Every environment has its own definition of normal. In Q3, Adlumin introduced new detections that learn each customer’s definition of normal, giving partners high-confidence visibility into attacker behavior that hides in everyday activity: trusted tools used in unusual ways, hijacked Microsoft 365 sessions, and brute force attempts measured against each user’s own patterns. Q3 also made Incident Response available to MSPs and extended automated account response to Google Workspace Custom Detections.
Here are the highlights.
New Detections That Learn Each Customer’s Normal
Three new detections share one idea: learn what normal looks like for each customer, then recognize when something isn’t.
Anomalous Process Execution: Seeing Attackers Who Use Trusted Tools
Attackers increasingly work with legitimate, signed tools instead of obvious malware. Anomalous Process Execution Activity uses machine learning to learn what normal process behavior looks like in each environment, then flags what stands out. Every alert arrives with the network activity, reputation data, and plain-language AI command line analysis an analyst needs to reach a verdict quickly.
What you get: High-confidence detection of living-off-the-land techniques like obfuscated scripting and suspicious outbound communication, with explainable risk scoring and the context to act on it quickly.
Enhanced M365 Session Hijacking Detection: Protection That Follows Behavior, Not Location
Attackers using VPNs and anonymizers can make a hijacked session appear to come from the legitimate user’s location. Our AI-powered anomaly detection looks at how the session behaves, so it can identify and remediate suspicious activity even when the attacker is hiding their tracks.
What you get: Stronger protection for Microsoft 365 and Azure identities, working automatically in the background with no configuration changes. Available now for all Adlumin customers.
Adaptive Brute Force Protection: Thresholds Built Around Each User and Tenant
Brute force detection is built on what’s normal for each user and tenant. Starting with Windows failed logons (Event 4625), Adlumin sets thresholds per user and per tenant instead of applying one fixed number to everyone. This is the first brute force detection built on our Univariate Modeling Framework, with more to follow.
What you get: Higher-fidelity alerts that reflect how each environment actually behaves. Every alert includes model details, so analysts can see why it fired.
Expert Help When an Incident Runs Deep: Incident Response for MSPs
When an incident goes beyond containment, our Adlumin experts are ready for deeper investigation, coordinated response leadership, and guidance through the full compromise. The Incident Response add is now available for MSPs using Adlumin MDR.
Partners can purchase hours in advance as a retainer or engage the team during an active incident. Buying in advance is the recommended path: the hours are planned and budgeted before you need them, so an incident day is spent responding, not arranging approvals.
What you get: One continuous team from first alert to full recovery, faster scoping, clearer decisions, and incident response cost you can plan for instead of absorb.
Automated Response for Google Workspace Custom Detections
Not every customer runs on Microsoft. Partners and detection engineers who build Custom Detections for Google Workspace can now link them directly to SOAR playbooks that disable or enable an account. Containment starts the moment the detection fires, day or night. It’s a workflow that will feel familiar to partners already using SOAR actions with Microsoft 365.
What you get: Compromised Google Workspace accounts contained without waiting for a person, a consistent approach across customers on Microsoft and Google, and an audit trail of every response action.
Wrapping up
Q3 comes down to what partners can promise their customers. Threats that hide in everyday activity get found with high confidence, because Adlumin knows what normal looks like for each environment. When an incident runs deep, partners have expert leadership behind them and a cost they planned for in advance. And for customers using Google Workspace, a compromised account can be contained the moment a Custom Detection fires, whether or not anyone is at a keyboard. The result is a service partners can stand behind on their best day and their worst.
A Heads-Up for Those Who Like an Early Look
Two previews are ready for you to try. Preview features are early access and may change before general availability.
Natural Language AI Log Search (Preview): Available now in Analysis > Research. Ask a question in plain language and get an answer with the matching logs, without learning query syntax or field names. The query behind every answer is open for you to inspect and edit, so you can verify what ran and refine it. You can also vote on your results right on the screen to help shape what comes next.
Adlumin–Cove Integration (Limited Preview): Backup telemetry from Cove adds an early ransomware warning signal to your detection picture. Interested in joining the preview? Reach out to your CSM to secure your spot in the preview program.
As always, review the full Release Notes for a deeper dive.