Continuous Threat Exposure Management

Know what's exposed. Know what to fix first.

Discover exposed assets, prioritize remediation, and verify fixes across every customer environment.

Identity, cloud, PSA and RMM integrations are currently in beta. See integration status.

sniff.exploithound.com/fix-firstDemonstration data · v2.80.2
The Fix First view in the Exploit Hound console: remediation actions ranked, each with the reasons behind its position and the modeled attack paths it could remove
Expand
The Fix First view from the running console. Real interface, invented environment — every hostname uses example.com. See the full tour →

The exposure workflow works today. Some integrations are still being proven.

Exploit Hound’s core workflow — discovering assets, correlating exposure, prioritizing remediation with Fix First, tracking changes and verifying fixes — is running today.

Several integrations that extend that workflow are still in guided beta, including identity, cloud, PSA and RMM connections.

We publish the status separately because “the exposure engine works” and “we have validated this against every third-party vendor API” are not the same claim.

See every capability and its validation status →

For MSPs

Turn another security report into work your technicians can actually finish.

Traditional vulnerability reports can leave an MSP with thousands of findings and no useful answer to the question: What should we fix first?

Exploit Hound connects findings to reachability, known exploitation, asset importance, identity relationships and modeled attack paths. Then it groups them into the changes a technician can actually perform.

Instead of

2,417 findings

the goal is

Here are the 12 changes that remove the most meaningful exposure first.

After the work is done, Exploit Hound checks again. An RMM saying a script completed is not treated as proof that the exposure disappeared.

Discover → Prioritize → Act → Verify

Why not just my RMM, EDR or scanner?

You probably already have security tools. Exploit Hound is designed to connect the evidence between them.

Your RMM knows about managed endpoints.

It does not necessarily know what exists outside its inventory.

Your vulnerability scanner knows about vulnerabilities.

It does not necessarily know which combination creates a route to something important.

Your EDR knows what it sees on protected endpoints.

An asset absent from the EDR console is not automatically proof that the asset is unprotected — only that the tool has no record of it.

Your PSA knows what work has been assigned.

A closed ticket is not proof that the exposure is gone.

Exploit Hound combines these observations into one customer-scoped exposure graph, keeps their sources separate, prioritizes the work, and re-checks the result.

It is not intended to replace every security product in the stack.

It is intended to answer the question those products leave behind: What should we fix first, and did fixing it actually reduce the customer’s exposure?

Where Exploit Hound fits

An MSP-focused workflow connecting discovery, prioritized remediation and verification, with published environment and asset pricing.

Evidence says which kind it is

A route inferred from the graph is called potential. Traffic seen on the wire is observed. A read-only check that confirmed a service is validated. The three are never merged.

Discover freely. Enroll assets deliberately.

Discovery finds everything it can reach; you are billed only for the assets you deliberately enrol as managed. Finding more does not cost more.

Hosted management, local collection

The platform is ours to run. The onsite probe and the OS clients sit in the customer’s environment and report outward. Multi-tenant throughout, with white-labelled reporting.

How Exploit Hound builds the exposure picture

Outside-in discovery, inside-network observation, and endpoint evidence—connected to show what needs attention.

Outside the network

  • External attack surfaceActive assessment
  • Threat intelligenceIntelligence enrichment

Inside the network needs a collector

  • Onsite LAN probePassive discovery, active assessment
  • Endpoint agentsLocal inventory collection
  • Honeypots and deceptionPassive observation
  • Passive network telemetryPassive observation

Systems you connect read-only collection

  • Identity, cloud and connected toolsRead-only API / LDAP collection

Reading is one thing and writing is another: raising a PSA ticket, running an approved RMM action and changing a DNS record each modify a system, each needs its own authorisation, and none of them is part of collection.

↓ Matched, correlated and prioritised in the hosted platform, with the source, time, confidence and coverage kept against every observation.

See what each source collects, needs and cannot tell you

What you get

  • See exposure from outside and inside your network.

    External discovery runs from the hosted platform. Inside the network needs a probe or an agent you deploy, and where neither is there the platform says so rather than reporting the estate as clear.

  • Connect network, endpoint, identity and threat evidence. Beta

    Each observation keeps the source it came from and when it was seen, so a conclusion can be taken apart rather than trusted.

  • Catch fixes that come undone.

    A fix this platform verified and has since seen return is a different problem from a finding that reopened, and is reported as one — with the evidence for the original fix and for its return.

  • Know when temporary exceptions are still open. Beta

    An exception that reaches its date is judged on evidence, not closed by the clock. If nothing could re-check it, that is what it says.

  • See where your security tools disagree. Beta

    An asset a tool has no record of is reported as exactly that — not as unprotected, which is a claim about the customer rather than about what we can see.

  • Verify the result — and see what remains unknown.

    Fixes are re-checked where they can be. Coverage gaps and stale evidence are stated rather than left blank.

How it works

Discover → Prioritize → Act → Verify

Four stages, and the same four everywhere on this site. Correlation, assignment and reporting happen inside these stages rather than being stages a technician waits through.

01

DISCOVER

Find what is actually there, through whichever collection the environment allows — then join it up: asset to vulnerability, vulnerability to exploitability, exposure to the business context around it.

  • External surface, internal network, endpoints, identity
  • One evidence-backed exposure graph per customer
  • Threat intelligence and network telemetry as enrichment
02

PRIORITIZE

Thousands of findings become the handful of changes worth doing first, with the reasons attached.

03

ACT

The work lands in the PSA your technicians already live in, and approved actions run through your RMM.

  • HaloPSA, ConnectWise, Autotask, Jira, ServiceNow — beta
  • Re-running a recommendation updates the ticket rather than opening a second
  • Named actions from a fixed catalogue — never a script we wrote
04

VERIFY

The service is re-checked, the exposure graph recalculated, and the report says which exposure actually disappeared.

  • The RMM reporting success is not evidence; the re-check is
  • What could not be checked is reported as unverified, never as fixed
  • How verification works →

What we scan, and how

What it draws on

Prioritization is only as good as what it knows

400,000+

Vulnerability records held, from the CVE Program, NVD, FIRST EPSS, OSV, Exploit-DB, GitHub and CISA KEV. One record is one vulnerability identifier this platform has synchronized. Last synchronized 10 Oct 2026 19:20 UTC.

46,698 exploits

Published proof-of-concept and working exploit code, searchable in its own right — including the entries no CVE was ever assigned to. A public exploit is not evidence of exploitation in the wild; it is weighed as one factor.

290,381 package advisories

The OSV corpus for eight package ecosystems: 51,031 advisories and 239,350 malicious-package records. Most describe packages that have no CVE at all.

CISA KEV

Known exploited vulnerabilities flagged and weighted, not just listed.

EPSS

Exploit prediction scores from FIRST.org, used as one factor among many.

21 identity checks

Read-only Active Directory posture checks, from delegation to certificate templates.

See the evidence behind each recommendation.

Explore the console

Five screens from the running console. Inventory and the graph are Discover, Fix First is Prioritize, Changes is Verify — the same four stages as above.

sniff.exploithound.com/assetsDemonstration data · v2.80.2
Exploit Hound discover step: External surface, internal networks and endpoints in one inventory, each carrying the context prioritization depends on.

External surface, internal networks and endpoints in one inventory, each carrying the context prioritization depends on. 1Authorization state2Scope3Environment

Real interface, demonstration environment. See the walkthrough →

How the work runs

Four things worth knowing

The short version. Each has a page of its own that explains the mechanism.

Fix First, not severity first

Findings are grouped into the change a technician actually performs, and those changes are prioritized using exploit activity, reachability, asset importance, evidence quality, and the exposures each action could address — not by the severity of the worst finding in the group.

How the ranking is built →

A score you can argue with

Every risk score is the sum of named factors, each carrying the points it contributed and the evidence behind it, with the scoring version recorded on the finding. You can disagree with a number when you can see what built it.

Factor by factor → · Try it on a synthetic finding →

Attack paths, not isolated findings

A weak configuration, an exposed service and a privileged account are one route once they are edges in the same graph. Choke points — the single changes that break the most routes — are what Fix First ranks on.

How paths are built →

Closed on evidence, not on assertion

A finding closes when the service is re-checked and the exposure graph recalculated. An RMM reporting success is not evidence. What could not be re-checked is reported as unverified — never as fixed.

How verification works →

Identity is part of your attack surface

Attackers don't stop at software vulnerabilities.

Identity and privilege relationships are edges in the same graph as everything else, which is what makes the route below findable.

The Active Directory assessment requests no directory-write permissions, and reads a fixed attribute allowlist that excludes credential-bearing attributes. It requires explicit written authorization before it runs.

View Product Tour

Why identity belongs in the graph

  • Compromised workstation
    communicates with
  • Application server
    trusted for unconstrained delegation
  • Domain controller

A delegation misconfiguration is not a separate report — it is an edge in the same graph, so attack path analysis finds routes like this one without anyone writing them down.

Built for MSPs

Manage customer environments from one console.

Identify which organizations need immediate attention, prioritize the exposures that matter most, track remediation SLAs and deliver reports that demonstrate measurable security improvement.

Ranked by attention

Immediate attention, critical, high, moderate, healthy — sorted so triage takes seconds.

Tenant-scoped access

Every query is scoped to the tenant the signed-in user is authorized for, in the data model rather than only in the interface.

Operational health

Agent health, scan health, SLA violations and overdue remediation on the same screen.

Evidence for reviews

Show what changed, what was fixed, and what was verified since the last conversation.

See Exploit Hound for MSPs

sniff.exploithound.com/mspDemonstration data · v2.80.2
Exploit Hound multi-customer console: four customers ranked by attention needed, with exposure score, critical findings, known exploited vulnerabilities, paths to critical systems, agent health and overdue remediation for each

Real interface, demonstration environment with invented customer names. See Exploit Hound for MSPs → 1Customers needing attention2Why each one needs it

Start with what's actually exposed.

Point Exploit Hound at the assets you are authorized to assess, and see what is exposed, what to fix first, and what the fix actually changed.

v2.80.2 Exploit Hound 2.80.2 · Continuous Threat Exposure Management