
Ease of onboarding.
Not too reactive when it comes to alerts. Review collected by and hosted on G2.com.
There isn't much I don't like. Maybe a couple alerts I think they should have acted on. Review collected by and hosted on G2.com.

Ease of onboarding.
Not too reactive when it comes to alerts. Review collected by and hosted on G2.com.
There isn't much I don't like. Maybe a couple alerts I think they should have acted on. Review collected by and hosted on G2.com.
Security operations are often an afterthought in startup environments. Our partnership with Expel ensures this isn't the case and our business and customers remain protected. During the sales process, we mapped our cloud/SaaS ecosystem to a number of MDRs, and only Expel came close. Onboarding took less than a day. Expel's new features have served us well as our business has morphed and changed. Reporting is targeted toward our security objectives. Customer relationship management is strong. Whenever we've had issues/incidents (which has been very rare), support is responsive, direct, and fast in resolving. Review collected by and hosted on G2.com.
I haven't encountered many downsides. From a pricing perspetive, they are at the top, though for a startup like ours, I've found that the ROI counterbalanaces the cost nicely. Review collected by and hosted on G2.com.
Expel aim to be a true partner that can be a replacemet for a SOC or a part of a hybrid SOC model. The platform is easy to implement and instantly provides value. The product covers a widest range of log sources and can assist any company under-going a digital transformation in to the cloud. Review collected by and hosted on G2.com.
The detection strategy isn't transparent for a customer building a hybrid SOC implementation and can make it difficult to report on detection posture. Review collected by and hosted on G2.com.

Time-To-Value was huge, we had all of our tools feeding into Expel and getting Actionable alerts within hours of starting our Proof Of Concept.
Low False Positive Rate: our previous provider had a very high noise to signal ratio of alerts. Expel has vastly reduced the rate of false positives being sent to our team, freeing my team up to tackle bigger security projects and spend less time chasing ghosts.
Alert to Incident times are consistently the fastest i've ever seen from an MDR provider with most Incidents being opened in less than 5 minutes after an alert is generated.
Auto-Remediation Options, while more providers are offering this, it's nice to not only have these features - but Expel also offers a great deal of granularity in selecting what remediation actions can be performed on what accounts or devices through the customer context you provide.
With Expel, I sleep soundly knowing if something goes wrong we've got a word class security partner watching over our environment Review collected by and hosted on G2.com.
Expel offers extremely robust and smart features and tools in Slack, unfortunately many of those features are not also available in Microsoft Teams, as a Microsoft centric organization this has been our biggest downside. But at the end of the day it's a pretty minor annoyance.
There is 1 tool that we are currently using that does not integrate natively with Expel, overall the impact is pretty minor - but it's always nice to have more integrations. Review collected by and hosted on G2.com.

The time to onboard 14 security devices was quite astounding. Within 8 hours of having an environment provisioned, our workbench was fully operational. The depth and breadth of information provided to alerts and incidents has allowed our ops team to push the benchmark forward. Review collected by and hosted on G2.com.
Nothing to complain about as of yet. All tracked service levels are being exceeded with strong margin. Review collected by and hosted on G2.com.
Expel sets itself apart from the competition by offering SLA's on alerts. This is a game changer. Without a SLA, how do you sleep at night knowing that your MSP might be handling a alert quickly or not. Expel has a very easy dashboard that offers quick insights into your environment.
Sales team was easy to work with and helped design a solution that fit our company. Review collected by and hosted on G2.com.
Expel has been running in our environment for the past 6 months and we have not run into any dislikes yet. Review collected by and hosted on G2.com.
Expel’s centralized dashboards provide valuable information to investigate threats. The data related to investigations is well organization and easy to locate key information. Expel provides notification when an investigation is kickd off which allows our security team to get a head start with investigating and remediating threats. Review collected by and hosted on G2.com.
Expel does have some limitiations on what applications or security solutions it can be integrated with but they are always adding new solutions so we look forward to any new interractions they expand to. Review collected by and hosted on G2.com.

The ease to integrate with their workbench platform and their knowledge to get telemetry through splunk made the implementation quick and proved value early. They have deep knowledge to build custom rules based out of splunk and quickly accelerated the time to detect and respond across the security teams. Review collected by and hosted on G2.com.
The only thing I've disliked was the price. At some point it became hard too afford due to cost cutting and some other internal issues. They worked out a renewal at a very good deal (which is a plus) but I would still think that the overall TCO being better would be the only thing making me stay away of a 10 Review collected by and hosted on G2.com.
The gears behind the expel engine which works inteligently with so many widley available hooks of integrations Review collected by and hosted on G2.com.
So far nothing found any bad noise. Review collected by and hosted on G2.com.
The SOC is able to reduce the amount of false positives and provide analysis on alerts where needed. Threat update are VERY GOOD and we have leveraged these a good deal to assess and beter secure our environment. Review collected by and hosted on G2.com.
Lately (within the last 6 months) there has been a reduction in commo between our groups. Example - the SOC recently elevated a alert the was a more minor conditional access to a BEC - when BEC was not the source. We clarified this to Ruxie and our Customer Rep, but did not get a resolution or recommendation for almost a month after raising it. Interactive commo (asking questions through Slack) is delayed at best - very unresponsive at worst. If a better way to interact with the SOC needs to be identified, then customers should be made aware. Review collected by and hosted on G2.com.