Continuous Threat Exposure Management

Know what's exposed. Know what matters. Know what to fix first.

Exploit Hound correlates vulnerabilities, external exposure, endpoint context, identity risk, threat signals and attack paths, so MSPs can fix the issues that remove the most real-world risk first.

Setup is guided rather than self-service: authorization, probe scope and integration credentials all have to be confirmed before anything is assessed.

Built for MSPs and MSSPs. Multi-tenant by design · prioritization beyond severity · PSA and RMM workflows through supported integrations · fixes verified by re-checking · scoring a technician can explain.

Selected PSA, RMM, identity and cloud integrations are currently in beta. See integration status.

External attack surface Internal network discovery Endpoint agents Configuration assessment Exposure graph Attack paths Risk scoring Fix First Fix verification Active Exposure Compliance mapping PSA ticketing Multi-tenant MSP console
sniff.exploithound.com/fix-firstDemonstration data · v2.75.0
The Fix First view in the Exploit Hound console, listing remediation actions ranked by the attack paths and findings each one removes

The Fix First view from the running console. Real interface, demonstration environment — every hostname uses example.com. See the full tour → 1Recommended actions2Why this one is first3Estimated reduction

Not just another vulnerability scanner

Traditional scanners generate thousands of findings. Exploit Hound connects them.

Severity alone cannot tell you whether a finding is reachable, whether the affected system matters, or whether one change clears twelve of them at once. The dangerous combinations sit between tools — an exposed service on one report, a weak configuration on another, a privileged account on a third. Exploit Hound stores assets, services, weaknesses, identities and observed traffic as a single evidence-backed graph, per customer, fully isolated.

Architecture

Cloud management. Local visibility.

Exploit Hound is a hosted platform. The collection happens inside your customers’ networks, on the machines and segments where the assets actually live, and reports out to the platform over a connection the customer’s side opens.

Exploit Hound deployment The hosted Exploit Hound platform sits outside the customer environment. Inside the customer environment, an onsite probe and endpoint clients collect from assets and send results outbound over TLS on port 443 to the platform. Every connection is started from inside the customer network; the platform opens none inward, and the customer opens no inbound port. Customer environment Runs on your infrastructure Onsite probe Network discovery and assessment Endpoint clients Linux, Windows and macOS hosts Authorized assets Only assets you have explicitly marked authorized are assessed collects Exploit Hound — hosted Operated by us. You do not deploy it. Ingestion and correlation Exposure graph, per tenant Attack paths and Fix First Ranking and verification Console and reporting Multi-customer view Outbound TLS 443 initiated from inside No inbound connection to the customer network
Deployment. The management platform is hosted and operated by Exploit Hound; you never install it. An onsite probe and endpoint clients run inside your environment, collect only from assets you have authorized, and report outbound over TLS on port 443. Every connection is initiated from inside your network — you open no inbound port, and nothing of ours reaches in.

The platform is ours to run, patch and keep current — there is nothing for you to host. What runs in the customer environment is the collection, because a scanner outside a network cannot see what a machine inside it can. Local collector health therefore depends on the customer’s own infrastructure and connectivity as well as on us; the status page says which half it can speak for.

Why Exploit Hound instead of another scanner?

Traditional scanners tell you what is wrong. Exploit Hound connects the evidence, ranks the changes that remove the most exposure, and re-checks the environment to prove what the fix actually changed.

Findings become actions

Fix First groups findings into the changes a technician actually performs, and ranks those by what each one removes rather than by the severity of its worst member.

Ranked by exposure, not severity

Whether something is reachable, whether the system it sits on matters, and whether one change clears twelve findings at once — none of which a severity number can tell you.

Every score is explainable

A score is the sum of named factors and the methodology version is stored with it, so last quarter’s numbers are not silently reinterpreted by this quarter’s model.

Evidence says which kind it is

A route inferred from the graph is called potential. Traffic seen on the wire is observed. A read-only check that confirmed a service is validated. The three are never merged.

Nothing closes without a re-check

An RMM reporting success is a script exiting zero. The exposure is gone when a targeted re-check says so, and what could not be checked is reported as unverified rather than as fixed.

Discovered is not billable

Discovery finds everything it can reach; you are billed only for the assets you deliberately enrol as managed. Finding more does not cost more.

Hosted management with local collection: the platform is ours to run, the onsite probe and OS clients sit in the customer’s environment and report outward. Multi-tenant throughout, with white-labelled reporting.

How it works

Discover → Correlate → Prioritize → Assign → Remediate → Verify → Report

The whole loop, once. Every stage after Prioritize is the part most tools leave to you, and the last two are why a finding here closes on evidence rather than on somebody saying so.

01

DISCOVER

Find what is actually there, through whichever collection the environment allows.

  • External attack surface
  • Internal network
  • Endpoints
  • Active Directory identity
02

CORRELATE

Join asset to vulnerability, vulnerability to exploitability, exposure to the business context around it.

  • Exposure graph
  • Attack paths
  • Threat intelligence
  • Network telemetry
03

PRIORITIZE

Thousands of findings become the handful of changes worth doing first, with the reasons attached.

  • Ranked by attack paths removed, not by CVSS
  • Every point attributable to a named factor
04

ASSIGN

The work lands in the PSA your technicians already live in.

  • HaloPSA, ConnectWise, Autotask, Jira, ServiceNow — beta
  • Re-running a recommendation updates the ticket rather than opening a second
05

REMEDIATE

Approved actions run through your RMM.

  • Named actions from a fixed catalogue — never a script we wrote
  • You choose how much runs without a person approving it
06

VERIFY

The service is re-checked and the exposure graph recalculated.

  • The RMM reporting success is not evidence; the re-check is
  • What could not be checked is reported as unverified, never as fixed
07

REPORT

Which vulnerabilities and attack paths actually disappeared.

  • Measured against a baseline taken before the work started
  • A partial result stays partial — the endpoint that failed keeps its ticket open

How verification works What we scan, and how

What it draws on

Prioritization is only as good as what it knows

380,000+

Vulnerability records held, from NVD, GitHub, CISA KEV, ExploitDB and OSV. One record is one vulnerability identifier this platform has synchronized. Last synchronized 08 Sep 2026 22:20 UTC.

CISA KEV

Known exploited vulnerabilities flagged and weighted, not just listed.

EPSS

Exploit prediction scores from FIRST.org, used as one factor among many.

21 identity checks

Read-only Active Directory posture checks, from delegation to certificate templates.

See Exploit Hound in action

Five stages, five real screens

sniff.exploithound.com/assetsDemonstration data · v2.75.0
Exploit Hound discover step: External surface, internal networks and endpoints in one inventory, each carrying the context prioritization depends on.

External surface, internal networks and endpoints in one inventory, each carrying the context prioritization depends on. 1Authorization state2Scope3Environment

Real interface, demonstration environment. See the walkthrough →

Fix First

Stop treating every vulnerability equally.

Exploit Hound groups findings into the actions a person actually performs, then ranks those actions by what each one removes — attack paths, critical systems exposed, findings closed. Every ranking states its reasons.

96/100
Fix now
#1 RECOMMENDED ACTION

Patch the edge firewall

Internet-facing · affects 4 systems

17
Paths removed
3
Critical systems protected
12
Findings resolved

Why this is first

Internet exposed CISA KEV EPSS 97% Public exploit available Observed probing
#2
Disable SMBv1 on FILESERVER01
11 paths removed · 2 critical systems protected
89
#3
Remove excess local administrators
8 paths removed · lateral movement enabler
84
#4
Close exposed RDP on the perimeter
6 paths removed
71

Illustrative example. These are not customer results. Your numbers are calculated from your own exposure graph — path counts are exact over the current graph, and anything estimated is labeled as an estimate. How prioritization works →

Explainable risk

Not a black box.

Every Exploit Hound risk score is the sum of named factors. You can show a customer why a finding ranked where it did, and the methodology version is stored with the score, so a change to the model does not silently reinterpret last quarter's numbers.

Exploit Hound risk
96/100
Fix now
methodology v1.0

Why 96?

Internet exposure
Reachable from the public Internet
+20
CISA KEV listed
Known exploited in the wild
+20
EPSS 97.8%
Exploit prediction score from FIRST.org
+18
Public exploit available
Working exploit code published
+15
Observed probing
Honeypot activity against this service
+12
Critical production asset
Business criticality set by your team
+11
Total
96

Factors that can contribute, depending on the evidence available:

CVSSEPSS CISA KEVExploit availability Internet exposureAsset criticality Attack pathsActive Directory privilege Network activityHoneypot activity Threat intelligenceSafe validation

Illustrative example. Real scores are computed from your own evidence; a finding with no observed activity and no public exploit simply does not receive those points. How scoring works →

From findings to attack paths

A severe vulnerability does not always equal severe business risk.

Every hop is backed by evidence, and the language is deliberate: a route inferred from graph analysis is called potential, not exploited.

reachableexposesobserved trafficSMBdelegation INTERNETEntry pointvpn.example.comAsset · risk 96CVE-2026-21882Vulnerability · KEVjump01.example.comAssetfs01.example.comAssetbackup01.example.comCritical asset

The path in words: the Internet reaches vpn.example.com, which exposes CVE-2026-21882 (known exploited). Observed traffic connects it to jump01.example.com, which reaches fs01.example.com over SMB and, through unconstrained delegation, the critical asset backup01.example.com.

Entry point Asset Vulnerability Identity Critical asset
○ Potential ◉ Observed ✓ Safely validated

Why this connection exists

Select a node

Choose any node in the diagram — by click or keyboard — to see the evidence behind that step, where it came from, and how confident the platform is.

This path in words
  1. The Internet can reach vpn.example.com on TCP/443.
  2. That host is affected by CVE-2026-21882, which is on CISA KEV with a public exploit.
  3. NetFlow shows traffic from it to jump01.example.com.
  4. From there, an SMB session reaches fs01.example.com.
  5. Active Directory shows backup01.example.com — a critical asset — is trusted for unconstrained delegation.

Illustrative example using documentation hostnames. Real paths are computed from your own exposure graph and labeled potential, observed or validated according to the evidence behind them. How attack path analysis works →

Identity is part of your attack surface

Attackers don't stop at software vulnerabilities.

Identity and privilege relationships are edges in the same graph as everything else, which is what makes the route below findable.

The Active Directory assessment is read-only and requires explicit written authorization before it runs. It never cracks passwords, never reads password hashes, and never writes to your directory.

View Product Tour

Why identity belongs in the graph

  • Compromised workstation
    communicates with
  • Application server
    trusted for unconstrained delegation
  • Domain controller

A delegation misconfiguration is not a separate report — it is an edge in the same graph, so attack path analysis finds routes like this one without anyone writing them down.

Find. Fix. Prove.

A finding is not closed because someone said so.

Verification is read-only and its target comes from the finding’s own asset record, so it cannot be pointed somewhere else. What that produces is a before and an after that somebody can hand to a customer.

Before

  • Vulnerable version observed on the host
  • Internet-reachable on TCP/443
  • One potential attack path to a critical system

After verification

  • Patched version observed by the same check
  • Service no longer offering the affected version
  • Path retired from the graph, not deleted from history

Illustrative example. Risk accepted, false positive and reopened are states too — nothing quietly disappears. Retired paths are kept rather than removed, so you can show what an action eliminated and when. The full finding lifecycle →

Built for MSPs

See risk across every customer from one console.

Identify which organizations need immediate attention, prioritize the exposures that matter most, track remediation SLAs and deliver reports that demonstrate measurable security improvement.

Ranked by attention

Immediate attention, critical, high, moderate, healthy — sorted so triage takes seconds.

Absolute isolation

Customer data never crosses a tenant boundary — enforced in the data model, not just the UI.

Operational health

Agent health, scan health, SLA violations and overdue remediation on the same screen.

Evidence for reviews

Show what changed, what was fixed, and what was verified since the last conversation.

See Exploit Hound for MSPs

sniff.exploithound.com/mspDemonstration data · v2.75.0
Exploit Hound multi-customer console: four customers ranked by attention needed, with exposure score, critical findings, known exploited vulnerabilities, paths to critical systems, agent health and overdue remediation for each

Real interface, demonstration environment with invented customer names. See Exploit Hound for MSPs → 1Customers needing attention2Why each one needs it

Start with what's actually exposed.

Point Exploit Hound at the assets you are authorized to assess and see the connected picture — not another list.

v2.75.0 Exploit Hound 2.75.0 · Continuous Threat Exposure Management