logo

How to investigate like an Expel analyst: The Expel Workbench managed alert process

ID: c0b6f276-69e6-5060-80e5-eeb5f83c83ed

STIX ID: report--c0b6f276-69e6-5060-80e5-eeb5f83c83ed

Feed Name: Expel Blog

Date Published: 2020-12-15

Date Updated: 2026-04-27

Author: Ben Brigida; Deshawn Luu

...
...

This blog post explains Expel’s managed alert process (MAP) and the OSCAR investigative framework for SOC analysts, describing how alerts move through triage, investigation, incident, close, and notify states; it highlights decision-support tools, investigative actions (queries and artifact acquisition), and automation (Ruxie). An example walkthrough (macro-enabled document leading to obfuscated PowerShell downloader behavior) demonstrates how analysts collect evidence, analyze obfuscated payloads, use OSINT, and escalate malicious findings to incidents, emphasizing consistent, question-driven investigations rather than rote runbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.