logo

Spotting suspicious logins at scale: (Alert) pathways to success

ID: 59bc2426-f403-500c-9e38-da7526b8e46f

STIX ID: report--59bc2426-f403-500c-9e38-da7526b8e46f

Feed Name: Expel Blog

Date Published: 2020-06-02

Date Updated: 2026-04-27

Author: Jon Hencinski; Peter Silberman

...
...

Expel outlines how they cut median investigation time for suspicious login alerts by 75% through a decision support approach that combines automation, contextual enrichment, investigation orchestration, and UI improvements; by instrumenting SOC metrics (alert pathways and investigation cycle time) they identified repetitive manual queries and automated retrieval of user authentication histograms, geolocation maps, IP/user-agent summaries, and MFA/account details, improving alert-to-close from 61% to 86% and reducing investigations from 39% to 14% (May 2019 → May 2020).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.