Product | 3 min read
New Ruxie AI power-up: Precedent engine turns repetitive alerts into faster decisions

Ruxie's precedent engine feature is a long-term memory for Expel's SOC, using AI to instantly recognize when a new alert matches previous historical cases.

Product | 2 min read
What we built: August 2026

This month we released MDR for AI—coverage for the AI attack surface—along with CSV exports and a new home for product documentation.

Product | 4 min read
New Ruxie AI power-up: Meet rapid triage agent, the AI agent bringing self-challenging logic to identity and cloud alert triage

Rapid triage agent (RTA) is Ruxie's latest power-up. It performs first-pass investigations and stress-tests its own reasoning to eliminate bias.

Product | 3 min read
Expel now covers the full AI attack surface

Expel is the top MDR provider covering the full AI attack surface: AI-powered attacks, employee misuse, and exposure inside AI systems. See what's live now.

Product | 3 min read
What we built: July 2026

In July, Expel launched six new threat hunts spanning the AI attack surface, for new features, and one integration update.

Product | 2 min read
What we built: June 2026

See what Expel shipped in June 2026, including two new threat hunts and updated CrowdStrike Falcon detection coverage.

Product | 5 min read
Ruxie AI now covers every stage of the threat lifecycle

Expel extends Ruxie with new agentic AI capabilities across every stage of the threat lifecycle—from enrichment and detection to response and reporting.

Product | 3 min read
New Ruxie AI power-up: Blocked malware triage agent clears the noise

Ruxie, our AI SOC manager, has a new power-up that automatically enriches and triages blocked malware alerts end to end, saving analysts time.

Product | 2 min read
What we built: May 2026

See what Expel shipped in May 2026—including three new threat hunts, a new alert grid view in Workbench, and a Ruxie-powered blocked malware triage agent.

Product | 3 min read
What we built: April 2026

Expel shipped two new threat hunts, AI-powered DUET and verify summaries, SentinelOne and Zendesk status syncing, and two new integrations in April.

Product | 3 min read
What we built: March 2026

In March, Expel shipped four new features and one new integration we're sharing with you, including our new Mimecast email integration.

Product | 2 min read
Mimecast customers: Expel MDR for Email is now available for you

Expel MDR coverage for email now supports Mimecast, adding a fourth email security integration to our lineup.

Product | 3 min read
Your SIEM, our detection engineering, no black boxes: Introducing Expel Managed SIEM

We're launching Expel Managed SIEM: a transparent, co-managed service for Splunk and Microsoft Sentinel paired with Expel MDR.

Product | 2 min read
New Ruxie AI power-up: Related alert summaries turns endless logs into an instant attack narrative

Our new Ruxie AI power-up, related alert summaries, automatically analyzes and transforms disparate source alerts into a clear, chronological narrative.

Product | 4 min read
New Ruxie power-up: AI detection agent automatically layers defenses on new third-party alerts

Expel's latest Ruxie power-up, detection agent, automatically identifies coverage gaps in vendor telemetry and proposes new detection rules.

Product | 3 min read
Direct to the SOC: Enhanced collaboration with Expel’s analysts

We're introducing bi-directional threaded commenting that natively connects Slack and Teams to Expel Workbench.

Product | 1 min read
What we built: February 2026

This month we’re featuring two new features and three new integrations from Expel's product team, including what they are and why they matter.

Product | 3 min read
New Ruxie AI power-up: Getting to the “so what” of your alerts faster

We’ve added a new natural language summary feature to Expel Workbench™, powered by Ruxie, our AI and automation engine. 

Product | 2 min read
Expel deepens its partnership with support for CrowdStrike Falcon Next-Gen SIEM

Expel now integrates with CrowdStrike Falcon Next-Gen SIEM (NG-SIEM), expanding our existing partnership with CrowdStrike.

Product | 5 min read
How we built it: Expel’s latest RMM detections

Expel is leveling up its detection capabilities against remote monitoring and management tools (RMMs). Here's how we're doing it.

Product | 2 min read
What we built: January 2026

Here's what Expel's product team shipped in January. This month, we're highlighting new webhooks for phishing and dark mode for Workbench.

Product | 5 min read
New Ruxie AI power-up: “Pop the hood” on our detection strategies

Expel added new AI-generated descriptions to our detection rules, written in plain English, to improve transparency and understanding.