logo

How we use VMRay to support Expel for Phishing

ID: 8b25f823-ab2f-5d72-9e8a-df1bfda9d93e

STIX ID: report--8b25f823-ab2f-5d72-9e8a-df1bfda9d93e

Feed Name: Expel Blog

Threat Score
20/100

Date Published: 2021-09-21

Date Updated: 2026-04-27

Author: Ray Pugh; Hiranya Mir

...
...

This post describes Expel's managed phishing investigation workflow using VMRay for static and dynamic analysis of suspicious URLs and attachments, demonstrates examples of credential-harvesting pages and macro-enabled Excel payload behavior, and explains how analysts pivot from sandbox indicators to customer EDR, SIEM, and network logs to determine scope and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.