How to investigate like an Expel analyst: The Expel Workbench managed alert process
ID: c0b6f276-69e6-5060-80e5-eeb5f83c83ed
STIX ID: report--c0b6f276-69e6-5060-80e5-eeb5f83c83ed
Feed Name: Expel Blog
This blog post explains Expel’s managed alert process (MAP) and the OSCAR investigative framework for SOC analysts, describing how alerts move through triage, investigation, incident, close, and notify states; it highlights decision-support tools, investigative actions (queries and artifact acquisition), and automation (Ruxie). An example walkthrough (macro-enabled document leading to obfuscated PowerShell downloader behavior) demonstrates how analysts collect evidence, analyze obfuscated payloads, use OSINT, and escalate malicious findings to incidents, emphasizing consistent, question-driven investigations rather than rote runbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
