When your keys go missing: getting real about identity threats
ID: ff9d2a5b-ef43-5df5-92cf-1d7c8800923e
STIX ID: report--ff9d2a5b-ef43-5df5-92cf-1d7c8800923e
Feed Name: Expel Blog
This announcement outlines Expel Workbench's updated identity-threat alert taxonomy, splitting alerts into Credential theft (credentials obtained but not observed in use), Account compromise (confirmed login/foothold), and Business Email Compromise (active malicious use of an account). It recommends concrete actions—reset credentials for theft; reset and disable accounts for compromise and BEC—and highlights optional auto-remediation to reduce time-to-contain, improve prioritization, speed response, and simplify reporting for leadership and compliance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
