Expel MDR: Agentic Detection and Response

Expel is a leading provider of agentic managed detection and response. It pairs an AI SOC assistant with a 24x7 human SOC and full investigative transparency. Here's our overview of the solution, based on a product deep dive.

Last updated on Aug 7, 2026
Joel Witts Written by Joel Witts
Expel PAR Logo
Strengths
24x7 monitoring with real-time investigations and a five-minute critical alert SLO.
Tool and platform agnostic with no new tech required.
Innovative agentic remediation capabilities.
Live monitoring within hours of connection.
Fully transparent audit trail of AI decision-making and analyst actions in Workbench.
Regular security reviews and advice from human SOC experts.
Cautions
You will need to have a strong existing security toolset to make the most out of this solution, best suited for mid-market to enterprise.
Pricing not publicly available.

Vendor: Expel, Inc.

Product: Expel MDR

Category: Agentic Managed Detection and Response (MDR)

HQ: Herndon, Virginia, USA

Founded: 2016, by Dave Merkel, Yanek Korff, and Justin Bajko

Our Analysis

Expel’s Approach

Expel is a leading provider of agentic managed detection and response (MDR), a new way of delivering MDR services where automation, AI, and autonomous AI agents enable human experts to effectively monitor for suspicious activity and take action to stop cyber threats.

The company was founded in 2016 by Mandiant alumni Dave Merkel, Yanek Korff, and Justin Bajko. Expel delivers 24×7 managed security operations via a mixture of detection engines, AI, and human analysts, with threat monitoring across attack surfaces such as cloud services, identity, email, SaaS apps, Kubernetes, SIEM, on-prem environments, AI, and more.

The platform is designed to integrate with your existing tools, rather than you having to deploy a new agent or SIEM. Telemetry data is gathered via direct API connections. Expel supports 160+ integrated tools, so deployment is straightforward and you can be up and running in hours.

The service is built around two key components: Expel Workbench™, an AI-powered SecOps platform, and Ruxie™, Expel’s AI SOC manager. Ruxie can instantly triage alerts and events without human involvement. It can gather evidence, provide context for investigations, and filter out false positives.

With Ruxie in place, in Q1 2026, Expel reported a fourteen-minute mean time to remediate for high severity alerts.

The Human SOC

Although Expel’s Workbench platform is built on a strong foundation of AI, agentic workflows and automation, Expel’s human SOC analyst team remains at the core of Expel’s service offering. Around 45 analysts across Expel’s threat analyst and global response teams provide 24×7 monitoring, with triage response SLOs within five minutes for critical alerts and 15 minutes for high-severity alerts.

Expel SOC analysts provide remediation recommendations alongside every validated threat. Customers can configure remediation actions to run automatically in their environment.

After every incident, the SOC provides security hardening and resilience recommendations based on what was observed in your environment to protect you from similar attacks in the future. They also conduct monthly or quarterly reviews to benchmark your organization against others of the same size or in a similar industry.

Response and Remediation

If an incident is detected, Expel can instantly respond, either via human action or via Ruxie, if enabled. Automated responses can include host containment, credential resets, account disablement, access key deactivation, file and registry key deletion, email removal, process killing, and hash blocking.

There are two ways you can implement this: you can either configure remediations to fire automatically when a specific detection triggers, or when an Expel analyst confirms a true positive first, at which point assigning the action sends an API call to the underlying product to contain the host or force the password reset, for example. The second option is the most common method customers choose.

Expel can also act as a backstop to controls you already run. So if, for example, Microsoft conditional access or your IAM tool has already locked an account, Expel confirms the remediation, traces the initial attack vector, and tells you when it is safe to reactivate.

Agentic Detection Engineering

Expel also offers a detection engineering agent. When a vendor like Microsoft or CrowdStrike ships a new detection that generates an alert Expel has not seen before, the agent drafts a new rule or updates an existing one, checks it against Expel’s existing detections, and routes it to a human detection engineer for quality assurance.

Transparency and Reporting

One thing that stands out with Expel is the transparency in decision making, without overloading teams with alerts. Every automated and manual action Expel’s analysts take is visible in Workbench, with a fully transparent audit trail of AI decision-making.

Customers can run the same investigative workflows Expel’s SOC uses, and some teams run their own on-demand investigations and threat hunts through Ruxie directly.

For example, an Entra ID account takeover investigation will show the AI alert summary, a behavioral identity classification with key decision drivers, and correlated alerts from SentinelOne and Zscaler, all in a clear investigation timeline.

Key Features

  • 24×7 SOC team, with SLOs of five minutes for critical alerts and 15 minutes for high-severity alerts.
  • Ruxie™, Expel’s AI SOC manager, triages millions of events to gather evidence, provide context for investigations, and minimize false positives.
  • Expel Workbench™ provides 24×7 real-time visibility into SOC monitoring, with a full audit trail of AI and analyst decision-making and reviewable detection rule logic.
  • Telemetry and alerts pulled from 160+ integrated tools via direct API connections across endpoint, network, identity, cloud, SIEM, Kubernetes, IaaS, SaaS, and AI providers.
  • AI alert summaries, presented to analysts at the point of detection.
  • 10 different auto remediation capabilities, including host containment, credential resets, account disablement, and hash blocking.
  • Remediation actions trigger when an alert fires or after Expel analysts validate a threat.
  • Threat intelligence and detection engineering, plus proactive threat hunting across your environment.
  • Detailed findings reports with root cause analysis and recommendations.
  • On-demand investigations let your own team run Ruxie workflows.
  • Add-on service extensions including a Managed SIEM, a security data lake solution, and a Managed Phishing solution built on M365 or Google Workspace.

The Interface

Expel Workbench is a SaaS console with a clean user interface with a huge amount of detail. In practice this is a managed service, so you may not need to be in here every day checking logs and alerts. But Expel has still taken time to make the interface user friendly and packed with information.

The investigation view shows the AI alert summary, as well as Ruxie’s automated investigative actions, alerts, and the full audit trail of analyst decisions. The findings report shows the attack chain, remediation actions, root cause analysis, and resilience recommendations.

Users can also filter the detection library to see exactly which rules were built by the detection engineering agent and review the logic.

Target Use Cases

Expel’s customer base is focused on commercial mid-market and enterprise. Expel is leveraged widely across industries, including airlines, hospitals, and financial services.

Most customers will already have strong security tooling (EDR, identity, email, cloud, SIEM) but may be looking to outsource experts to handle a huge volume of security alerts.

Smaller teams typically hand the full triage workload to Expel. Large enterprise SOCs (teams of 20 or more) may use Expel MDR as a second set of eyes, leveraging the Workbench platform for investigation and threat hunting use cases.

Pricing

Expel offers three MDR packages:

  • Starter (cloud, identity, network, and endpoint coverage).
  • Select (adds cloud control plane and SaaS app coverage plus multi-surface auto-remediation).
  • Premium (adds unlimited integrations, Workbench API access, and a dedicated engagement manager).

Pricing scales with the number of integrated technologies and telemetry volume.

Our Take

Expel offers an AI-native MDR solution built on integrations across your tech stack. We think it delivers on the two things that matter most in MDR: speed and trust.

Expel’s agentic Workbench platform understands your environment and organizational context, enabling deeper context during investigations and faster detection. The solution is highly transparent so you can always see how an investigation was handled with a full audit log.

We think the agentic powered detection gap analysis, ai assisted triage, and automated response with analyst oversight is a good playbook to speed up detection and remediation without the risk of AI hallucinations or mistakes.

Overall, we’d recommend Expel to small to midsized and large enterprises looking to speed up detection and response, with a trusted platform backed by AI and a team of human experts.

Read Further

Endpoint Security Resources

Further reading on endpoint security from Expert Insights — buyers' guides, comparison articles, and platform-specific shortlists.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.