At three in the morning, every security alert looks important. A laptop behaves strangely. An identity logs in from somewhere new. A cloud setting changes. An inbox coughs up a suspicious attachment. Modern enterprises have spent years buying tools to notice these things, and the tools have obliged with a blizzard of signals. The remaining problem is stubbornly human: Which warning matters, what happened, and who is awake to do something about it?
Expel lives in that gap. Founded in Virginia in 2016 by Dave Merkel, Yanek Korff and Justin Bajko, the company provides managed detection and response, or MDR. In ordinary language, it connects to a customer's existing security products, monitors them around the clock, investigates suspicious activity and helps contain the real threats. The customer does not buy another endpoint agent or throw away a functioning stack. Expel arrives through APIs, sits above the tools and turns their competing signals into a single operating picture.
This sounds like outsourcing, and it is. But Expel's distinguishing decision was to make outsourced work visible. Its Workbench platform gives customers access to the same investigations its analysts see - the evidence gathered, the actions taken, the reasoning behind a conclusion and the recommended fix. A customer can collaborate while the incident is unfolding instead of waiting for a tidy ticket after the interesting part is over.
“We founded Expel to build the MDR service we wish we could buy.”Expel's account of its origin
01 / The job
An answer factory, not an alert factory
The founders knew the old model from the inside. Merkel had been Mandiant's chief technology officer and later held senior product roles at FireEye. Korff and Bajko also came through Mandiant and FireEye service operations. Their complaint was not that security products failed to produce data. It was that traditional managed providers often compressed a thousand alerts into a hundred and tossed the smaller pile back over the fence. A customer paid for relief and received homework.
Expel's product begins after detection. Workbench gathers signals from endpoint, network, cloud, identity, software-as-a-service, email, operational technology and SIEM products. Automation enriches them with context. Analysts examine what survives, communicate with the customer and record the path from suspicion to decision. Threat hunting adds proactive searches for attacks that automated controls may have missed. Managed phishing takes on the repetitive work around employee-reported messages.
The practical audience is a security leader who cannot staff every specialty for every hour, or who has a capable team trapped in a queue. Large companies use Expel as an extension of an internal security operations center. Smaller enterprises use it to obtain the coverage and expertise they would struggle to assemble alone. Either way, the sale is not fear in the abstract. It is capacity: fewer false positives, faster investigations and more time for an internal team to work on risks particular to its business.
02 / The proof
What a customer actually gets back
Affirm offers a useful example because its results are unusually concrete. The financial technology company used Expel across more than a dozen AWS accounts. According to an AWS case study, Affirm cut the alerts requiring manual review by half, improved mean time to remediate by 40 percent and estimated it would otherwise have needed two to three times as many security engineers to centralize the work. Those numbers describe Expel's economic argument more clearly than a shelf of security acronyms: the service makes an existing team behave like a larger one.
Other customers emphasize a softer benefit: control. Venable has described following investigations and communicating with Expel in the shared platform. An Estes security director called the arrangement a team sport. This is the clever part of the transparency pitch. It is not merely a nicer report. It reduces the distance between an outside provider and the people who remain responsible for the company.
That distance matters during an incident. A ticketing system turns conversation into a relay race. In 2026 Expel added threaded, two-way collaboration between Workbench and Slack or Microsoft Teams. A customer can speak directly with the analysts working an active case and launch an on-demand investigation without hopping between systems. The feature is mundane in the best way. A faster conversation can matter more than a dramatic dashboard.
03 / The machine
Ruxie does the legwork, not the last word
Expel now calls its AI and automation layer Ruxie. The mascot-like name softens a fairly disciplined division of labor. Software collects telemetry, enriches evidence, finds patterns, proposes triage decisions and drafts plain-language records. Human analysts handle ambiguous evidence, business context and consequential calls. The company says Ruxie is trained on a decade of production security operations data and analyst outcomes, an advantage that comes from having operated its own service rather than merely selling software to other people's analysts.
In May 2026, for example, Expel added a blocked-malware triage agent. It automates a roughly five-minute routine: checking a file against outside analysis, reviewing prior Workbench history, adding process and host data and running a seven-rule decision process. The agent recommends approval or escalation. An analyst still makes the decision. Five minutes is not cinematic, but multiplied across a queue it is precisely the kind of chore that determines whether people can concentrate on harder cases.
The company has also introduced an agent that finds gaps in third-party alert coverage and proposes detection rules. Those rules must pass automated syntax tests and mandatory review by Expel's SOC before deployment. Another feature translates detection logic into plain English so customers can inspect why a rule exists. Together, the releases show where Expel wants AI to sit: inside a traceable workflow, with bounded jobs and a visible reviewer.
The durable AI product may not be the one that removes the expert. It may be the one that gives the expert five minutes back, a thousand times over.YesPress
04 / The market
A crowded field, and a narrow place to stand
MDR is not an empty category. Arctic Wolf, Red Canary, eSentire, Rapid7, Secureworks, ReliaQuest, Huntress and CrowdStrike's managed services all compete for variations of the same budget. An enterprise can also build its own operation around a SIEM or XDR platform. Some rivals sell a tightly unified stack. Expel takes the opposite position: customers will continue to own a mixed collection of products, so the managed layer should adapt to them.
A conceptual map of the choices
This technology-agnostic promise has a cost. Supporting more than 160 integrations means chasing vendors as APIs, data models and detections change. It is also a moat. Every connection creates operational knowledge about how one product's signal relates to another's, especially when an attacker moves between identity, cloud and endpoint systems. Expel says its own detection logic surfaced 78.8 percent of alerts tied to critical or high-severity incidents in 2025. The claim is company-reported, but it illustrates the strategy: integrate broadly, then add intelligence in the seams.
The business is recurring enterprise service revenue. Customers subscribe to MDR coverage and add services according to attack surface and operational need. Partners widen the route to market. Expel works with AWS, Microsoft, Google Cloud, CrowdStrike and others while remaining, at least in principle, neutral about which underlying tool wins. This places it between software vendor, consultancy and outsourced operations team - a position that is harder to explain than “buy our box,” but closely matched to how enterprise security is actually assembled.
05 / The company
The joke is on the jargon
Expel has raised $288.8 million. Its $140.3 million Series E in 2021 put its valuation above $1 billion; an additional $31 million arrived in 2022. CapitalG and Paladin Capital Group repeatedly led rounds, with backing that has included Index Ventures, Scale Venture Partners, Greycroft, Battery Ventures, Cisco Investments and March Capital. In 2024, Mandiant founder Kevin Mandia joined the board, reconnecting the company to the professional lineage that produced its founders.
For a company entrusted with grim possibilities, Expel has always sounded mildly amused by its own industry. Employees are “Expletives.” The original brand idea was discussed around a table in Merkel's barn. A 2019 financing announcement included an editor's note listing the buzzwords removed from the press release. That instinct is more than decoration. Security buying is saturated with opaque claims, and Expel's tone says: we know how this language sounds because we used to be the customer.
Humor does not settle the important questions. A buyer still has to test coverage, response authority, data handling and whether vendor-reported speed survives the peculiarities of its environment. The customer also remains accountable. No managed provider can decide how much business interruption an organization will tolerate or which system is too important to isolate without context.
What Expel offers is a more legible partnership around those decisions. The machines gather and sort. The analysts investigate. The customer can look over their shoulder. Ten years after three practitioners set out to stop the 3 a.m. alert ritual, that visibility remains the most interesting part of the company - and the hardest for a competitor to copy with a feature checkbox.