Capability
Fix First prioritization
Actions ranked by how much exposure they remove, with the prediction checked against what happened.
Who this is for
MSPs billing technician hours
You need a defensible answer to why this fix and not that one, for a customer who did not choose the tool.
Security teams that have to justify ranking
You need the ranking to survive being questioned by somebody who disagrees with it.
The problem it addresses
Ranking by CVSS sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today. Ranking by count sends them to whichever product is noisiest. Neither answers the question an operator actually has, which is which single change removes the most exposure from this estate this week.
How Exploit Hound handles it
- 1Actions are ranked on evidence, not on one number
The unit is an action a technician can take, not a finding. The order comes from exploit activity, reachability, asset importance, evidence quality and the exposures each action could address. The number of routes an action could close counts, and counts sub-linearly: nine potential routes to an unimportant host do not outweigh a known-exploited vulnerability reachable from the Internet on a critical one.
- 2Every point in the score is named
The risk score is a sum of labelled factors, not a model output. A finding carries the factor list and the scoring version used, so a score can still be explained after the methodology changes.
- 3The prediction is measured
After the work, the graph is rebuilt and the routes are counted again. Where other remediation was in flight at the same time, the paths are reported gone without attributing which change removed them.
What the result rests on
- CVSS base severity where available, otherwise scanner severity
- EPSS exploit prediction from FIRST.org, as one factor among many
- CISA KEV listing, weighted rather than merely flagged
- Internet reachability, asset criticality and role
- How many attack paths the finding participates in
- Recorded risk acceptance and compensating controls, which reduce the score
The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.
What is generally available, and what is Beta
Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.
| Capability | Status | Notes |
|---|---|---|
| Fix First remediation ranking | Generally Available | |
| Fix First prediction accuracy | Generally Available | Measures predictions somebody acted on, after the exposure graph is rebuilt. Where other remediation was in flight at the same time the paths are reported gone without attributing which change removed them, and no financial value is estimated. |
| Explainable, versioned risk scoring | Generally Available | |
| Vulnerability intelligence (CVE, EPSS, KEV, exploit availability) | Generally Available | |
| PSA / ITSM ticketing | Beta | Beta ×5 — HaloPSA, ConnectWise, Autotask, Jira, ServiceNow |
| RMM remediation orchestration | Beta | Beta ×4 — NinjaOne, Datto, Syncro, N-able |
Questions MSPs ask about this
How is Fix First different from sorting by CVSS?
The unit is an action a technician performs, not a finding, and the order comes from exploit activity, reachability, asset importance, evidence quality and the exposures the action could address. CVSS is one input among those.
Can I see why an action is ranked where it is?
Yes. Every recommendation lists the findings it covers and the named factors behind its position, and the risk score is a sum of labelled factors with the scoring version recorded on the finding.
Does Fix First check whether its predictions were right?
Yes. After the work, the graph is rebuilt and the routes are counted again. Where other remediation was in flight at the same time, the routes are reported gone without attributing which change removed them.
In the console
See it against your own estate
A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.
Request a guided evaluation Pricing Trust Center Integration status Product tour