Expel

Expel

Software-driven MDR services with threat analysis

Overview

Expel provides Managed Detection and Response (MDR) services that help organizations protect their digital assets. It combines technology and human expertise to monitor, detect, and respond to threats across cloud, SaaS, and on‑premises systems. The platform collects logs and alerts from a company’s existing tech stack and processes them with automated tools and security analysts to identify malicious activity and take action. It also offers clear, actionable recommendations to improve security and maximize ROI, along with workflows that support and augment a company’s security team. Unlike some providers that rely on limited tools or slow handoffs, Expel emphasizes quick integration with new technologies and a transparent, software‑driven approach that continuously improves security posture. The company’s goal is to raise a customer’s security maturity while delivering measurable security outcomes and better ROI by preventing incidents and guiding future security spending.

About Expel

Simplify's Rating
Why Expel is rated
C+
Rated C on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Consulting

Enterprise Software

Cybersecurity

Company Size

201-500

Company Stage

Series E

Total Funding

$288.8M

Headquarters

Herndon, Virginia

Founded

2016

Get referred to Expel

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Expel’s Q2 2026 report says identity drove 68.1% of SOC incidents.
  • Expel’s August 2026 AI launch maps detections to 13 of 16 MITRE ATLAS tactics.
  • Managed SIEM monetizes existing Sentinel and Splunk customers without platform migration.

What critics are saying

  • Microsoft, CrowdStrike, and Arctic Wolf compress MDR pricing through integrated platform bundles.
  • Expel’s 414-person workforce in December 2025 dropped 14.2% from 2024.
  • AI-native competitors threaten Expel’s transparency moat by automating investigations faster and cheaper.

What makes Expel unique

  • Expel’s Workbench exposes investigations end-to-end, unlike black-box MDR rivals.
  • Expel’s March 2026 Managed SIEM embeds detection engineering inside Sentinel and Splunk.
  • Expel’s August 2026 AI coverage spans attacks using AI, misuse, and AI-system exposure.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$288.8M

Below

Industry Average

Funded Over

6 Rounds

Series E funding typically includes additional rounds after Series D if the company needs more capital. The business is usually stable, and these rounds are typically used for further expansion or to address market challenges.
Series E Funding Comparison
Below Average

Industry standards

$100M
$245M
Stripe
$250M
Reddit
$1.3B
Epic Games
$1.5B
Airbnb

Benefits

Unlimited vacation

401k plan

Healthcare plan with dental and vision

Flexible work hours

Opportunity to work from home

One paid conference per year

Parental leave

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
PR Newswire
Aug 4th, 2026
Expel launches first MDR covering full AI attack surface with MITRE ATLAS detection

Expel has launched the first managed detection and response (MDR) service covering the complete AI attack surface. The coverage addresses three areas: attacks launched using AI, employee misuse of AI, and vulnerabilities within AI systems themselves. The service includes an Anthropic Claude integration that analyses prompt content to detect intent, not just activity logs. Expel's detection library maps to 13 of 16 MITRE ATLAS tactics and is available to customers. Human operators run the detection and triage processes, using AI to accelerate rather than replace their work. The company also offers AI-focused threat hunting for customers. James Shank, Director of Threat Operations at Expel, will present the Expel AI Risk Framework at Black Hat USA 2026 on 5 August.

PR Newswire
Jun 23rd, 2026
Expel extends Ruxie AI with agentic capabilities across entire threat lifecycle

Expel has extended Ruxie, its AI SOC manager, with new agentic capabilities to provide AI coverage across every stage of the threat lifecycle. The capabilities are now in production in customers' MDR deployments. The enhancements address AI-powered attacks that compress the time from initial access to impact. Ruxie's new capabilities include automated enrichment pulling data from over 160 security tools, contextual analysis, threat detection across multiple attack surfaces, automated detection engineering, alert triage and classification, investigation workflows, targeted response actions, and automated reporting. The system operates alongside human analysts to improve speed and accuracy. According to Expel's Chief Strategy Officer Justin Bajko, the agentic workflows are designed to match the pace of machine-speed attackers at every stage, eliminating gaps for exploitation.

PR Newswire
May 4th, 2026
Expel launches AI security framework backed by decade of production experience across trillions of alerts

Expel, a security provider, has published a practitioner framework for implementing AI in security operations, supported by a decade of production AI experience. The "Trust vs. Impact" framework maps security workflows based on potential impact and system confidence, helping practitioners determine where AI should operate autonomously versus where humans should lead. The company released an interactive tool allowing security teams to plot their own workflows on the framework. Expel's AI engine, Ruxie, now includes capabilities such as agentic detection rule generation, AI-powered identity alert triage with 99.7% confidence, and AI-generated summarisation. The identity classification feature alone reduces alert volume by approximately 10%. The framework, interactive tool, and Ruxie capabilities are available now through Expel Workbench for managed detection and response customers.

PR Newswire
Mar 23rd, 2026
Expel launches Managed SIEM to tackle detection engineering burden for Sentinel and Splunk users

Expel has launched Expel Managed SIEM, a co-managed service that integrates the company's detection engineering expertise into customers' existing Microsoft Sentinel and Splunk Enterprise Security environments. The service is now generally available as an add-on to Expel MDR. The offering handles detection strategy, writes custom detection logic, optimises data ingestion costs, and feeds SIEM alerts into Expel's MDR response workflows. Unlike traditional providers that profit from increased data volume, Expel helps customers control ingestion costs whilst maintaining security coverage. The service includes two tiers: Detection Engineering provides ongoing detection support and rule optimisation, whilst Performance Engineering offers deeper operational support including SIEM health monitoring and automation development. Customers retain full ownership of all detection rules created by Expel, with complete visibility into every tuning decision.

PR Newswire
Apr 28th, 2025
Expel Brings Security Heroes Together At Rsac™ Conference 2025

Leading MDR provider to celebrate security defenders with cutting-edge service innovations and exclusive VIP experiencesHERNDON, Va., April 28, 2025 /PRNewswire/ -- Expel , the leading managed detection and response (MDR) provider, today announced its return to the showfloor at RSAC™ Conference 2025. Find Expel in the South Hall of the Moscone Center (booth #0535) for product demos and activations celebrating the true heroes protecting our digital world: cybersecurity defenders."Security teams are often the unsung heroes of their organizations—protecting their businesses, people, and critical systems from threats every day," said Dave Merkel, co-founder and CEO, Expel. "But even the strongest defenders can't go it alone. Expel combines the best people, tech, and expertise to elevate our customers' efforts—creating a force multiplier against today's biggest threats for the best security outcomes."Security teams are fighting an uphill battle—balancing threats that are growing in volume, sophistication, and speed, especially enabled by generative AI, against tighter budgets and heightened scrutiny on their security programs. Expel combats these issues head-on by extending and enhancing security operations helping customers stay ahead of adversaries with industry-leading coverage across their attack surfaces, while maximizing the ROI on their existing security investments.Visit the booth to learn how Expel's human-centric, AI-driven MDR approach delivers the most comprehensive security coverage with unmatched results. Highlights include:A 17-minute mean-time-to-remediate on critical incidents, minimizing disruption so your business keeps running smoothly.on critical incidents, minimizing disruption so your business keeps running smoothly

Recently Posted Jobs

Sign up to get curated job recommendations

Expel is Hiring for 8 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →