Top 5 takeaways: Expel Quarterly Threat Report Q2
ID: 17a7d1a6-c9dc-560e-9ec0-44f714d99f0a
STIX ID: report--17a7d1a6-c9dc-560e-9ec0-44f714d99f0a
Feed Name: Expel Blog
The Q2 2022 Expel Quarterly Threat Report summarizes SOC findings from April–June 2022: macro-based initial access fell sharply after Microsoft blocked macros by default, with attackers pivoting to ISO, LNK, and ZIP file vectors; identity-based attacks dominated (56% of incidents) with business email compromise (45%) concentrated in Microsoft O365 and some MFA bypass via legacy protocols; 54% of leads originated from cloud application or identity integrations, automation completed key investigative actions 77% of the time, and orchestration reduced median remediation time from two hours to seven minutes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
