Abnormal Security vs Elastic

Abnormal Security — Application · Private · $5.1B valuation · 3 of 3 figures sourced  |  Elastic — Infrastructure · Public · $10.2B mkt cap · 4 of 4 figures sourced

Relationship

AI Governance and Elastic Security do comparable work on threat detection and response; both also serve buyers who need to detect and respond to security threats; similar scale (public).

Assembled from the recorded fields for this pair, not hand-checked. The comparison below is read from each company’s own profile.

3 of 3 capabilitiesShared product type

3 of 3 capabilities — Shares data analysis, threat detection and response and workflow automation.

Ludbee capability tags · from the product records

Shared product type — Both ship application and platform.

Ludbee product records

Aligned comparison

FieldAbnormal SecurityElastic
Size$5.1B valuation$10.2B mkt cap different basis
Employees—4,019
Founded20182012 6 yrs earlier
StatusPrivatePublic
CategoryApplicationInfrastructure
Stack layerAI agent, Application, PlatformAgent platform, Application, Model API, Platform
HeadquartersSan Francisco, USAAmsterdam, Netherlands

Capability overlap

Shared · 3

Data analysisThreat detection and responseWorkflow automation

Not verified for Abnormal Security · 6

Agent orchestrationEvaluation and observabilityModel hostingModel inferenceKnowledge retrievalVector search

Recorded for Elastic. Abnormal Security’s product records say nothing either way — a missing record is not a missing capability.

Abnormal Security has no capability Elastic lacks, among the 3 recorded here.

Products, side by side

Algorithmic pairing — assembled from recorded fields, not hand-checked

Abnormal Security

Application

AI GovernanceApplication

Discovers shadow AI tool/agent/chat usage via email, OAuth, identity and browser signals and enforces policy automatically.

Abnormal AI Data AnalystApplication

Answers security teams' questions about threats, attack patterns and risk across email and SaaS on demand, without writing queries.

Abnormal AI Phishing CoachApplication

Phishing simulation and training that generates its exercises from the real attacks aimed at that organisation rather than from static templates.

Abnormal AI Security MailboxApplication

Automates phishing triage: answers every employee report in seconds and remediates campaign-wide threats without an analyst in the loop.

Email DLP RulesApplication

Combines a custom outbound DLP policy engine with an AI triage agent that evaluates matches in context, releasing benign messages and quarantining likely violations.

Email ProductivityApplication

Behavioral AI that automatically moves low-priority promotional email (graymail) out of the inbox without manual rules.

Identity Threat ProtectionApplication

Behavioral AI that catches hijacked sessions, abused OAuth grants and privilege misuse across email, IdP and SaaS.

Inbound Email SecurityApplication

Behavioral-AI email threat detection that builds per-employee/vendor baselines to catch BEC, phishing and payload-free social engineering before delivery.

Infiltration PreventionApplication

Analyzes identity signals pre-provisioning (HR systems, IdP, email) to detect synthetic personas and coordinated nation-state infiltration campaigns.

Messaging SecurityApplication

Inspects Microsoft Teams and Slack for malicious URLs and weaponized attachments, auto-remediating high-risk messages.

Misdirected EmailApplication

Uses behavioral AI to detect outbound email sent to unintended recipients and quarantines it before delivery.

Security Posture ManagementApplication

Checks a Microsoft 365 environment against CIS Benchmarks, detects configuration drift in real time and provides prioritized remediation.

Platform

Abnormal AIPlatform

Behavioural AI platform, powered by Abnormal's own Attune model, that baselines normal behaviour for every employee and vendor to detect phishing, business email compromise and account takeover that signature-based filters miss.

AttunePlatform

Abnormal's behavioural AI foundation model: builds a baseline for every identity from billions of signals so the products above it can flag anomalies in real time.

Elastic

Application

Elastic AI SOC EngineApplication

An AI security-operations layer that correlates alerts from a customer's existing security tools, prioritizes threats and guides response workflows without replacing their SIEM.

Elastic AIOpsApplication

GenAI- and ML-driven capability inside Elastic Observability that automatically detects, diagnoses and helps resolve operational issues, providing recommended actions for SREs.

Elastic LLM ObservabilityApplication

Monitoring capability inside Elastic Observability for generative-AI and agentic applications: performance, cost control, guardrail tracking and reliability for GenAI workloads.

Elastic SecurityApplication

Agentic security-operations platform unifying SIEM, XDR and native automation, with autonomous agents handling detection-to-response workflows and purpose-built AI skills for threat hunting, alert analysis and detection engineering; supports multiple LLMs including on-premises models.

Platform

Elastic AI AssistantPlatform

A conversational assistant embedded in Kibana that answers natural-language questions against a customer's own indexed data across Elastic's Observability, Security and Search solutions.

No counterpart

Abnormal Security sells these in a stack layer with no product recorded for Elastic yet — nothing on the other side to compare them against.

AI agent

Account Takeover ProtectionAI agent

Detects and autonomously remediates compromised Microsoft 365/Google Workspace accounts by learning normal sign-in, device and behavioral patterns.

Elastic sells these in a stack layer with no product recorded for Abnormal Security yet — nothing on the other side to compare them against.

Agent platform

Elastic Agent BuilderAgent platform

A builder for custom AI agents that answer questions and take actions over data indexed in Elasticsearch, using configurable tools, skills and prompts.

Elastic WorkflowsAgent platform

An automation engine that runs both scripted steps and AI agents which reason through investigations and execute response actions against data in Elasticsearch.

Model API

Elastic Inference ServiceModel API

Hosted inference endpoint that runs Elastic-managed LLMs, the ELSER sparse-embedding model and third-party embedding models for ingest, search and chat without provisioning ML nodes in a customer's own Elasticsearch deployment.