Abnormal Security vs Datadog
Relationship
Account Takeover Protection and Bits Security Analyst do comparable work on threat detection and response; both also serve buyers who need to detect and respond to security threats; larger scale (public).
Assembled from the recorded fields for this pair, not hand-checked. The comparison below is read from each company’s own profile.
3 of 3 capabilities — Shares data analysis, threat detection and response and workflow automation.
Ludbee capability tags · from the product recordsShared product type — Both ship AI agent and application.
Ludbee product recordsLarger scale — Datadog: $84.9B market cap, against Abnormal Security's $5.1B valuation.
Ludbee scale figures · valuation, market cap or revenue estimateAligned comparison
Capability overlap
Shared · 3
Not verified for Abnormal Security · 6
Recorded for Datadog. Abnormal Security’s product records say nothing either way — a missing record is not a missing capability.
Abnormal Security has no capability Datadog lacks, among the 3 recorded here.
Products, side by side
Algorithmic pairing — assembled from recorded fields, not hand-checked
Abnormal Security
Application
Discovers shadow AI tool/agent/chat usage via email, OAuth, identity and browser signals and enforces policy automatically.
Answers security teams' questions about threats, attack patterns and risk across email and SaaS on demand, without writing queries.
Phishing simulation and training that generates its exercises from the real attacks aimed at that organisation rather than from static templates.
Automates phishing triage: answers every employee report in seconds and remediates campaign-wide threats without an analyst in the loop.
Combines a custom outbound DLP policy engine with an AI triage agent that evaluates matches in context, releasing benign messages and quarantining likely violations.
Behavioral AI that automatically moves low-priority promotional email (graymail) out of the inbox without manual rules.
Behavioral AI that catches hijacked sessions, abused OAuth grants and privilege misuse across email, IdP and SaaS.
Behavioral-AI email threat detection that builds per-employee/vendor baselines to catch BEC, phishing and payload-free social engineering before delivery.
Analyzes identity signals pre-provisioning (HR systems, IdP, email) to detect synthetic personas and coordinated nation-state infiltration campaigns.
Inspects Microsoft Teams and Slack for malicious URLs and weaponized attachments, auto-remediating high-risk messages.
Uses behavioral AI to detect outbound email sent to unintended recipients and quarantines it before delivery.
Checks a Microsoft 365 environment against CIS Benchmarks, detects configuration drift in real time and provides prioritized remediation.
AI agent
Detects and autonomously remediates compromised Microsoft 365/Google Workspace accounts by learning normal sign-in, device and behavioral patterns.
Datadog
Application
Detects AI-assisted pull requests from coding assistants such as Claude Code, Cursor and GitHub Copilot and compares them on adoption, PR throughput, cycle time, change failure rate and daily cost per active user.
Conversational AI interface for querying Datadog metrics, logs, traces and monitors in natural language and generating dashboards and notebooks, accessible from Datadog, Slack or mobile.
Datadog's Infrastructure-family product for shared GPU fleets across cloud, on-prem and neocloud providers: it links device health, cost and performance to the workloads and teams using them, alerts on unmet GPU requests, thermal throttling and ECC/XID errors, forecasts GPU demand and recommends optimisations such as reclaiming GPUs held by zombie processes. The page markets alerting, forecasting and recommendations but does not name a model or AI mechanism behind them.
Datadog's built-in AI engine: it continuously analyses metrics, traces and logs across the platform to raise anomaly alerts without configuration, detect faulty deployments by comparing code versions, run automated root-cause analysis on critical failures and surface tag-based insights and impact analysis. Available inside Infrastructure Monitoring, APM, Log Management and RUM rather than sold on its own.
AI agent
Coding agent that triages production errors, regressions and vulnerabilities from Datadog telemetry, generates fixes with unit tests grounded in logs, traces and runtime variables, and opens pull requests for review.
AI SRE agent that autonomously investigates every alert the moment it fires, explores multiple root-cause hypotheses in parallel and reports findings into Slack, Jira, ServiceNow or GitHub.
Always-on AI SOC analyst that autonomously triages and investigates security alerts and delivers written investigation results to Datadog, Slack or Jira within minutes.
No counterpart
Abnormal Security sells these in a stack layer with no product recorded for Datadog yet — nothing on the other side to compare them against.
Platform
Behavioural AI platform, powered by Abnormal's own Attune model, that baselines normal behaviour for every employee and vendor to detect phishing, business email compromise and account takeover that signature-based filters miss.
Abnormal's behavioural AI foundation model: builds a baseline for every identity from billions of signals so the products above it can flag anomalies in real time.
Datadog sells these in a stack layer with no product recorded for Abnormal Security yet — nothing on the other side to compare them against.
Agent platform
No-code builder for custom AI agents that investigate, decide and act inside Datadog to automate incident response, observability, security and operational workflows.
Developer tool
Traces, evaluates and monitors LLM and AI-agent applications in production, with offline experimentation on datasets built from real traces.
Model Context Protocol server that gives AI coding agents such as Claude Code, Cursor and Codex secure real-time access to Datadog logs, metrics and traces under existing RBAC controls.