Continuous Threat Exposure Management
Know what's exposed. Know what to fix first.
Discover exposed assets, prioritize remediation, and verify fixes across every customer environment.
Identity, cloud, PSA and RMM integrations are currently in beta. See integration status.
The exposure workflow works today. Some integrations are still being proven.
Exploit Hound’s core workflow — discovering assets, correlating exposure, prioritizing remediation with Fix First, tracking changes and verifying fixes — is running today.
Several integrations that extend that workflow are still in guided beta, including identity, cloud, PSA and RMM connections.
We publish the status separately because “the exposure engine works” and “we have validated this against every third-party vendor API” are not the same claim.
For MSPs
Turn another security report into work your technicians can actually finish.
Traditional vulnerability reports can leave an MSP with thousands of findings and no useful answer to the question: What should we fix first?
Exploit Hound connects findings to reachability, known exploitation, asset importance, identity relationships and modeled attack paths. Then it groups them into the changes a technician can actually perform.
Instead of
2,417 findings
the goal is
Here are the 12 changes that remove the most meaningful exposure first.
After the work is done, Exploit Hound checks again. An RMM saying a script completed is not treated as proof that the exposure disappeared.
Discover → Prioritize → Act → Verify
Why not just my RMM, EDR or scanner?
You probably already have security tools. Exploit Hound is designed to connect the evidence between them.
Your RMM knows about managed endpoints.
It does not necessarily know what exists outside its inventory.
Your vulnerability scanner knows about vulnerabilities.
It does not necessarily know which combination creates a route to something important.
Your EDR knows what it sees on protected endpoints.
An asset absent from the EDR console is not automatically proof that the asset is unprotected — only that the tool has no record of it.
Your PSA knows what work has been assigned.
A closed ticket is not proof that the exposure is gone.
Exploit Hound combines these observations into one customer-scoped exposure graph, keeps their sources separate, prioritizes the work, and re-checks the result.
It is not intended to replace every security product in the stack.
It is intended to answer the question those products leave behind: What should we fix first, and did fixing it actually reduce the customer’s exposure?
Where Exploit Hound fits
An MSP-focused workflow connecting discovery, prioritized remediation and verification, with published environment and asset pricing.
Evidence says which kind it is
A route inferred from the graph is called potential. Traffic seen on the wire is observed. A read-only check that confirmed a service is validated. The three are never merged.
Discover freely. Enroll assets deliberately.
Discovery finds everything it can reach; you are billed only for the assets you deliberately enrol as managed. Finding more does not cost more.
Hosted management, local collection
The platform is ours to run. The onsite probe and the OS clients sit in the customer’s environment and report outward. Multi-tenant throughout, with white-labelled reporting.
How Exploit Hound builds the exposure picture
Outside-in discovery, inside-network observation, and endpoint evidence—connected to show what needs attention.
Outside the network
- External attack surfaceActive assessment
- Threat intelligenceIntelligence enrichment
Inside the network needs a collector
- Onsite LAN probePassive discovery, active assessment
- Endpoint agentsLocal inventory collection
- Honeypots and deceptionPassive observation
- Passive network telemetryPassive observation
Systems you connect read-only collection
- Identity, cloud and connected toolsRead-only API / LDAP collection
Reading is one thing and writing is another: raising a PSA ticket, running an approved RMM action and changing a DNS record each modify a system, each needs its own authorisation, and none of them is part of collection.
↓ Matched, correlated and prioritised in the hosted platform, with the source, time, confidence and coverage kept against every observation.
What you get
See exposure from outside and inside your network.
External discovery runs from the hosted platform. Inside the network needs a probe or an agent you deploy, and where neither is there the platform says so rather than reporting the estate as clear.
Connect network, endpoint, identity and threat evidence. Beta
Each observation keeps the source it came from and when it was seen, so a conclusion can be taken apart rather than trusted.
Catch fixes that come undone.
A fix this platform verified and has since seen return is a different problem from a finding that reopened, and is reported as one — with the evidence for the original fix and for its return.
Know when temporary exceptions are still open. Beta
An exception that reaches its date is judged on evidence, not closed by the clock. If nothing could re-check it, that is what it says.
See where your security tools disagree. Beta
An asset a tool has no record of is reported as exactly that — not as unprotected, which is a claim about the customer rather than about what we can see.
Verify the result — and see what remains unknown.
Fixes are re-checked where they can be. Coverage gaps and stale evidence are stated rather than left blank.
How it works
Discover → Prioritize → Act → Verify
Four stages, and the same four everywhere on this site. Correlation, assignment and reporting happen inside these stages rather than being stages a technician waits through.
DISCOVER
Find what is actually there, through whichever collection the environment allows — then join it up: asset to vulnerability, vulnerability to exploitability, exposure to the business context around it.
- External surface, internal network, endpoints, identity
- One evidence-backed exposure graph per customer
- Threat intelligence and network telemetry as enrichment
PRIORITIZE
Thousands of findings become the handful of changes worth doing first, with the reasons attached.
- Ranked by attack paths removed, not by CVSS
- Every point attributable to a named factor
- How Fix First ranks work →
ACT
The work lands in the PSA your technicians already live in, and approved actions run through your RMM.
- HaloPSA, ConnectWise, Autotask, Jira, ServiceNow — beta
- Re-running a recommendation updates the ticket rather than opening a second
- Named actions from a fixed catalogue — never a script we wrote
VERIFY
The service is re-checked, the exposure graph recalculated, and the report says which exposure actually disappeared.
- The RMM reporting success is not evidence; the re-check is
- What could not be checked is reported as unverified, never as fixed
- How verification works →
What it draws on
Prioritization is only as good as what it knows
400,000+
Vulnerability records held, from the CVE Program, NVD, FIRST EPSS, OSV, Exploit-DB, GitHub and CISA KEV. One record is one vulnerability identifier this platform has synchronized. Last synchronized 10 Oct 2026 19:20 UTC.
46,698 exploits
Published proof-of-concept and working exploit code, searchable in its own right — including the entries no CVE was ever assigned to. A public exploit is not evidence of exploitation in the wild; it is weighed as one factor.
290,381 package advisories
The OSV corpus for eight package ecosystems: 51,031 advisories and 239,350 malicious-package records. Most describe packages that have no CVE at all.
CISA KEV
Known exploited vulnerabilities flagged and weighted, not just listed.
EPSS
Exploit prediction scores from FIRST.org, used as one factor among many.
21 identity checks
Read-only Active Directory posture checks, from delegation to certificate templates.
See the evidence behind each recommendation.
Explore the console
Five screens from the running console. Inventory and the graph are Discover, Fix First is Prioritize, Changes is Verify — the same four stages as above.
How the work runs
Four things worth knowing
The short version. Each has a page of its own that explains the mechanism.
Fix First, not severity first
Findings are grouped into the change a technician actually performs, and those changes are prioritized using exploit activity, reachability, asset importance, evidence quality, and the exposures each action could address — not by the severity of the worst finding in the group.
A score you can argue with
Every risk score is the sum of named factors, each carrying the points it contributed and the evidence behind it, with the scoring version recorded on the finding. You can disagree with a number when you can see what built it.
Attack paths, not isolated findings
A weak configuration, an exposed service and a privileged account are one route once they are edges in the same graph. Choke points — the single changes that break the most routes — are what Fix First ranks on.
Closed on evidence, not on assertion
A finding closes when the service is re-checked and the exposure graph recalculated. An RMM reporting success is not evidence. What could not be re-checked is reported as unverified — never as fixed.
Identity is part of your attack surface
Attackers don't stop at software vulnerabilities.
Identity and privilege relationships are edges in the same graph as everything else, which is what makes the route below findable.
The Active Directory assessment requests no directory-write permissions, and reads a fixed attribute allowlist that excludes credential-bearing attributes. It requires explicit written authorization before it runs.
View Product TourWhy identity belongs in the graph
- Compromised workstation
communicates with - Application server
trusted for unconstrained delegation - Domain controller
A delegation misconfiguration is not a separate report — it is an edge in the same graph, so attack path analysis finds routes like this one without anyone writing them down.
Built for MSPs
Manage customer environments from one console.
Identify which organizations need immediate attention, prioritize the exposures that matter most, track remediation SLAs and deliver reports that demonstrate measurable security improvement.
Ranked by attention
Immediate attention, critical, high, moderate, healthy — sorted so triage takes seconds.
Tenant-scoped access
Every query is scoped to the tenant the signed-in user is authorized for, in the data model rather than only in the interface.
Operational health
Agent health, scan health, SLA violations and overdue remediation on the same screen.
Evidence for reviews
Show what changed, what was fixed, and what was verified since the last conversation.
Start with what's actually exposed.
Point Exploit Hound at the assets you are authorized to assess, and see what is exposed, what to fix first, and what the fix actually changed.