logo

Explore Expel’s auto remediations: Block bad hash

ID: 64fdd5c5-12f5-545e-8225-36e1225e639c

STIX ID: report--64fdd5c5-12f5-545e-8225-36e1225e639c

Feed Name: Expel Blog

Threat Score
30/100

Date Published: 2025-06-12

Date Updated: 2026-04-27

Author: Jake Godgart; Claire Hogan

...
...

Expel outlines its "block bad hash" auto-remediation workflow that leverages EDR integrations (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) to block execution of known malicious files by their cryptographic hashes. The doc explains when analysts use this action, a step-by-step playbook from detection to confirmation (including validation and customer approval), example use cases (droppers, RATs, credential-stealers like Mimikatz), and guidance for setup and integration in Workbench.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.