Capability

Fix First prioritization

Actions ranked by how much exposure they remove, with the prediction checked against what happened.

Who this is for

MSPs billing technician hours

You need a defensible answer to why this fix and not that one, for a customer who did not choose the tool.

Security teams that have to justify ranking

You need the ranking to survive being questioned by somebody who disagrees with it.

The problem it addresses

Ranking by CVSS sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today. Ranking by count sends them to whichever product is noisiest. Neither answers the question an operator actually has, which is which single change removes the most exposure from this estate this week.

How Exploit Hound handles it

  • 1
    Actions are ranked by exposure removed

    The unit is an action a technician can take, not a finding. An action that closes one route ranks below an action that closes nine, whatever their severities say.

  • 2
    Every point in the score is named

    The risk score is a sum of labelled factors, not a model output. A finding carries the factor list and the scoring version used, so a score can still be explained after the methodology changes.

  • 3
    The prediction is measured

    After the work, the graph is rebuilt and the routes are counted again. Where other remediation was in flight at the same time, the paths are reported gone without attributing which change removed them.

What the result rests on

  • CVSS base severity where available, otherwise scanner severity
  • EPSS exploit prediction from FIRST.org, as one factor among many
  • CISA KEV listing, weighted rather than merely flagged
  • Internet reachability, asset criticality and role
  • How many attack paths the finding participates in
  • Recorded risk acceptance and compensating controls, which reduce the score

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
Fix First remediation rankingGenerally Available
Fix First prediction accuracyGenerally AvailableMeasures predictions somebody acted on, after the exposure graph is rebuilt. Where other remediation was in flight at the same time the paths are reported gone without attributing which change removed them, and no financial value is estimated.
Explainable, versioned risk scoringGenerally Available
Vulnerability intelligence (CVE, EPSS, KEV, exploit availability)Generally Available
PSA / ITSM ticketingBetaBeta ×5 — HaloPSA, ConnectWise, Autotask, Jira, ServiceNow
RMM remediation orchestrationBetaBeta ×4 — NinjaOne, Datto, Syncro, N-able

In the console

sniff.exploithound.com/fix-firstDemonstration data · v2.58.16
Fix First ranking in the Exploit Hound console: actions ordered by the exposure each one removes, with the contributing factors listed

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.58.16 Exploit Hound 2.58.16 · Continuous Threat Exposure Management