logo

Top 5 takeaways: Expel Quarterly Threat Report Q2

ID: 17a7d1a6-c9dc-560e-9ec0-44f714d99f0a

STIX ID: report--17a7d1a6-c9dc-560e-9ec0-44f714d99f0a

Feed Name: Expel Blog

Threat Score
65/100

Date Published: 2022-08-09

Date Updated: 2026-04-27

Author: Jonathan Hencinski

...
...

The Q2 2022 Expel Quarterly Threat Report summarizes SOC findings from April–June 2022: macro-based initial access fell sharply after Microsoft blocked macros by default, with attackers pivoting to ISO, LNK, and ZIP file vectors; identity-based attacks dominated (56% of incidents) with business email compromise (45%) concentrated in Microsoft O365 and some MFA bypass via legacy protocols; 54% of leads originated from cloud application or identity integrations, automation completed key investigative actions 77% of the time, and orchestration reduced median remediation time from two hours to seven minutes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.