logo

Detection and response in action: an end-to-end coverage story

ID: 8bb06893-c46a-5ecd-9d9c-cfadaf044fc6

STIX ID: report--8bb06893-c46a-5ecd-9d9c-cfadaf044fc6

Feed Name: Expel Blog

Threat Score
50/100

Date Published: 2022-09-08

Date Updated: 2026-04-27

Author: Nathan Sorrel

...
...

Expel presents a staged customer incident where a phishing email with a malicious Word attachment resulted in Regsvr32.exe being spawned by Winword.exe and making network connections; the report walks through alert triage, collaborative investigation, containment/remediation actions (isolating hosts, blocking hashes/domains), subsequent threat hunting to validate resilience, and updates to detection rules to catch similar TTPs in the future.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.