Capability
Exposure management vs vulnerability scanning
Scanning answers what is weak. Exposure management asks which weaknesses matter together, what to fix first, and whether the fix held.
Who this is for
MSPs deciding whether a scanner is enough
You already produce vulnerability reports and want to know what exposure management would add to them.
IT teams evaluating CTEM
You have read about continuous threat exposure management and want to see what it means for the work itself.
The problem it addresses
A vulnerability scanner produces a list: each finding judged on its own and ranked by severity. That list is a necessary input and an incomplete answer. It does not say which findings are reachable, which combine with an account or a misconfiguration into a route, or whether a fix made last month is still in place.
How Exploit Hound handles it
- 1Scanning is an input, not the output
Exploit Hound runs its own discovery and vulnerability checks, and the results go into one exposure graph per customer alongside identity, network telemetry and asset context.
- 2Exposure is judged in combination
Related findings become routes, and the changes that break the most routes are named. A route is labelled potential, observed or validated according to the evidence behind it.
- 3Work is ranked by exposure removed
Fix First ranks actions by how much exposure each removes, not by the severity of the worst finding they touch.
- 4The result is re-checked
Validation closes the loop: after a change, the exposure is re-checked and the graph rebuilt, so the report says what actually went away.
What the result rests on
- Discovery and vulnerability check results, each with its stored artefact
- Reachability, asset criticality and identity relationships as edges in the graph
- Evidence strength on every finding: detected, high confidence or safely validated
- Re-check results after remediation
The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.
What is generally available, and what is Beta
Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.
| Capability | Status | Notes |
|---|---|---|
| Exposure graph | Generally Available | |
| Attack paths and choke points | Generally Available | |
| External attack surface discovery | Generally Available | |
| Internal network discovery | Generally Available | |
| Remediation verified by re-checking | Generally Available | |
| Tool disagreement reconciliation | Beta | Beta — built 10 September 2026. Compares discovered assets, endpoint agents, connected tool inventory and independent verification, and reports where they contradict each other. |
| Active Directory exposure | Beta | Beta — no live directory assessed |
| Cloud posture (Azure, AWS, Google Cloud) | Beta | Beta ×3 — never run against a live account |
Questions MSPs ask about this
Do I still need a vulnerability scanner?
Exploit Hound includes its own discovery and vulnerability checks, so it does not need another scanner’s output to work, and it does not import one. Whether to keep yours is a coverage question best answered on one customer: the pilot guide describes the comparison.
What does CTEM mean?
Continuous threat exposure management: a cycle of scoping, discovering, prioritizing, validating and mobilizing remediation, repeated rather than run as a one-off assessment. Exploit Hound’s four stages — discover, prioritize, act, verify — follow that cycle.
Is exposure management only for large security teams?
Exploit Hound is built for MSPs and for IT teams without a security team: the output is a ranked list of actions a technician performs, with the reasons attached, not an analysis to interpret.
In the console
See it against your own estate
A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.
Request a guided evaluation Pricing Trust Center Integration status Product tour