Capability

Fix First prioritization

Actions ranked by how much exposure they remove, with the prediction checked against what happened.

Who this is for

MSPs billing technician hours

You need a defensible answer to why this fix and not that one, for a customer who did not choose the tool.

Security teams that have to justify ranking

You need the ranking to survive being questioned by somebody who disagrees with it.

The problem it addresses

Ranking by CVSS sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today. Ranking by count sends them to whichever product is noisiest. Neither answers the question an operator actually has, which is which single change removes the most exposure from this estate this week.

How Exploit Hound handles it

  • 1
    Actions are ranked on evidence, not on one number

    The unit is an action a technician can take, not a finding. The order comes from exploit activity, reachability, asset importance, evidence quality and the exposures each action could address. The number of routes an action could close counts, and counts sub-linearly: nine potential routes to an unimportant host do not outweigh a known-exploited vulnerability reachable from the Internet on a critical one.

  • 2
    Every point in the score is named

    The risk score is a sum of labelled factors, not a model output. A finding carries the factor list and the scoring version used, so a score can still be explained after the methodology changes.

  • 3
    The prediction is measured

    After the work, the graph is rebuilt and the routes are counted again. Where other remediation was in flight at the same time, the paths are reported gone without attributing which change removed them.

What the result rests on

  • CVSS base severity where available, otherwise scanner severity
  • EPSS exploit prediction from FIRST.org, as one factor among many
  • CISA KEV listing, weighted rather than merely flagged
  • Internet reachability, asset criticality and role
  • How many attack paths the finding participates in
  • Recorded risk acceptance and compensating controls, which reduce the score

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
Fix First remediation rankingGenerally Available
Fix First prediction accuracyGenerally AvailableMeasures predictions somebody acted on, after the exposure graph is rebuilt. Where other remediation was in flight at the same time the paths are reported gone without attributing which change removed them, and no financial value is estimated.
Explainable, versioned risk scoringGenerally Available
Vulnerability intelligence (CVE, EPSS, KEV, exploit availability)Generally Available
PSA / ITSM ticketingBetaBeta ×5 — HaloPSA, ConnectWise, Autotask, Jira, ServiceNow
RMM remediation orchestrationBetaBeta ×4 — NinjaOne, Datto, Syncro, N-able

Questions MSPs ask about this

How is Fix First different from sorting by CVSS?

The unit is an action a technician performs, not a finding, and the order comes from exploit activity, reachability, asset importance, evidence quality and the exposures the action could address. CVSS is one input among those.

Can I see why an action is ranked where it is?

Yes. Every recommendation lists the findings it covers and the named factors behind its position, and the risk score is a sum of labelled factors with the scoring version recorded on the finding.

Does Fix First check whether its predictions were right?

Yes. After the work, the graph is rebuilt and the routes are counted again. Where other remediation was in flight at the same time, the routes are reported gone without attributing which change removed them.

In the console

sniff.exploithound.com/fix-firstDemonstration data · v2.80.8
Fix First ranking in the Exploit Hound console: actions ordered by the exposure each one removes, with the contributing factors listed

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.80.8 Exploit Hound 2.80.8 · Continuous Threat Exposure Management