoft Content Search. You no longer need to write Powershell scripts for searches and purges! With Quick Search and Full Search, O365 customers get the best of both worlds in terms of search speeds and search history.
  • Robust security and privacy features. Searching your tenant for emails is sensitive, so Abnormal offers role-based access control and audit logging. Administrators can provision users with the ability to use Search and Respond and view message bodies. Once provisioned, Administrators can feel confident that the tool is being used appropriately by keeping tabs on the Activity Log, which keeps records of all searches and remediations. Abnormal retrieves message bodies in real-time via an API call for maximum privacy.
Activity log

Try Search and Respond Today

Your time as a security analyst is valuable. With Search and Respond, you can save time and increase visibility—making it easier than ever to ensure that your organization is protected. Search and Respond is now available to all customers within the Abnormal Security portal. Please reach out to your support representative with questions.

Curious to see how Search and Respond could work for you? Request a demo today.

Blog purple person outline
Identity theft is not a joke, impacting more than 14 million people each year in the United States alone. Over the course of their lifetime, nearly one-third of all people will become victims of identity theft—often as a result of a corporate data breach. Once attackers have access to identifying information like your full name, address, date of birth, and/or social security number...
Read More
Blog yellow microsoft squares
Security is now a $10 billion business for Microsoft, and the company is a leader in five Gartner Magic Quadrants—access management, endpoint management tools, cloud access security brokers, enterprise information archiving, and endpoint protection platforms. This validation proves that their customers...
Read More

Related Posts

B 10 15 21
With Detection 360, submission to threat containment just got 94% faster, making it incredibly easy for customers to submit false positives or missed attacks, and get real-time updates from Abnormal on investigation, conclusion, and remediation.
Read More
Extortion blog cover
Unfortunately, physically threatening extortion attempts sent via email continue to impact companies and public institutions when received—disrupting business, intimidating employees, and occasioning costly responses from public safety.
Read More
Blog engineering cybersecurity careers
Cybersecurity Careers Awareness Week is a great opportunity to explore key careers in information security, particularly as there are an estimated 3.1 million unfilled cybersecurity jobs. This disparity means that cybercriminals are taking advantage of the situation, sending more targeted attacks and seeing greater success each year.
Read More
Blog hiring cybersecurity leaders
As with every equation, there are always two sides and while it can be easy to blame users when they fall victim to scams and attacks, we also need to examine how we build and staff security teams.
Read More
Cover automated ato
With an increase in threat actor attention toward compromising accounts, Abnormal is focused on protecting our customers from this potentially high-profile threat. We are pleased to announce that our new Automated Account Takeover (ATO) Remediation functionality is available.
Read More
Email spoofing cover
Email spoofing is a common form of phishing attack designed to make the recipient believe that the message originates from a trusted source. A spoofed email is more than just a nuisance—it’s a malicious communication that poses a significant security threat.
Read More
Cover cybersecurity month kickoff
It’s time to turn the page on the calendar, and we are finally in October—the one month of the year when the spooky becomes reality. October is a unique juncture in the year as most companies are making the mad dash to year-end...
Read More
Ices announcement cover
Abnormal ICES offers all-in-one email security, delivering a precise approach to combat the full spectrum of email-borne threats. Powered by behavioral AI technology and deeply integrated with Microsoft 365...
Read More
Account takeover cover
Account takeovers are one of the biggest threats facing organizations of all sizes. They happen when cybercriminals gain legitimate login credentials and then use those credentials to send more attacks, acting like the person...
Read More
Blog podcast green cover
Many companies aspire to be customer-centric, but few find a way to operationalize customer-centricity into their team’s culture. As a 3x SaaS startup founder, most recently at Orum, and a veteran of Facebook and Palantir, Ayush Sood...
Read More
Blog attack atlassian cover
Credential phishing links are most commonly sent by email, and they typically lead to a website that is designed to look like common applications—most notably Microsoft Office 365, Google, Amazon, or other well-known...
Read More
Blog podcast purple cover
Working at hyper-growth startups usually means that unreasonable expectations will be thrust on individuals and teams. Demanding timelines, goals, and expectations can lead to high pressure, stress, accountability, and ultimately, extraordinary growth and achievements.
Read More