Capability

Attack path management

Individual findings become routes. The route, not the finding, is what decides which fix matters first.

Who this is for

MSP security operations

You manage exposure across many customers and have to justify which change gets a technician's hour this week.

Internal IT with no security team

You have a scanner's output and no way to tell which twenty of its four hundred findings actually chain into something.

The problem it addresses

A vulnerability list ranks findings against each other in isolation. It cannot tell you that an unpatched service is reachable from the internet, that the account running it is a local administrator, and that the same credential exists on the file server. Those three facts are each ordinary. Together they are a route, and a route is what an attacker uses.

How Exploit Hound handles it

  • 1
    Findings become nodes and edges

    Assets, accounts, services, credentials and network reachability are correlated into one graph rather than kept in separate tables. An exposure is a node; the thing that makes it reachable is an edge.

  • 2
    Routes are labelled by the evidence behind them

    A path is potential unless something stronger supports it. Graph analysis alone never earns the word exploited, and observed probing against a service is reported as observed probing.

  • 3
    Choke points are ranked

    Where one change removes several routes, that change is named and the number of routes it removes is stated. That number is recalculated from the rebuilt graph after the work, not asserted in advance.

What the result rests on

  • Scan results with the stored artefact behind them: a probe result, a banner, a negotiated protocol
  • Internet reachability and exposure category for each asset
  • Account and group membership read from the directory, read-only
  • Passive network telemetry and DNS, correlated back to the host involved
  • Each hop cites what it is based on, so a path can be argued with rather than taken on trust

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
Attack paths and choke pointsGenerally Available
Exposure graphGenerally Available
External attack surface discoveryGenerally Available
Internal network discoveryGenerally Available
Active Directory exposureBetaBeta — no live directory assessed
Entra ID / Microsoft 365 exposureBetaBeta — Graph payload mapping unproven
Cloud posture (Azure, AWS, Google Cloud)BetaBeta ×3 — never run against a live account

In the console

sniff.exploithound.com/attack-pathsDemonstration data · v2.58.16
Attack paths in the Exploit Hound console: routes through related exposures, each labelled with the confidence its evidence supports

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.58.16 Exploit Hound 2.58.16 · Continuous Threat Exposure Management