MDR, AI/ML

Expel expands MDR coverage across the AI attack surface

Expel is expanding its MDR platform to cover more AI-related security risks as businesses use more AI tools.

When asked about Expel's claims about this being the first MDR solution to cover the full AI attack surface, Sarah Crone, principal product marketing manager at Expel, told MSSP Alert,

"'Full' means all three fronts of AI risk: the threats attackers launch with AI, the risk employees create through everyday AI use, and the exposure inside the AI systems an organization is building and running itself. Expel covers tactics across all three dimensions today, with plans to expand coverage through 2026 and beyond."

To support that broader scope, Expel is pulling AI-related activity into the same detection and investigation workflows it already uses across identity, cloud, SaaS, endpoint and network environments.

Bringing AI activity into MDR workflows

One of the first additions is an integration with Anthropic's Claude Enterprise. Expel pulls usage activity, prompt content and tool use from the Claude Compliance API into its detection pipeline, giving analysts more context around how the tool is being used and what users or systems are trying to do.

Crone said Expel is applying that visibility alongside its broader detection coverage rather than treating AI security as a separate layer.

"We aren’t just building AI-specific detections in a silo; we’ve mapped our detection coverage to MITRE ATLAS and look at AI risk through the entire attack life cycle. Expel’s focus on AI detection spans our 160+ integrations where applicable - endpoint, identity, cloud, SaaS, network, and more."

Expel currently maps its AI-related detections to 13 of the 16 tactics in MITRE ATLAS, the framework focused on threats to AI systems. The company has also introduced AI-focused threat hunting techniques built around AI-related attack patterns and exposure.

Those capabilities are not dependent on Claude. Crone said the MITRE ATLAS-mapped detections and threat hunting work across telemetry that is already available inside a customer's environment.

"At launch, the only live AI-native integration is Anthropic's Claude Compliance API, pulling usage activity, prompt content, and tool use into Expel's detection pipeline. The other two, MITRE ATLAS-mapped detection coverage and AI-focused hunt techniques, aren't Claude-dependent. They run across whatever's already in a customer's environment."

Analysts still drive the decision loop

The other part of Expel's approach is how much responsibility it gives AI inside the SOC. Expel is using AI to accelerate investigation and analysis, while its analysts remain responsible for evaluating signals and making response decisions.

"The difference is who's driving. Expel's operators investigate every signal themselves. AI speeds them up, but it doesn't make the call," Crone said. "That includes the Claude integration above: our people work the prompt content directly instead of handing it to an agent, and it’s not confined to one platform’s telemetry."

That distinction is important as security vendors put more autonomous agents into triage, investigation and remediation. The question for MDR customers is increasingly about what an AI system can act on by itself and where an analyst remains responsible for the outcome.

Expel's Alex Glass, vice president of global channel sales and alliances at Expel, said that human oversight remains central to how the company is approaching AI in the SOC and that speed is only a part of the equation.

"Our approach has always kept humans in the loop. The question is not whether AI belongs in the SOC. It does. The question is whether removing human judgment is the right decision for customers today, and we do not believe it is. The market appears to be moving toward a middle ground that combines AI with human oversight. Expel has AI, humans in the loop, and 10 years of data behind the service. And speed is only one part of the equation. You can collect data, detect activity, enrich information, and triage quickly, but you still need to ask whether the investigation is complete and whether the measurement includes time to respond. Speed, efficiency, and the quality of the outcome are related, but they are not always the same thing. The goal should be to drive the right outcome, not simply the fastest number."

Claude is currently Expel's only live integration built specifically for an AI platform, so the broader AI integration story is still developing. The company plans to add integrations with more model providers and AI security platforms, including support for prompt injection and telemetry generated by AI agents.

"Claude's the first of several," Crone said. "We have expanded AI-native partner integrations are on the roadmap, including coverage for prompt injection and agentic telemetry across a growing set of AI platforms, with integrations spanning model providers and AI-specific EDR and endpoint protection. This roll out will continue through this year and moving forward."

For customers, Expel’s AI-specific telemetry currently comes from Claude, while its broader detection and threat hunting work across existing integrations. As companies use more AI models, apps and agents, security teams will need to connect that activity with identity, endpoint and cloud data to understand the full attack path.

The MSSP opportunity

There is also an MSSP angle, although Expel is not positioning the current release as a multi-tenant service for providers.

"MDR for AI is built for enterprise environments today. Multi-tenant and partner-led delivery for MSSPs isn’t a current focus, but they’re factored into the roadmap as demand develops," Crone said.

For MSSPs, while the immediate opportunity is limited because Expel’s AI coverage is not yet built for multi-tenant or partner-led delivery, the direction is still clear: AI telemetry is becoming another data source SOC teams need to investigate alongside identity, endpoint, cloud and network activity. As customers adopt more AI tools, models and agents, more of that work will move into security operations. For MDR providers, the next step will be expanding coverage across more AI platforms and making it easier to manage across multiple customer environments.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds