Expel
Expel is a managed detection and response (MDR) provider that delivers 24x7 security operations across endpoint, network, cloud, SaaS, identity, Kubernetes, and phishing surfaces. Customers and integration partners interact with Expel primarily through Workbench, Expel's investigation and case-management platform, which exposes a gated REST API for sending signals in from third-party tools and pulling alerts, investigations, and remediation actions back out into SIEMs, SOARs, and ticketing systems.
Expel publishes 1 API on the APIs.io network. Tagged areas include Cybersecurity, MDR, Managed Detection and Response, SOC, and SIEM.
Expel’s developer surface includes developer portal, engineering blog, and 12 more developer resources.
Kin Score
APIs 1
Individual APIs this provider publishes, each with its own machine-readable definition.
Expel Workbench API
The Expel Workbench API is a gated REST API used by customers and technology partners to integrate with the Expel MDR platform. The API powers ingest of signals from endpoint, c...
Pricing Plans 1
Published pricing tiers and plan structures.
Expel Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Expel Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Expel Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
MDR for Cloud
24x7 managed detection and response across AWS, Azure, and Google Cloud
MDR for SaaS
Detection and response across Microsoft 365, Google Workspace, Okta, and other SaaS platforms
MDR for Kubernetes
Container and Kubernetes-aware detection and response
Phishing
Managed phishing triage, investigation, and remediation
Threat Hunting
Proactive hunting across customer telemetry by Expel analysts
Vulnerability Prioritization
Risk-based vulnerability prioritization tied to threat context
Workbench
Investigation, case-management, and analytics platform with REST API for customers and integration partners
Scroll for all 7
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Use Cases 5
What developers build with this provider.
24x7 SOC Outsourcing
Augment or replace an internal SOC with Expel's analysts and Workbench platform
Cloud Security Monitoring
Continuous monitoring and incident response across multi-cloud environments
Phishing Triage and Response
Automated and analyst-assisted phishing investigation and remediation
SIEM and SOAR Augmentation
Use Expel as the analyst layer on top of existing SIEM and SOAR investments
Compliance and Reporting
Use Workbench data and reports to support SOC2, PCI, and other compliance regimes
Integrations 8
Pre-built integrations with other platforms and tools.
AWS
Native MDR integrations for AWS accounts, GuardDuty, and related cloud signals
Microsoft Azure
MDR coverage and integrations for Azure, Entra ID, and Microsoft Defender
Google Cloud
MDR coverage for Google Cloud workloads and security signals
Microsoft 365
SaaS detection and response coverage for Microsoft 365 tenants
Google Workspace
SaaS detection and response coverage for Google Workspace tenants
SIEM Platforms
Bidirectional integrations with Splunk, Sentinel, Chronicle, and other SIEMs
EDR Platforms
Workbench connectors for CrowdStrike, SentinelOne, Microsoft Defender, and other EDR tools
Identity Providers
Integrations with Okta, Entra ID, and other identity providers for identity-centric detections
Scroll for all 8
Resources
Get Started 1
Portal, sign-up, and the first successful call
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Access & Security 3
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 5
The organization behind the API
Other 1
Properties that don't map to a standard resource type