What we built: September 2026

By Scout Scholes

Published: October 5, 2026  •  2 minute read



Placeholder image for What we built: September 2026

TL;DR

  • This is a monthly recap of everything our product team shipped in the last 30 days
  • Questions? Reach out to your Expel contact, or if you don’t have one, connect with us here
  • One new Ruxie power-up and one new threat hunt are in the books for September 

 

September was a light month for product updates, as we work on some internal releases that will be coming to you all soon. This month, we have one new Ruxie power-up, and a new threat hunt. See you in October!

 

Live this month

Ruxie precedent engine

What it is: A long-term memory for our SOC. When a new alert looks a lot like ones we’ve already triaged, Ruxie surfaces the closest historical matches, how each one was closed, and a plain-language summary of why they match. It also shows what would need to change for the call to go the other way. If the match is weak or the history isn’t verified, it defaults to escalation. An analyst always makes the final call.

Why it matters: A big chunk of any alert queue is repeat noise that looks almost exactly like cases we’ve already closed. Proving that used to mean digging through old tickets and raw logs. Now that context is waiting for the analyst before the investigation starts, so we spend less time re-researching and more time on the alerts that need a human. The precedent engine also feeds our rapid triage agent, so first-pass triage on identity and cloud alerts gets smarter as our history grows. Read the full breakdown on the blog.

 

New threat hunts 

EtherHiding: Blockchain dead-drop command-and-control resolution

 

What it covers: Most malware finds its command-and-control (C2) server through DNS, and defenders can block or take that down. EtherHiding skips DNS. Instead, the malware asks a public blockchain for a C2 address or payload that keeps changing. It does this through a remote procedure call (RPC) node or a block-explorer API. Nothing written to a blockchain can be changed or removed, so there’s nothing to take down.

This hunt looks for processes contacting known blockchain RPC and block-explorer domains when they aren’t expected Web3 or crypto wallet tools. It traces each connection back to the process and process lineage that made it. It also pulls that process’s certificate and signing status, so our threat hunters  can quickly separate normal activity from suspicious activity.

Why it matters: Blocklists and takedowns work on domains and IP addresses. EtherHiding gets around both by hiding its instructions somewhere that can’t be pulled offline. Its traffic also blends in, because plenty of legitimate tools talk to the same blockchain endpoints. This hunt focuses on what an attacker can’t easily hide: which process on your endpoint is making the call.

Supported tech: CrowdStrike, Microsoft Defender for Endpoint, and SentinelOne