TL;DR
- This is a monthly recap of everything our product team shipped in the last 30 days
- Questions? Reach out to your Expel contact, or if you don’t have one, connect with us here
- This month we’re featuring a new AI investigation agent, two triage upgrades, and a new status syncing integration for Palo Alto Networks Cortex XDR
New threat hunts
Six new threat hunts target AI risk across identity and endpoint
What they cover:
- AI app sign-ins in Entra ID: Inventories every AI assistant, copilot, and third-party AI tool your team signs into with a corporate identity, and profiles how each one behaves.
- AI baseline and shadow AI hunt: Inventories every AI tool and service touching the environment, sanctioned or not, across process execution, DNS, and command-line activity.
- Rare process lineages using AI tools or domains: Flags hosts where AI activity and a rare LOLBin parent-child process pairing show up in the same window.
- AI guardrail files modification: Watches admin-only AI policy files for unauthorized changes that would loosen an agent’s guardrails.
- Anomalous process creation from common AI tools: Surfaces AI tool binaries spawning a shell, interpreter, or LOLBin, which they shouldn’t do under normal use.
- Common AI tools going to rarely seen domains: Correlates AI tool activity with DNS requests outside a curated allowlist of about 40 known AI vendor domains.
Why it matters: Every one of these hunts assumes the same thing: most AI usage in your environment is legitimate, and that’s what makes the rest visible. An AI coding tool that spawns a shell, a guardrail file edited by a non-admin process, or a “Claude” binary phoning home to a domain nobody’s ever seen—none of that is normal, and there’s now a hunt looking for each one (MITRE ATT&CK T1218, T1562.001, T1036, T1078.004; MITRE ATLAS AML.T0007, AML.T0047).
Live this month
Phishing classification
What it covers: Expel Phishing now runs a new ML classifier that automatically closes high-confidence benign phishing submissions. Phishing generates more volume than almost any other alert type, and the large majority of it is benign. Phishing classification clears that majority on its own, consistently, regardless of shift or volume.
Why it matters: The classifier only touches benign email. Anything malicious still goes to analysts exactly as it does today, and auto-close is the only action it takes—no severity changes, no escalations. Every auto-close shows its decision drivers, and analysts can reopen any of them. If you’re on the managed phishing service, this is already running on your incoming submissions.
Rapid alert disposition (RAD) investigation agent
What it is: RAD is a new AI agent that runs the first pass of investigation on identity and AWS cloud alerts, before an analyst picks them up. It reads the alert and its supporting evidence, reasons through it the way an experienced Tier 1 analyst would, and produces a read of known good, known bad, or needs more information, along with a confidence score, the key facts that matter, and recommended next steps. It’s human-led: RAD sets the alert’s priority so the right alerts rise to the top, but it never closes an alert on its own—every close and escalation still goes through an analyst.
Why it matters: Identity and cloud alerts are high-volume and time-consuming to work, and they’re where real account takeovers and cloud compromises hide. Every one still needs a human to check the login and session evidence, cross-reference prior history, weigh the vendor signal, and document the reasoning, regardless of who’s on shift or how busy the queue is. RAD does that first pass in under a minute so analysts start from an informed frame instead of a blank slate, which means shorter attacker dwell time and a faster mean time to respond.
Faster, more consistent triage on phishing and repeat alerts
Two new AI triage capabilities are now live: alert similarity in triage, and phishing classification.
Alert similarity in triage: When an alert closely resembles ones we’ve already triaged, this capability surfaces the most similar past cases and how they were closed, so analysts triage with the benefit of precedent instead of starting cold on every alert. It’s decision support that doesn’t close alerts or change severity or routing.
Phishing classification: A new model helps our SOC recognize benign phishing submissions faster, cutting down the manual review time spent on emails that turn out to be nothing so analysts can focus on the ones that aren’t.
Security Device notification conditions now available for Verify and Notify Actions
Last month’s security device notification condition is now available for Verify Actions and Notify Actions, in addition to Expel Alert, Investigation, Incident, and Health Status Change events. It’s the same setup, with wider coverage. Please note, this condition is only available for Org level notifications, not User level notifications.
Integration update
Status syncing for Palo Alto Networks Cortex XDR
1-way Workbench status syncing is now available for PAN’s Cortex XDR! If enabled, Cortex XDR customers automatically see updates to Cortex alerts and incidents based on the Expel Alerts our SOC have worked. No manual dual-tracking required. To enable 1-way syncing, simply Edit the security device and enable 1way status syncing, which is located beneath the API key ID field.
This joins the status syncing we already have in place for CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, and Wiz, so Cortex XDR customers get the same closed-loop visibility.
