Check here to learn about Expel's latest features, enhancements, fixes, and other improvements.
December 2024
Updates
-
Fix for notifications: Fixes an issue where Wiz notifications were appearing in Org Settings without setup.
- Fix for proxy URL and invalid device messages: Fixes an issue that incorrectly displayed for some security devices, indicating a proxy URL and an invalid device.
November 2024
New Features
- MFA Secret Key: When setting up MFA for your account, you now have the option to scan a QR code or enter a secret key to add the account to the authenticator app.
-
ServiceNow Notification Synchronization: Expel now offers notification synchronization for ServiceNow IT Service Management (ITSM) and Security Incident Response (SIR) modules, so tickets can be continuously updated based on changes in Workbench Investigations or Incidents. ServiceNow is used to support notifications and is not used to ingest security signals for MDR purposes.
Updates
- Fix for Phishing Submissions: Fixes an issue where Phishing submissions were bouncing back when using Microsoft Outlook.
- Fix for Outcome Emails for Simulations: Fixes an issue where outcome emails for Phishing simulations were not received.
- Fix for Other Recipients List: Fixes an issue where the Other Recipients list was not populating for Phishing emails.
- Fix for Security Devices: Fixes an issue where an error message incorrectly described the device as invalid.
October 2024
New Features
- Timestamps: Timestamps are now shown in both local and UTC time in Workbench.
September 2024
New and Updated Integrations
- New: ExtraHop Reveal(x) 360: Expel now integrates with ExtraHop Reveal(x) 360 to bring additional security signals, 360-degree visibility, and situational intelligence into the Expel Workbench platform.
- Updated: CrowdStrike Falcon: CrowdStrike On-Demand Scan alerts are now a part of our CrowdStrike Falcon integration. These alerts can be used to find indicators of malicious activity.
New Features
- Reset Credentials Auto-Remediation for Okta and Microsoft Entra ID: When a user account is compromised and a password reset is necessary, the Reset Credentials Auto-Remediation allows our analysts to reset the password and kill active sessions, stopping the attacker within seconds. Learn how to configure this action for your environment with the recommended security settings.
Updates
- Fix for closed alerts: This fixes an issue where closed, suppressed alerts were incorrectly dispositioned as New in the Workbench Grid view.
- Fix for tool tip: This fixes an issue where the tooltip is cut off when there is a long list of devices included in How did your technologies contribute to detection? bar graphs.