Threat intel
You don’t find ManualFinder, ManualFinder finds you

We're investigating ManualFinder, a trojan malware we're seeing in new activity, likely coming from potentially unwanted programs (PUPs).

MDR | 3 min read
Getting real value from your Palo Alto investment: how Expel MDR transforms security operations

Expel MDR reduces Palo Alto alert noise by 87% with 17-minute response times. Expert 24x7 analysis maximizes your security investment ROI.

Threat intel | 17 min read
The history of AppSuite: the certs of the BaoLoader developer

We're tracking the malware BaoLoader and their fraudulent code-signing certificates via AppSuite-PDF and PDF editor campaigns.

Current events | 3 min read
Patch Tuesday: September 2025 (Expel’s version)

This month, we're highlighting top critical vulnerabilities, including an SAP S/4HANA code injection vulnerability currently being exploited.

Product | 6 min read
From data to deployment: A deep dive into building our AI Resolutions (part two)

Dive deeper into Expel's AI Resolutions (AIR) and understand how we developed and tested this feature for our analysts.

Product | 3 min read
Explaining the ‘why’: Our vision for AI-powered alert transparency (part one)

Expel created AI Resolutions (AIR) uses AI to generate detailed, data-backed explanations for why a security alert was considered benign.

Product | 5 min read
Explore Expel’s auto remediations: Remove malicious email

In this series, we explore Expel's auto remediations so you understand how they work. Let's explore remove malicious email.

Threat intel | 10 min read
You don’t find ManualFinder, ManualFinder finds you

We're investigating ManualFinder, a trojan malware we're seeing in new activity, likely coming from potentially unwanted programs (PUPs).

Expel culture | 3 min read
Meet the Expletive: James Shank, Director of Threat Operations

Meet James Shank, Expel's first Director of Threat Operations. We cover James' past career experience, and why he thrives in the chaos.

Product | 2 min read
Level up your cloud defense: Expel’s Wiz Defend integration is now live

Expel's partnership with Wiz Defend gives mutual customers richer alert context, faster response times, and streamlined cloud security.

Product | 3 min read
Unlocking more from your CrowdStrike investment

Expel cuts through the flood of CrowdStrike alerts by 91% on average to maximize your security tools with strong API connections.

Product | 5 min read
Explore Expel’s auto remediations: Reset credentials

In this series, we explore Expel's auto remediations so you understand how they work. Let's explore reset credentials.

Current events | 2 min read
Black Hat 2025: What we’re still thinking about

Black Hat 2025 has come to an end, but here's what we're still thinking about and expect to continue seeing in headlines and strategies.