Capability

Exposure management vs vulnerability scanning

Scanning answers what is weak. Exposure management asks which weaknesses matter together, what to fix first, and whether the fix held.

Who this is for

MSPs deciding whether a scanner is enough

You already produce vulnerability reports and want to know what exposure management would add to them.

IT teams evaluating CTEM

You have read about continuous threat exposure management and want to see what it means for the work itself.

The problem it addresses

A vulnerability scanner produces a list: each finding judged on its own and ranked by severity. That list is a necessary input and an incomplete answer. It does not say which findings are reachable, which combine with an account or a misconfiguration into a route, or whether a fix made last month is still in place.

How Exploit Hound handles it

  • 1
    Scanning is an input, not the output

    Exploit Hound runs its own discovery and vulnerability checks, and the results go into one exposure graph per customer alongside identity, network telemetry and asset context.

  • 2
    Exposure is judged in combination

    Related findings become routes, and the changes that break the most routes are named. A route is labelled potential, observed or validated according to the evidence behind it.

  • 3
    Work is ranked by exposure removed

    Fix First ranks actions by how much exposure each removes, not by the severity of the worst finding they touch.

  • 4
    The result is re-checked

    Validation closes the loop: after a change, the exposure is re-checked and the graph rebuilt, so the report says what actually went away.

What the result rests on

  • Discovery and vulnerability check results, each with its stored artefact
  • Reachability, asset criticality and identity relationships as edges in the graph
  • Evidence strength on every finding: detected, high confidence or safely validated
  • Re-check results after remediation

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
Exposure graphGenerally Available
Attack paths and choke pointsGenerally Available
External attack surface discoveryGenerally Available
Internal network discoveryGenerally Available
Remediation verified by re-checkingGenerally Available
Tool disagreement reconciliationBetaBeta — built 10 September 2026. Compares discovered assets, endpoint agents, connected tool inventory and independent verification, and reports where they contradict each other.
Active Directory exposureBetaBeta — no live directory assessed
Cloud posture (Azure, AWS, Google Cloud)BetaBeta ×3 — never run against a live account

Questions MSPs ask about this

Do I still need a vulnerability scanner?

Exploit Hound includes its own discovery and vulnerability checks, so it does not need another scanner’s output to work, and it does not import one. Whether to keep yours is a coverage question best answered on one customer: the pilot guide describes the comparison.

What does CTEM mean?

Continuous threat exposure management: a cycle of scoping, discovering, prioritizing, validating and mobilizing remediation, repeated rather than run as a one-off assessment. Exploit Hound’s four stages — discover, prioritize, act, verify — follow that cycle.

Is exposure management only for large security teams?

Exploit Hound is built for MSPs and for IT teams without a security team: the output is a ranked list of actions a technician performs, with the reasons attached, not an analysis to interpret.

In the console

sniff.exploithound.com/exposureDemonstration data · v2.80.8
The Exploit Hound exposure graph: vulnerabilities, configuration, identity and network telemetry stored as one evidence-backed graph per customer

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.80.8 Exploit Hound 2.80.8 · Continuous Threat Exposure Management