Ruxie Library
Years of SOC work.
Built into Ruxie.
Each capability targets a specific friction point between detecting a threat and acting on it. Built from years of watching where analysts lose time.
Detect
Alert similarity
Flags incoming alerts that match cases your analysts have already resolved, surfacing the prior outcome before they open the queue so repeat decisions take seconds.
Triage
Alert summaries
Synthesizes alert details into plain-English summaries covering impact and recommendations for faster threat assessment.
Enrich
Asset & identity contextualization
Tags alerts with business-critical details, managed device status, user roles, and public intelligence to prioritize risk by business impact.
Report
Automated customer verifications
Generates context-aware prompts asking users to confirm suspicious activity, auto-closing alerts if authorized or escalating if denied.
Investigate
Automated email classification
Scores incoming phishing emails as benign or malicious to auto-close high-confidence benign alerts and route the rest to analysts with a recommendation, cutting down manual review volume.
Report
Bi-directional chat
Syncs Expel Workbench™ investigations directly with Slack and Microsoft Teams, allowing seamless collaboration without switching platforms.
Respond
Block bad hash
Blocks potentially malicious processes and files based on their hash values.
Triage
Blocked malware triage agent
Automates alert triage of blocked malware by enriching files and processing with an AI-powered decision engine to assist analyst triage.
Report
Centralized evidence archive
Maintains a complete, auditable history of all chat threads, alert data, and automated Ruxie actions in one centralized incident record.
Report
Close comment generation
Generates detailed close comments for benign alerts to provide clear context and transparency for security decisions.
Triage
Cloud identity & authentication analysis
Evaluates AWS/Azure/Google Cloud identity and access, Okta SSO, Duo, and Azure IDP events to provide context for historical user behavior and automatically triage known benign activities.
Detect
Cloud perimeter monitoring
Proactively flags critical posture changes, such as new AWS/Azure security group rules allowing public inbound access or exposed S3 buckets.
Enrich
Cloud telemetry analysis
Ingests and correlated AWS, Google Cloud, Azure, Oracle, and cloud workload logs to map user behavior and role usage across all cloud environments.
Respond
Contain host
Isolates hosts from your network and severs all communication with other business applications.
Investigate
Deep identity investigation agent
Automatically gathers source-process context, identity and role data, LDAP detail, and host timelines for CrowdStrike IDP alerts; produces a close/verify/escalate recommendation with full rationale and counter-evidence before the analyst opens the alert.
Respond
Delete malicious file
Deletes potentially malicious threat artifacts.
Respond
Delete registry key
Removes malicious persistence entries from Windows Registry.
Detect | Evolve
Detection engineering agent
Generates new detection rules and alert logic for vendor telemetry to expand detection strategy coverage.
Detect | Evolve
Detection gap analysis agent
Evaluated newly seen vendor alerts against current Expel detection strategies and rules to identify gaps in coverage.
Report
Detection rule descriptions
Generates clear descriptions for every security rule to help you understand the specific logic behind each detection.
Respond
Disable access key
Automatically revokes compromised AWS or cloud access keys to lock down environments during an active threat.
Respond
Disable user account
Disables compromised user accounts, resets credentials, and terminates active sessions to stop lateral movement.
Enrich
Email risk & forensics context
Pulls forensic evidence, user context, rule metadata, and sender reputation from platforms like Abnormal AI, Proofpoint, and Sublime Security.
Enrich
Endpoint & EDR telemetry automation
Instantly parses host timelines and verifies process execution across CrowdStrike, SentinelOne, Microsoft Defender, Cybereason, and more.
Investigate
Enterprise-wide email scoping
Scans O365 or Google Workspace to identify every recipient of a phishing campaign and removes malicious emails from all inboxes.
Enrich
Historical activity baselines
Compiles 30-day behavioral profiles (login history, location trends, MFA activity) to establish a baseline for normal user behavior.
Triage
Identity alert classification
Leverages machine learning (ML) models trained on historical patterns to predict and auto-close benign login alerts, reducing the amount of manual triage needed by the security team for identity alerts.
Investigate
Identity Investigation Agent
Automatically consolidates evidence, applies structured reasoning, and delivers a full disposition recommendation on identity-based alerts before your analyst opens the queue.
Report
Incident narratives
Synthesizes alert details and key findings into a plain-English attack narrative, including detailed close comments for benign alerts.
Investigate
Key findings generation
Generates plain-English summaries using LLMs of critical investigation findings to help teams understand and report security incidents quickly.
Respond
Kill process
Terminates malicious processes across endpoints.
Investigate
Marketing email triage
Uses machine learning (ML) models to identify marketing emails and automatically triages phishing alerts.
Detect
Network behavior pattern analysis
Correlates network traffic over time to identify persistent beaconing patterns and suspicious outbound communications to malicious infrastructure.
Enrich
Network traffic analysis
Gathers granular network context from tools like Zscaler, Arista, and Palo Alto, mapping behavior across the environment and providing context for endpoint and cloud alerts.
Investigate
On-demand deep investigations
Executes automated and manual queries across many technologies to gather and provide analysts with additional context for suspicious behavior and potential blast radius.
Investigate
Phishing & URL analysis
Safely submits indicators to a sandbox for safe detonation and automated reporting.
Investigate
Phishing campaign clustering
Fingerprints and groups related phishing emails into a single campaign based on HTML structure and HTTP attributes so analysts can triage them all at once.
Report
Real-time automation visibility
Displays the live status and progress of all automated investigation and remediation steps directly within the Expel Workbench™.
Report
Real-time multi-channel escalation
Pushes instant notifications for high-risk incidents and remediation actions directly to preferred tools.
Triage
Related alert context
Summarizes findings from correlated alerts into a single narrative to speed up triage and reduce investigation time.
Respond
Remove malicious email
Hunts down and purges confirmed malicious emails from inboxes.
Respond
Reset credentials
Invalidates user passwords and terminates active sessions.
Triage
SaaS alert triage
Audits SaaS app activities such as file sharing, sensitive data access, and authentications to identify malicious behavior or unauthorized data exposure.
Enrich
SIEM telemetry aggregation
Organizes disparate logs such as process details, login history, and device metadata from existing SIEM tools into a single unified view.
Enrich
Third-party alert enrichment
Enriches alerts with risk scores and infrastructure intelligence from external feeds (VirusTotal, VMRay, Spur) for domains, IPs, and hashes.
Investigate
Transparent investigation timeline
Generates chronological timelines from SIEM, WAF, Active Directory, and cloud log sources to automatically surface user, IP, domain, and authentication activity to accelerate root-cause analysis.
Triage
Triage agent
An agentic workflow that applies structured AI reasoning (OSCAR methodology) to identity alerts, returning a disposition verdict — Known Good, Known Bad, or Needs More Info — with full evidence.
Respond
Undo alert-driven auto containment
Uncontains a device once Expel confirms no threat is present (applicable only to assets preemptively isolated per customer request).
Collect
Unified data collection
A unifies telemetry and data from across a customer's tech stack to centralize, normalize, and use AI to correlate security signals across the environment to power Expel-written detection strategies.
Enrich
User context summaries
Summarizes identity and endpoint logs into a clear narrative of user roles and recent activity for faster triage.