Our SOC-as-a-service capability offers 24x7 security monitoring and response for cloud, hybrid and on-premises environments. We use the security signals our customers already own so organizations can get more value from their existing security investments. We connect to customer tech remotely through APIs, not agents, so our SOC can start monitoring a customer's environment in a matter of hours, letting their internal teams get back to focusing on the most strategic security priorities that are unique to their business.
Secure your cloud. Expel's detection and response strategy is tailored for each cloud provider and our team is continually monitoring changes and improving our detection strategy, so you do not have to
Free up analysts time. Since Expel is chasing down your alerts, your team can focus on security risks unique to your business. When we investigate something that needs your attention we will tell you and provide clear instructions on how to fix it.
Fix the root cause of recurring incidents - We package up details on recurring incidents and highlight the root cause, how to fix the event from recurring and the business impact to implementing the change.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension for cloud infrastructure protection. You buy in units, where each unit covers 500 resources. Pricing scales with how many resources you need to protect: add more units as your cloud footprint grows. You commit to a 1-year contract and pay upfront. The managed detection and response service monitors your cloud environment around the clock. Since only one dimension exists, your total cost depends on the number of 500-resource units you purchase for the term.
Top-of-mind questions for buyers
What counts as one resource toward my 500-resource unit?
A resource is any cloud asset the service monitors across your environment. Expel covers cloud infrastructure, workloads, containers, and hosts. Each monitored asset counts individually toward your unit total. One unit covers 500 such resources, so your unit count scales with how many cloud assets you protect.
What happens if my protected resources grow beyond the units I purchased?
Pricing scales by adding more 500-resource units as your cloud footprint grows. Each additional unit covers another 500 resources. You purchase enough units to cover your resource count for the contract term. Growth beyond your current units means buying more units rather than an automatic tier jump.
What security work is included once I buy a cloud infrastructure unit?
Each unit covers 24x7 managed detection and response for your cloud environment. Expel provides monitoring, alert triage, threat investigation, and automated containment. The service also includes threat hunting, threat intelligence, and metrics reporting. Coverage spans cloud hosts, containers, and workloads under continuous monitoring.
expel.io+1
Helpful?
Vendor refund policy
No refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Continuous security monitoring and incident response across cloud, hybrid, and on-premises environments
API-Based Integration
Remote connection to customer infrastructure through APIs without requiring agent deployment, enabling monitoring initiation within hours
Cloud Provider-Specific Detection Strategy
Detection and response strategies tailored to individual cloud providers with continuous monitoring of provider changes and detection improvements
Alert Investigation and Remediation Guidance
Investigation of security alerts with clear remediation instructions and actionable guidance for addressing identified threats
Recurring Incident Analysis
Analysis and documentation of recurring incidents including root cause identification, remediation recommendations, and business impact assessment
Continuous Threat Monitoring
24x7 monitoring of networks, endpoints, and cloud environments for threat and risk detection
Incident Detection and Response
Managed investigations and guided response capabilities to detect and respond to critical security incidents within minutes
Multi-Environment Coverage
Monitoring across networks, endpoints, and cloud environments for comprehensive security visibility
Security Operations Platform
Arctic Wolf Platform providing the foundation for threat detection and response capabilities
Managed Security Team
Named security experts with cloud expertise providing security advisory and operational support
Extended Detection and Response (XDR) Technology
XDR technology with full coverage across endpoints, network, users, and cloud environments powered by proprietary Threat Intelligence and Detection Engine
Unlimited Data Ingestion and Retention
Unlimited data ingestion capability with 13 months of data storage for comprehensive investigation and threat visibility
24/7 Threat Hunting and Incident Response
Round-the-clock monitoring, triage, investigation, threat hunting, and incident response services delivered by security experts
Vulnerability and Exposure Management
Integrated vulnerability management and exposure management capabilities to identify and prioritize risks for remediation
Digital Forensics and Investigation
Unlimited end-to-end digital forensics and incident response capabilities regardless of investigation complexity or duration
Rapid threat management and diverse technology integration for effective monitoring
Reviewed on Oct 16, 2024
Review provided by PeerSpot
What is our primary use case?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so forth. Expel is beneficial for customers with diverse environments in terms of technologies that need monitoring and managed detection and response. It's particularly effective if the customer has a deep cloud deployment.
How has it helped my organization?
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.
What is most valuable?
The most valuable features of Expel include the short time to value, their vast library of technology integrations, and their easy-to-use Workbench platform. Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses.
What needs improvement?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management. If Expel could provide a place to store logs, it could satisfy this gap.
For how long have I used the solution?
I've been associated with Expel for a little over two years.
How are customer service and support?
Expel's customer service is very high, at an eight or nine out of ten. They provide strong service despite the natural limitations of human involvement.
Which solution did I use previously and why did I switch?
I have customers who have switched from Expel to others and vice versa. Some started without any provider and chose Expel after evaluations.
How was the initial setup?
The initial setup of Expel is very straightforward and easy, often completed in a few days. If the customer provides the necessary access, the setup can be done rapidly.
What about the implementation team?
The implementation typically involves an onboarding manager, an onboarding engineer, and possibly someone from customer success, alongside a single point of contact from the customer's side.
What was our ROI?
Expel's Workbench platform and dashboards provide the ability to compare similar tools in a customer's environment. This allows customers to assess which tools are more effective and possibly eliminate redundancy, providing cost savings.
What's my experience with pricing, setup cost, and licensing?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What other advice do I have?
I currently have two deals that Expel is likely to win, indicating my recommendation for the solution.