Capability
Attack path management
Individual findings become routes. The route, not the finding, is what decides which fix matters first.
Who this is for
MSP security operations
You manage exposure across many customers and have to justify which change gets a technician's hour this week.
Internal IT with no security team
You have a scanner's output and no way to tell which twenty of its four hundred findings actually chain into something.
The problem it addresses
A vulnerability list ranks findings against each other in isolation. It cannot tell you that an unpatched service is reachable from the internet, that the account running it is a local administrator, and that the same credential exists on the file server. Those three facts are each ordinary. Together they are a route, and a route is what an attacker uses.
How Exploit Hound handles it
- 1Findings become nodes and edges
Assets, accounts, services, credentials and network reachability are correlated into one graph rather than kept in separate tables. An exposure is a node; the thing that makes it reachable is an edge.
- 2Routes are labelled by the evidence behind them
A path is potential unless something stronger supports it. Graph analysis alone never earns the word exploited, and observed probing against a service is reported as observed probing.
- 3Choke points are ranked
Where one change removes several routes, that change is named and the number of routes it removes is stated. That number is recalculated from the rebuilt graph after the work, not asserted in advance.
What the result rests on
- Scan results with the stored artefact behind them: a probe result, a banner, a negotiated protocol
- Internet reachability and exposure category for each asset
- Account and group membership read from the directory, read-only
- Passive network telemetry and DNS, correlated back to the host involved
- Each hop cites what it is based on, so a path can be argued with rather than taken on trust
The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.
What is generally available, and what is Beta
Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.
| Capability | Status | Notes |
|---|---|---|
| Attack paths and choke points | Generally Available | |
| Exposure graph | Generally Available | |
| External attack surface discovery | Generally Available | |
| Internal network discovery | Generally Available | |
| Active Directory exposure | Beta | Beta — no live directory assessed |
| Entra ID / Microsoft 365 exposure | Beta | Beta — Graph payload mapping unproven |
| Cloud posture (Azure, AWS, Google Cloud) | Beta | Beta ×3 — never run against a live account |
In the console
See it against your own estate
A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.
Request a guided evaluation Pricing Trust Center Integration status Product tour