Explore Expel’s auto remediations: Block bad hash
ID: 64fdd5c5-12f5-545e-8225-36e1225e639c
STIX ID: report--64fdd5c5-12f5-545e-8225-36e1225e639c
Feed Name: Expel Blog
Expel outlines its "block bad hash" auto-remediation workflow that leverages EDR integrations (e.g., Microsoft Defender for Endpoint, CrowdStrike, SentinelOne) to block execution of known malicious files by their cryptographic hashes. The doc explains when analysts use this action, a step-by-step playbook from detection to confirmation (including validation and customer approval), example use cases (droppers, RATs, credential-stealers like Mimikatz), and guidance for setup and integration in Workbench.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
