TL;DR
- Rapid alert disposition (RAD) is an autonomous Ruxie AI agent that performs first-pass investigations on high-volume identity and AWS cloud alerts in under 60 seconds.
- To eliminate bias and prevent automated misses, RAD stress-tests its own reasoning when evidence is ambiguous by executing benign-hypothesis tests or attack-scenario audits before setting alert severity.
- RAD elevates urgent threats to the top of the analyst queue to lower attacker dwell time and accelerate analyst response, while keeping expert human analysts as the sole decision-makers for every alert disposition.
Real account takeovers and cloud compromises hide in high-volume, noisy telemetry. Finding them before an adversary establishes persistence requires evaluating complex session evidence, user history, and multi-stage behaviors the instant an alert triggers.
At Expel, our Managed Detection and Response (MDR) platform ingests alerts and telemetry from over 160 third-party security tools across endpoint, firewall, SIEM, cloud, and identity environments. While point solutions excel inside their specific domains, Expel finds the adversary in the quiet spaces between those tools—layering proprietary, high-fidelity detection rules over vendor telemetry to connect the dots across multi-stage attack campaigns.
To translate this rich volume of telemetry into immediate operational velocity for your enterprise, we are excited to roll out a brand new Ruxie AI power-up: the rapid alert disposition (RAD) investigation agent.
RAD acts as an autonomous AI teammate that performs a rigorous first pass of investigation on identity and AWS cloud alerts in under 60 seconds, ensuring that when our SOC analysts step in, they start from an informed, experienced analysis rather than a blank slate.
Turning high-volume telemetry into immediate focus
Identity and cloud alerts—such as suspicious logins, account takeover (ATO) indicators, and AWS cloud compromises—arrive at relentless volume across modern enterprise environments. Evaluating these signals thoroughly requires verifying session evidence, cross-referencing user history, weighing vendor telemetry, and documenting investigative reasoning.
When queues fill up with medium-severity signals or routine chatter, human attention gets divided. Manual initial triage causes delays in time-to-coverage, and leaves rich vendor telemetry as underutilized signals, while analysts gather context step by step.
Completing a fast, consistent initial investigation the moment telemetry arrives ensures high-severity threats rise immediately to the top of the analyst queue, while benign noise settles down. By delivering an informative first pass in under a minute, security analysts get immediate clarity on every alert.
Meet RAD, your autonomous AI investigator
RAD functions as Ruxie’s dedicated AI teammate for first-pass identity and cloud triage. The moment an alert surfaces, RAD ingests the event and its supporting evidence—including Expel-automated investigation outputs, identity classification results, related alerts, historical user activity, customer context, and enriched cloud telemetry.
It reasons through the telemetry using the structured workflow of an experienced tier 1 analyst and delivers a clear read across identity threat vectors and AWS cloud environments:
| RAD read | Operational meaning |
|---|---|
|
Known good |
Activity is clearly benign based on contextual evidence. |
|
Known bad |
Clear malicious or unauthorized activity identified. |
|
Needs more information |
Evidence is genuinely ambiguous; RAD details whether signals lean good, bad, or unclear. |
Every RAD evaluation produces a structured investigative action inside Expel Workbench™, giving your security team complete transparency into key corroborating facts, calibrated confidence scores, and recommended next steps.
Queue prioritization and network-wide protection
RAD directly strengthens the defense of your enterprise through two key capabilities:
- Shorter attacker dwell time & accelerated SLOs: RAD dynamically adjusts alert severity based on its investigation. Promoting critical threats out of the medium-severity queue gets human eyes on urgent alerts faster, slashing attacker dwell times and helping our analysts consistently meet stringent service level objectives (SLOs) on your behalf.
- Global-basis learning & network defense: RAD is trained on outcomes across Expel’s entire customer base. The longer your organization stays with Expel, the more your defense compounds: threat patterns, tool configurations, and attacker tactics observed in one environment actively inform the models protecting yours. Malicious signals or unique tool configurations detected across the broader network directly strengthen protection for your specific environment.
Autonomous pipeline with adversarial self-challenge
Standard market AI tools rely on manual, chat-based copilots that require users to type prompts into a side panel and wait for generated answers. Expel engineered RAD as an autonomous, event-driven pipeline integrated directly into our core investigation engine, executing structured reasoning behind the scenes the moment telemetry arrives.
RAD also incorporates an advanced safeguard when evaluating mixed or uncertain evidence: the distractor review. When RAD encounters ambiguous evidence, it executes an adversarial self-challenge before committing to its final call:
- When leaning bad: RAD constructs the strongest innocent explanation possible and verifies whether the evidence genuinely rules it out.
- When leaning good: RAD constructs the strongest attack scenario and actively searches for positive proof of legitimate activity, verifying real proof alongside the absence of red flags.
Only when this self-challenge fails to disprove the initial call does the conclusion stand. If certainty remains low, RAD suppresses its leaning to “unclear” and passes the alert straight to an analyst.
Speed for us, absolute control for you
Expel maintains strict efficacy and accuracy standards by keeping expert human analysts at the center of every security outcome. Advanced AI capabilities turn our engineers into expert editors who validate conclusions with speed and precision.
RAD never auto-closes or resolves an alert. Every single close, escalation, and final disposition call stays entirely with an expert Expel analyst. RAD sets alert priority so true risks rise to the top, while analysts maintain full authority to override RAD at any time. Decision disagreements provide direct feedback used to continuously refine and calibrate Ruxie’s underlying models over time.
Measuring what matters
RAD’s architecture delivers speed, data privacy, and full operational transparency across every evaluation:
- Sub-minute triage velocity: Completes comprehensive initial triage in under 60 seconds per alert, accelerating mean time to respond (MTTR).
- Enterprise privacy boundaries: Operates on Claude Sonnet via AWS Bedrock within Expel’s standard data-handling posture. For more about how Expel handles customer data securely, see our Expel Workbench and Services Privacy Policy found here: https://expel.com/notices/#workbench.
- Self-challenging calibration: Automatically triggers adversarial stress-testing on moderate-confidence evaluations to prevent bias and ensure only validated conclusions guide queue priority.
- Continuous accuracy benchmarking: Evaluated continuously against real analyst decisions to maintain accuracy.
By embedding autonomous, self-challenging AI logic directly into our triage pipeline, RAD powers up security operations with instant clarity on identity and cloud threats. Your organization gains shorter attacker dwell times, faster triage, and full visibility into every AI reasoning path directly within Workbench.
To see RAD’s investigative actions in your environment, log in to Workbench or reach out to our team to learn more.


