> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-reference/expel-terminology.md).

# Expel Terminology

## Assembler

The Expel Assembler serves as a network proxy to allow our SOC analysts to access the security devices that live on internal networks. It is only needed if your security device lives on a private network where a direct external connection cannot be established.

Learn more about the [Expel Assembler](/connect-your-technology/expel-assembler/about-the-expel-assembler.md) or find it in Workbench at [Settings > Organization Settings > Assemblers](https://workbench.expel.io/settings/assemblers).

## Auto Remediation

An auto remediation enables Expel to automate certain response capabilities within your vendor technology so that attacks can be rapidly contained without requiring any intervention from you. If an auto remediation occurs, you will see it listed as a [Remediation Action](#remediation-action) in Workbench. There are a variety of auto remediations to choose from and they can be enabled or disabled individually at any time.

Learn more about [Auto Remediations](/workbench-setup/auto-remediations/about-auto-remediations.md) or edit them in Workbench at [Settings > Organization Settings > My Organizations > select an organization if multiple exist > Auto Remediations](https://workbench.expel.io/settings/organizations/).

## Detection Strategy

Expel's Detection Strategy automates certain types of decisions related to Events and triage, creates associated Expel Alerts when required, or marks an Event as benign. The specific detection strategy employed for a piece of vendor technology varies based on the type of technology it is, but in general the strategy always focuses on where fidelity is higher and we also still have time to act.

Learn more about [Detection Strategy](/workbench-reference/detections/about-detection-strategy.md) or find it in Workbench at [Tools > Detections > Detection Strategy.](https://workbench.expel.io/tools/detections/strategy)

## DUET

A DUET (did you expect this) rule flags certain events as needing an immediate verification or notification, and bypasses the [normal event triage process](/workbench-reference/alerts/how-expel-alerts-work.md#event-triage-process). The events subject to DUET rules contain behaviors that are not typically indicative of true security incidents, as they are related to policy violations or potential risk. When a DUET is enabled, the activity will be flagged for investigation and will be routed to you (rather than to us) to take a specified first action.

Find DUETs in Workbench at [Tools > Detections](https://workbench.expel.io/tools/detections/all) (search for "DUET" in the rule name or description).

## Event

Expel refers to the signals coming from the integrations you connected to Workbench as Events. These signals may take the form of actual alerts from security technologies, logs and signals from cloud and SaaS integrations, or audit events produced by other software that Expel monitors. Not all Events will require action from Expel (in the form of an associated [Expel Alert](#expel-alert)), but every Event will be associated with a specific security device in Workbench.&#x20;

Events do not have a status and we do not assign them to anyone; you can [search your Events](/workbench-reference/search-for-an-event.md) via <img src="/files/Wdq00CiWPzv3ihPoPCGB" alt="Image showing search for an event option in Workbench." data-size="line"> at the bottom left of Workbench.

## Expel Alert

An Expel Alert is created when a security event - typically an [Event](#event) or on-demand investigation request - merits further research or investigation on our part. Expel Alerts may be generated automatically because of detection strategy or created manually at any time by our SOC team. Expel Alerts are given a severity rating of Critical, High, Medium, or Low. The severity is determined by a combined approach that considers alert fidelity, alert impact, and security product fidelity.

Learn more about [Expel Alerts](/workbench-reference/alerts/how-expel-alerts-work.md) or find them in Workbench at [Activity > Alerts](https://workbench.expel.io/activity/alerts). See also, [Lead Alert](#lead-alert).

## Finding

**Incident Findings** are where our SOC analysts document answers to questions like: What is it? Where is it? When did it get here? How did it get here? These Findings are used for Investigations that have been flagged as an Incident. You may see text-only findings or more detailed evidence findings.

View Incident Findings in Workbench: [Activity > Incidents > select an incident](https://workbench.expel.io/activity/incidents)

**Hunting Findings** are used to report what was discovered during [threat hunts](/more-features/expel-threat-hunting/expel-hunting.md), and can be [categorized](/more-features/expel-threat-hunting/expel-hunting.md#categories-of-findings) as Malicious, Suspicious, or Notable.

View Hunting Findings in Workbench: [Activity > Hunting > Hunts > select an investigation](https://workbench.expel.io/activity/hunting/investigations)

## Incident

An Incident is simply a flag on an Investigation that enables Expel to document [Findings](#finding) and create [Remediation Actions](#remediation-action). Every Investigation is eventually either flagged as an Incident because there is a potential threat to your environment, or closed as benign with no further action needed. Anything that is especially urgent will be categorized as a Critical Security Incident.

Although an Incident is not actually a separate entity (each Incident is simply an Investigation that was flagged as a threat - learn more [here](/workbench-reference/investigations-and-incidents/understanding-incidents.md)), you can quickly view all Investigations flagged as Incidents in Workbench at [Activity > Incidents](https://workbench.expel.io/activity/incidents).&#x20;

## Investigation

The SOC analyst may decide to create an Investigation based on an Expel Alert, which means they believe there is a need for more in-depth analysis. The Investigation is where Expel can perform additional actions (labeled [Investigative Actions](#investigative-action)) to uncover more information and help determine the scope and nature of the activity that created the initial Expel Alert. Some Investigations will be flagged as Incidents, and some will be closed as benign with no further action needed. Customers with MDR contracts can also create [on-demand investigations](/workbench-reference/investigations-and-incidents/create-an-on-demand-investigation.md) if the suspicious activity meets certain criteria.

Learn more about [Investigations](/workbench-reference/investigations-and-incidents/understanding-investigations.md) or find them in Workbench at [Activity > Investigations](https://workbench.expel.io/activity/investigations).

## Investigative Action

An Investigative Action is how Expel tracks its activities and research related to an Expel Alert or to an open Investigation. An Investigative Action may capture an automated process or it may result in a notification to you, asking you to complete a manual process. You may see either of the following notification labels in Workbench:

* [Verify Action](#user-content-fn-1)[^1] - when we identify something that is highly suspicious, and ask you to verify whether or not the activity is authorized for business reasons.
* Notify Action - when we identify something that is not entirely malicious but is highly suspicious or a potential policy violation, and recommend an action for you to take (such as gathering device data or uploading a file for our SOC analysts).

Learn more about [Investigative Actions](/workbench-reference/investigations-and-incidents/understanding-investigations.md#investigative-actions) or find them in Workbench at [Activity > Actions](https://workbench.expel.io/activity/actions).&#x20;

## Josie

Josie is a bot that assists our SOC analysts with the alert triage process by leveraging detection strategies to automatically classify certain Events and then trigger the necessary Expel Alerts. Josie runs in the background and is not managed in Workbench.

## Lead Alert

A Lead Alert is the Expel Alert that initially triggered an Investigation or Incident. Additional Expel Alerts may also be linked to the same Investigation or Incident.

Learn more about [Expel Alerts](#expel-alert).

## Lookout

A Lookout is a type of supplemental rule that complements our [Detection Strategy](#detection-strategy). There are two types of Lookout Rules that can be applied: automatically create an Expel Alert, or automatically create an Investigation. Lookouts are used to process certain types of Events that meet very specific internal criteria, and the two Lookout Rule types can be used separately or together to override the behavior of our detection engine.

Learn more about [Lookout Rules](/workbench-reference/detections/lookout-rules.md) or find Lookouts in Workbench at [Tools > Detections > Lookouts](https://workbench.expel.io/tools/detections/lookouts).

## Org Context

Expel uses the term Org Context to refer to stored reference information about your environment. This type of context can be added by you or may be added proactively by our SOC analysts. You can use Org Context to decrease the number of manual verifications (Verify Actions) you must make, which allows our SOC analysts to respond to incidents more efficiently.

Learn more about [Context](/workbench-setup/get-started/add-and-manage-org-context.md) or find it in Workbench at [Settings > Organization Settings > Context.](https://workbench.expel.io/settings/context)

## Remediation Action

A Remediation Action contains the SOC analyst's recommendations on the best next actions to take to mitigate threats to your environment. The analyst will provide this guidance when they do not have sufficient access to your system and/or are not able to perform the task themselves based on the technology. You may also choose to enable one or more [Auto Remediations](#auto-remediation) to instruct our platform to perform certain SOC recommendations automatically, and to grant Expel with the necessary access to do so. Remediation Actions are only used for Investigations that have been flagged as an Incident.

Find Remediation Actions in Workbench at [Activity > Actions](https://workbench.expel.io/activity/actions) and in your Findings report ([Activity > Incidents > locate an incident and select the Findings link](https://workbench.expel.io/activity/incidents)).&#x20;

## Ruxie

Ruxie is a bot that assists our SOC analysts with the process of creating new Investigative Actions due to Expel Alerts or open Investigations. Ruxie runs in the background and is not managed in Workbench.

## Security Device

The method of connecting and monitoring each supported tech integration in Workbench. Every instance of an integration must have an associated security device (you add it during the final step of the setup process).

Learn more about [security device health](/connect-your-technology/security-devices/security-device-health.md) or how to [manage a security device](/connect-your-technology/security-devices/manage-security-devices.md).

## Situation Report

The Situation Report shows an overview of all security activity at your organization, including open action items that may need to be addressed by you.

Learn more about the [Situation Report](/workbench-reference/dashboards/situation-report-dashboard.md) or find it in Workbench at [Dashboards > Situation Report](https://workbench.expel.io/dashboards/situation-report).

## Suppression

A Suppression is a type of supplemental rule that complements our [Detection Strategy](#detection-strategy). It refers to a manual rule that our SOC analysts have added to help filter out known benign issues from Expel Alerts, and to automatically close an Expel Alert if it meets very specific internal criteria before it comes to a SOC analyst. Suppression Rules can be created for your organization, for multiple organizations, or for all Expel customers.

Learn more about [Suppression Rules](/workbench-reference/detections/suppression-rules.md) or find Suppressions in Workbench at [Tools > Detections > Suppressions](https://workbench.expel.io/tools/detections/suppressions).

## "Time To" Definitions

To help you understand our response timelines, we offer a few different metrics.

<div align="left"><figure><img src="/files/BSCi9BIVFrs9zxlOxrmn" alt="An image of the flow." width="563"><figcaption></figcaption></figure></div>

* **Time to Detect** - The time between when an event is created in your environment, to when an Expel Alert is created.
* **Time to Triage** - The time between Expel Alert creation and the first instance of SOC analyst activity on it. (When an Expel Alert appears in our queue, we often do a quick visual triage to determine urgency and prioritization.)
* **Time to Decision** - The time between an Expel Alert arriving in the queue, to when the SOC analyst actively makes a decision about what to do with it. They may decide to close it, to create an Investigation, to add it to an existing Investigation, or to immediately flag it as an Incident.
* **Time to Investigate** - The time between when an Investigation is created to when the investigative work ends, and it is either closed, assigned to you, or flagged as an Incident.
* **Time to Acknowledge** - The time between when the Expel Alert was created and when an Incident was created.&#x20;
* **Time to Respond** - The entire lifecycle of the Investigation, from when the Expel Alert was first created to when the first Remediation Action was recommended.

## Workbench Notifications

Expel Workbench has two types of notifications: an email notification is configured at the user level and sent to an individual email address, and an organization notification is configured at the organization level and sent to a communications platform like Slack​​® or Microsoft Teams™.

Learn more about [notifications](/workbench-setup/notifications/about-notifications.md) or find them in Workbench at [Settings > Organization Settings > My Organizations > select an organization if multiple exist > Notifications](https://workbench.expel.io/settings/organizations) or [Settings > Organization Settings > Users > View and edit a user > Email notifications](https://workbench.expel.io/settings/users).

[^1]: You have three options for responding to a Verify Action. For more information, see [Verify Action](/workbench-reference/investigations-and-incidents/understanding-investigations.md#verify-action).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-reference/expel-terminology.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
