Threat intel
You don’t find ManualFinder, ManualFinder finds you

We're investigating ManualFinder, a trojan malware we're seeing in new activity, likely coming from potentially unwanted programs (PUPs).

MDR | 5 min read
Cybersecurity myths from the depths of Reddit (that security pros want you to know about)

Cybersecurity professionals often take to Reddit to share thoughts with their community. You can learn more secure practices from it, too.

Product | 2 min read
Email coverage expansion: Sublime Security integration now live

Expel MDR for Email now integrates with Sublime Security for enhanced threat visibility across your inboxes.

MDR | 3 min read
Getting real value from your Palo Alto investment: how Expel MDR transforms security operations

Expel MDR reduces Palo Alto alert noise by 87% with 17-minute response times. Expert 24x7 analysis maximizes your security investment ROI.

Threat intel | 17 min read
The history of AppSuite: the certs of the BaoLoader developer

We're tracking the malware BaoLoader and their fraudulent code-signing certificates via AppSuite-PDF and PDF editor campaigns.

Current events | 3 min read
Patch Tuesday: September 2025 (Expel’s version)

This month, we're highlighting top critical vulnerabilities, including an SAP S/4HANA code injection vulnerability currently being exploited.

Product | 6 min read
From data to deployment: A deep dive into building our AI Resolutions (part two)

Dive deeper into Expel's AI Resolutions (AIR) and understand how we developed and tested this feature for our analysts.

Product | 3 min read
Explaining the ‘why’: Our vision for AI-powered alert transparency (part one)

Expel created AI Resolutions (AIR) uses AI to generate detailed, data-backed explanations for why a security alert was considered benign.

Product | 5 min read
Explore Expel’s auto remediations: Remove malicious email

In this series, we explore Expel's auto remediations so you understand how they work. Let's explore remove malicious email.

Threat intel | 10 min read
You don’t find ManualFinder, ManualFinder finds you

We're investigating ManualFinder, a trojan malware we're seeing in new activity, likely coming from potentially unwanted programs (PUPs).

Expel culture | 3 min read
Meet the Expletive: James Shank, Director of Threat Operations

Meet James Shank, Expel's first Director of Threat Operations. We cover James' past career experience, and why he thrives in the chaos.

Product | 2 min read
Level up your cloud defense: Expel’s Wiz Defend integration is now live

Expel's partnership with Wiz Defend gives mutual customers richer alert context, faster response times, and streamlined cloud security.

Product | 3 min read
Unlocking more from your CrowdStrike investment

Expel cuts through the flood of CrowdStrike alerts by 91% on average to maximize your security tools with strong API connections.