logo

Exabeam: an incident investigator’s cheat code

ID: 07acf085-5a60-5431-afa0-a077a8bd2e9c

STIX ID: report--07acf085-5a60-5431-afa0-a077a8bd2e9c

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2020-02-04

Date Updated: 2026-04-27

Author: Anthony Randazzo

...
...

Expel explains how Exabeam Advanced Analytics improves incident response by correlating EDR, Windows event, authentication, and web logs to create user/entity timelines; examples include attackers gaining access via compromised Citrix NetScaler VPN credentials, accessing a published VDI, staging post-exploitation tools from GitHub, attempted PowerSploit execution blocked by EDR, and use of a Cobalt Strike beacon—demonstrating detection of reconnaissance, dwell time, and anomalous credential usage that traditional EDR telemetry alone might miss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.