Expel website screenshot

Expel

Expel is a managed detection and response (MDR) provider that delivers 24x7 security operations across endpoint, network, cloud, SaaS, identity, Kubernetes, and phishing surfaces. Customers and integration partners interact with Expel primarily through Workbench, Expel's investigation and case-management platform, which exposes a gated REST API for sending signals in from third-party tools and pulling alerts, investigations, and remediation actions back out into SIEMs, SOARs, and ticketing systems.

Expel publishes 1 API on the APIs.io network. Tagged areas include Cybersecurity, MDR, Managed Detection and Response, SOC, and SIEM.

Expel’s developer surface includes developer portal, engineering blog, and 12 more developer resources.

23.4/100 emerging ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFree
1 APIs 7 Features 5 Use Cases
CybersecurityMDRManaged Detection and ResponseSOCSIEMWorkbench

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 23.4/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 2.2 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 2.7 / 13
Governance 0.0 / 12
Discoverability 6.9 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/expel: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Expel Workbench API

The Expel Workbench API is a gated REST API used by customers and technology partners to integrate with the Expel MDR platform. The API powers ingest of signals from endpoint, c...

Pricing Plans 1

Published pricing tiers and plan structures.

Expel Plans Pricing

1 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Expel Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Expel Finops

FINOPS

Features 7

Notable capabilities this provider offers.

MDR for Cloud

24x7 managed detection and response across AWS, Azure, and Google Cloud

MDR for SaaS

Detection and response across Microsoft 365, Google Workspace, Okta, and other SaaS platforms

MDR for Kubernetes

Container and Kubernetes-aware detection and response

Phishing

Managed phishing triage, investigation, and remediation

Threat Hunting

Proactive hunting across customer telemetry by Expel analysts

Vulnerability Prioritization

Risk-based vulnerability prioritization tied to threat context

Workbench

Investigation, case-management, and analytics platform with REST API for customers and integration partners

Scroll for all 7

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Expel Domain Security

TLSv1.2 · HSTS · DNSSEC · DMARC

SECURITY

Expel Vulnerability Disclosure

security.txt · contact published

SECURITY

Expel Trust Center

SOC 2, ISO 27001, GDPR, CSA STAR, FIPS 140

SECURITY

Use Cases 5

What developers build with this provider.

24x7 SOC Outsourcing

Augment or replace an internal SOC with Expel's analysts and Workbench platform

Cloud Security Monitoring

Continuous monitoring and incident response across multi-cloud environments

Phishing Triage and Response

Automated and analyst-assisted phishing investigation and remediation

SIEM and SOAR Augmentation

Use Expel as the analyst layer on top of existing SIEM and SOAR investments

Compliance and Reporting

Use Workbench data and reports to support SOC2, PCI, and other compliance regimes

Integrations 8

Pre-built integrations with other platforms and tools.

AWS

Native MDR integrations for AWS accounts, GuardDuty, and related cloud signals

Microsoft Azure

MDR coverage and integrations for Azure, Entra ID, and Microsoft Defender

Google Cloud

MDR coverage for Google Cloud workloads and security signals

Microsoft 365

SaaS detection and response coverage for Microsoft 365 tenants

Google Workspace

SaaS detection and response coverage for Google Workspace tenants

SIEM Platforms

Bidirectional integrations with Splunk, Sentinel, Chronicle, and other SIEMs

EDR Platforms

Workbench connectors for CrowdStrike, SentinelOne, Microsoft Defender, and other EDR tools

Identity Providers

Integrations with Okta, Entra ID, and other identity providers for identity-centric detections

Scroll for all 8

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 5

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: expel
url: https://raw.githubusercontent.com/api-evangelist/expel/refs/heads/main/apis.yml
name: Expel
type: Index
accessModel:
  pricing: free
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Free
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/expel.png
tags:
- Cybersecurity
- MDR
- Managed Detection and Response
- SOC
- SIEM
- Workbench
description: Expel is a managed detection and response (MDR) provider that delivers 24x7 security operations across endpoint,
  network, cloud, SaaS, identity, Kubernetes, and phishing surfaces. Customers and integration partners interact with Expel
  primarily through Workbench, Expel's investigation and case-management platform, which exposes a gated REST API for sending
  signals in from third-party tools and pulling alerts, investigations, and remediation actions back out into SIEMs, SOARs,
  and ticketing systems.
created: '2026-05-23'
modified: '2026-05-23'
specificationVersion: '0.19'
apis:
- aid: expel:expel-workbench-api
  name: Expel Workbench API
  tags:
  - Investigations
  - Alerts
  - Remediation
  - MDR
  humanURL: https://workbench.expel.io
  baseURL: https://workbench.expel.io/api
  properties:
  - url: https://workbench.expel.io
    type: Portal
    title: Expel Workbench (gated)
  - url: https://expel.com/integrations/
    type: Integrations
  description: The Expel Workbench API is a gated REST API used by customers and technology partners to integrate with the
    Expel MDR platform. The API powers ingest of signals from endpoint, cloud, SIEM, identity, and SaaS tools, surfaces Expel
    analyst investigations, alerts, findings, and remediation recommendations, and supports outbound integrations into customer
    SIEM, SOAR, ITSM, and notification systems. Access is provisioned to Expel customers and partners via the Workbench portal.
common:
- type: TrustCenter
  url: security/expel-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/expel-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/expel-domain-security.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/expel
- type: Website
  url: https://expel.com/
- type: Portal
  url: https://workbench.expel.io
  title: Expel Workbench
- type: Integrations
  url: https://expel.com/integrations/
- type: Blog
  url: https://expel.com/blog/
- type: Resources
  url: https://expel.com/resources/
- type: ContactSales
  url: https://expel.com/contact/
- type: Careers
  url: https://expel.com/careers/
- type: Partners
  url: https://expel.com/partners/
- type: PrivacyPolicy
  url: https://expel.com/privacy-policy/
- type: TermsOfService
  url: https://expel.com/terms-of-use/
- type: Features
  data:
  - name: MDR for Cloud
    description: 24x7 managed detection and response across AWS, Azure, and Google Cloud
  - name: MDR for SaaS
    description: Detection and response across Microsoft 365, Google Workspace, Okta, and other SaaS platforms
  - name: MDR for Kubernetes
    description: Container and Kubernetes-aware detection and response
  - name: Phishing
    description: Managed phishing triage, investigation, and remediation
  - name: Threat Hunting
    description: Proactive hunting across customer telemetry by Expel analysts
  - name: Vulnerability Prioritization
    description: Risk-based vulnerability prioritization tied to threat context
  - name: Workbench
    description: Investigation, case-management, and analytics platform with REST API for customers and integration partners
- type: UseCases
  data:
  - name: 24x7 SOC Outsourcing
    description: Augment or replace an internal SOC with Expel's analysts and Workbench platform
  - name: Cloud Security Monitoring
    description: Continuous monitoring and incident response across multi-cloud environments
  - name: Phishing Triage and Response
    description: Automated and analyst-assisted phishing investigation and remediation
  - name: SIEM and SOAR Augmentation
    description: Use Expel as the analyst layer on top of existing SIEM and SOAR investments
  - name: Compliance and Reporting
    description: Use Workbench data and reports to support SOC2, PCI, and other compliance regimes
- type: Integrations
  data:
  - name: AWS
    description: Native MDR integrations for AWS accounts, GuardDuty, and related cloud signals
  - name: Microsoft Azure
    description: MDR coverage and integrations for Azure, Entra ID, and Microsoft Defender
  - name: Google Cloud
    description: MDR coverage for Google Cloud workloads and security signals
  - name: Microsoft 365
    description: SaaS detection and response coverage for Microsoft 365 tenants
  - name: Google Workspace
    description: SaaS detection and response coverage for Google Workspace tenants
  - name: SIEM Platforms
    description: Bidirectional integrations with Splunk, Sentinel, Chronicle, and other SIEMs
  - name: EDR Platforms
    description: Workbench connectors for CrowdStrike, SentinelOne, Microsoft Defender, and other EDR tools
  - name: Identity Providers
    description: Integrations with Okta, Entra ID, and other identity providers for identity-centric detections
- type: LlmsText
  url: https://expel.com/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com