Interactive demo

Try the triage.

Three findings from an invented estate. Pick one and see why it scores what it scores — every point attributable to a named factor, which is the whole argument for ranking this way.

Synthetic data. Every host and advisory below is invented. Hostnames use example.com, reserved for documentation, and the advisory identifiers are deliberately not real CVE numbers. This page runs entirely in your browser, talks to no system, and changes nothing. It is not a live console and no customer data appears in it.

Ranked by what the score says

Not by CVSS. The kernel bug below is the more severe vulnerability and ranks last, because nothing can reach it.

Finding detail — demonstration

What this is showing

The score is a sum, not a verdict

Base severity, exploitation likelihood, exposure, business context, connectivity and evidence strength. You can argue with a number when you can see what built it.

Reachability changes everything

The same vulnerability on an isolated build runner and on an Internet-facing appliance are not the same problem, and a list sorted by CVSS cannot tell you that.

Evidence is graded

Detected, high confidence and safely validated are different claims. The console says which one it is holding, on every finding.

See it on your own estate Annotated tour of the real console

v2.6.0 Exploit Hound 2.6.0 · Continuous Threat Exposure Management