MDR
The Complimentary 2025 Gartner® Market Guide for Managed Detection & Response Services is here (and Expel is recognized, again)

The 2025 Gartner® Market Guide for Managed Detection & Response Services is here, and Expel is recognized as a Representative Vendor again.

MDR | 3 min read
DORA and NIS2: what you need to know about today’s cybersecurity regulations

Two new EU regulations—the Digital Operational Resilience Act (DORA) and Network and Information Security Directive 2 (NIS2)—are in effect.

MDR | 5 min read
Network and Information Security Directive (NIS2) compliance for businesses

Here's what to know about the Network and Information Security Directive (NIS2), a new cybersecurity standard for EU essential services.

MDR | 6 min read
How the Digital Operations Resilience Act (DORA) will affect your business

Here's what you should know about The Digital Operations Resilience Act (DORA), a new cybersecurity standard for financial orgs in the EU.

Company news | 6 min read
Expel co-founder Justin Bajko transitions to new role as Chief Strategy Officer

Justin Bajko, previously Expel’s VP of Strategy and Business Development, is now Expel’s Chief Strategy Officer.

Product | 4 min read
New Ruxie AI power up: Identity Classification gives analysts a ‘gut check’ for identity alerts

Expel AI has a new feature: Identity Classification. It triages and prioritizes alerts so analysts can spot identity threats faster.

Threat intel | 3 min read
Patch Tuesday: November 2025 (Expel’s version)

This month, we're highlighting top critical vulnerabilities, including one zero-day and an update on Windows Server Update Services (WSUS).

Product | 4 min read
New Ruxie AI power-up: User context summary turns ‘who?’ into ‘what’s next?’

User context summary is a new Expel AI power-up that automatically queries identity tools to gather relevant user details for an alert.

Product | 3 min read
Ruxie learned to think: Why our automation engine needed an AI brain

We've given Expel AI capabilities to Ruxie, our automation engine. Here's how it works, and how it benefits our customers.

Threat intel | 3 min read
Expel Quarterly Threat Report, Q3 2025: Threat intel recap

Here's a refresher on the threat intel we shared throughout the third quarter of 2025. Catch up on what you missed.

Threat intel | 4 min read
Expel Quarterly Threat Report, Q3 2025: Q3 by the numbers

Part I of our Quarterly Threat Report summarizes key findings and stats from Q3 of 2025. Learn what to focus on right now.

Threat intel | 6 min read
Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates

Rhysida ransomware gang has been using code-signing certificates to validate their malware campaigns repeatedly. Here's the latest.

SOC | 4 min read
Stories from the SOC: The curious case of termination notices

Our new "Stories from the SOC" series shares real-world attacks we've seen and stopped. This one covers a phishing attack on a university.