logo

Stories from the SOC: When threats come from inside the house

ID: 32854410-8135-58cd-a31b-cc552c65d4e8

STIX ID: report--32854410-8135-58cd-a31b-cc552c65d4e8

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2025-09-29

Date Updated: 2026-04-27

Author: Ben Nahorney; Zach Davis

...
...

Expel MDR detected and stopped an internal phishing incident in which an attacker used a compromised employee email to distribute a malicious link that downloaded an attacker-controlled remote management tool to five users; the SOC contained the affected accounts and hosts, blocked related domains/IPs, and recommended conditional access and application control to prevent recurrence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.