Expel website screenshot

Expel

Expel is a managed detection and response (MDR) provider that delivers 24x7 security operations across endpoint, network, cloud, SaaS, identity, Kubernetes, and phishing surfaces. Customers and integration partners interact with Expel primarily through Workbench, Expel's investigation and case-management platform, which exposes a gated REST API for sending signals in from third-party tools and pulling alerts, investigations, and remediation actions back out into SIEMs, SOARs, and ticketing systems.

Expel publishes 1 API on the APIs.io network. Tagged areas include Cybersecurity, MDR, Managed Detection and Response, SOC, and SIEM.

Expel’s developer surface includes developer portal, engineering blog, and 12 more developer resources.

22.2/100 emerging ▬ flat Agent 3/100 human only saas Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFree
1 APIs 7 Features 5 Use Cases
CybersecurityMDRManaged Detection and ResponseSOCSIEMWorkbench

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero: never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and several others — scorable at all.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/expel: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Expel Workbench API

The Expel Workbench API is a gated REST API used by customers and technology partners to integrate with the Expel MDR platform. The API powers ingest of signals from endpoint, c...

Pricing Plans 1

Published pricing tiers and plan structures.

Expel Plans Pricing

1 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Expel Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Expel Finops

FINOPS

Features 7

Notable capabilities this provider offers.

MDR for Cloud

24x7 managed detection and response across AWS, Azure, and Google Cloud

MDR for SaaS

Detection and response across Microsoft 365, Google Workspace, Okta, and other SaaS platforms

MDR for Kubernetes

Container and Kubernetes-aware detection and response

Phishing

Managed phishing triage, investigation, and remediation

Threat Hunting

Proactive hunting across customer telemetry by Expel analysts

Vulnerability Prioritization

Risk-based vulnerability prioritization tied to threat context

Workbench

Investigation, case-management, and analytics platform with REST API for customers and integration partners

Scroll for all 7

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Expel Domain Security

TLSv1.2 · HSTS · DNSSEC · DMARC

SECURITY

Expel Vulnerability Disclosure

security.txt · contact published

SECURITY

Expel Trust Center

SOC 2, ISO 27001, GDPR, CSA STAR, FIPS 140

SECURITY

Use Cases 5

What developers build with this provider.

24x7 SOC Outsourcing

Augment or replace an internal SOC with Expel's analysts and Workbench platform

Cloud Security Monitoring

Continuous monitoring and incident response across multi-cloud environments

Phishing Triage and Response

Automated and analyst-assisted phishing investigation and remediation

SIEM and SOAR Augmentation

Use Expel as the analyst layer on top of existing SIEM and SOAR investments

Compliance and Reporting

Use Workbench data and reports to support SOC2, PCI, and other compliance regimes

Integrations 8

Pre-built integrations with other platforms and tools.

AWS

Native MDR integrations for AWS accounts, GuardDuty, and related cloud signals

Microsoft Azure

MDR coverage and integrations for Azure, Entra ID, and Microsoft Defender

Google Cloud

MDR coverage for Google Cloud workloads and security signals

Microsoft 365

SaaS detection and response coverage for Microsoft 365 tenants

Google Workspace

SaaS detection and response coverage for Google Workspace tenants

SIEM Platforms

Bidirectional integrations with Splunk, Sentinel, Chronicle, and other SIEMs

EDR Platforms

Workbench connectors for CrowdStrike, SentinelOne, Microsoft Defender, and other EDR tools

Identity Providers

Integrations with Okta, Entra ID, and other identity providers for identity-centric detections

Scroll for all 8

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 5

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: expel
url: https://raw.githubusercontent.com/api-evangelist/expel/refs/heads/main/apis.yml
name: Expel
type: Index
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: false
  label: Hosted service · you call their endpoint
  confidence: medium
  source:
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: free
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Free
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/expel.png
tags:
- Cybersecurity
- MDR
- Managed Detection and Response
- SOC
- SIEM
- Workbench
description: Expel is a managed detection and response (MDR) provider that delivers 24x7 security operations across endpoint,
  network, cloud, SaaS, identity, Kubernetes, and phishing surfaces. Customers and integration partners interact with Expel
  primarily through Workbench, Expel's investigation and case-management platform, which exposes a gated REST API for sending
  signals in from third-party tools and pulling alerts, investigations, and remediation actions back out into SIEMs, SOARs,
  and ticketing systems.
created: '2026-05-23'
modified: '2026-05-23'
specificationVersion: '0.23'
apis:
- aid: expel:expel-workbench-api
  name: Expel Workbench API
  tags:
  - Investigations
  - Alerts
  - Remediation
  - MDR
  humanURL: https://workbench.expel.io
  baseURL: https://workbench.expel.io/api
  properties:
  - url: https://workbench.expel.io
    type: Portal
    title: Expel Workbench (gated)
  - url: https://expel.com/integrations/
    type: Integrations
  description: The Expel Workbench API is a gated REST API used by customers and technology partners to integrate with the
    Expel MDR platform. The API powers ingest of signals from endpoint, cloud, SIEM, identity, and SaaS tools, surfaces Expel
    analyst investigations, alerts, findings, and remediation recommendations, and supports outbound integrations into customer
    SIEM, SOAR, ITSM, and notification systems. Access is provisioned to Expel customers and partners via the Workbench portal.
common:
- type: TrustCenter
  url: security/expel-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/expel-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/expel-domain-security.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/expel
- type: Website
  url: https://expel.com/
- type: Portal
  url: https://workbench.expel.io
  title: Expel Workbench
- type: Integrations
  url: https://expel.com/integrations/
- type: Blog
  url: https://expel.com/blog/
- type: Resources
  url: https://expel.com/resources/
- type: ContactSales
  url: https://expel.com/contact/
- type: Careers
  url: https://expel.com/careers/
- type: Partners
  url: https://expel.com/partners/
- type: PrivacyPolicy
  url: https://expel.com/privacy-policy/
- type: TermsOfService
  url: https://expel.com/terms-of-use/
- type: Features
  data:
  - name: MDR for Cloud
    description: 24x7 managed detection and response across AWS, Azure, and Google Cloud
  - name: MDR for SaaS
    description: Detection and response across Microsoft 365, Google Workspace, Okta, and other SaaS platforms
  - name: MDR for Kubernetes
    description: Container and Kubernetes-aware detection and response
  - name: Phishing
    description: Managed phishing triage, investigation, and remediation
  - name: Threat Hunting
    description: Proactive hunting across customer telemetry by Expel analysts
  - name: Vulnerability Prioritization
    description: Risk-based vulnerability prioritization tied to threat context
  - name: Workbench
    description: Investigation, case-management, and analytics platform with REST API for customers and integration partners
- type: UseCases
  data:
  - name: 24x7 SOC Outsourcing
    description: Augment or replace an internal SOC with Expel's analysts and Workbench platform
  - name: Cloud Security Monitoring
    description: Continuous monitoring and incident response across multi-cloud environments
  - name: Phishing Triage and Response
    description: Automated and analyst-assisted phishing investigation and remediation
  - name: SIEM and SOAR Augmentation
    description: Use Expel as the analyst layer on top of existing SIEM and SOAR investments
  - name: Compliance and Reporting
    description: Use Workbench data and reports to support SOC2, PCI, and other compliance regimes
- type: Integrations
  data:
  - name: AWS
    description: Native MDR integrations for AWS accounts, GuardDuty, and related cloud signals
  - name: Microsoft Azure
    description: MDR coverage and integrations for Azure, Entra ID, and Microsoft Defender
  - name: Google Cloud
    description: MDR coverage for Google Cloud workloads and security signals
  - name: Microsoft 365
    description: SaaS detection and response coverage for Microsoft 365 tenants
  - name: Google Workspace
    description: SaaS detection and response coverage for Google Workspace tenants
  - name: SIEM Platforms
    description: Bidirectional integrations with Splunk, Sentinel, Chronicle, and other SIEMs
  - name: EDR Platforms
    description: Workbench connectors for CrowdStrike, SentinelOne, Microsoft Defender, and other EDR tools
  - name: Identity Providers
    description: Integrations with Okta, Entra ID, and other identity providers for identity-centric detections
- type: LlmsText
  url: https://expel.com/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/expel"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/expel/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/expel/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.