Capability
Identity exposure management
Directory posture read only, and correlated with the network rather than reported beside it.
Who this is for
MSPs managing customer directories
You run identity for many organizations and have no consistent read of how exposed each one is.
Internal IT after an audit finding
You have been asked about delegation, stale privilege and certificate templates and have no current answer.
The problem it addresses
Identity findings are usually produced by a separate tool and read on their own. An over-privileged service account is a moderate finding in isolation; the same account running an internet-reachable service is the first hop of a route. Nothing joins the two when identity lives in its own report.
How Exploit Hound handles it
- 1Read-only, and gated behind written authorization
Assessment is read-only LDAP, read-only Microsoft Graph and the read-only Google Admin SDK. Assets must be marked authorized before anything is assessed.
- 2Access is made as an administrator you nominate
For Google Workspace, every read is made through domain-wide delegation you add and revoke in your own Admin console, and appears in your audit log under that name.
- 3Unassessed is reported as unassessed
Where a scope needed to read an area is not granted, the area is reported as unassessed rather than as clean.
- 4Identity joins the same graph
Accounts, groups and privilege become nodes and edges alongside assets and services, so an identity weakness is visible as part of a route rather than as a separate list.
What the result rests on
- 21 read-only Active Directory posture checks, from delegation to certificate templates
- Microsoft Graph reads for Entra ID and Microsoft 365 exposure
- Google Admin SDK reads for Workspace, with third-party application grants optional and reported as unassessed when not granted
- Group membership and privilege relationships as edges in the exposure graph
The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.
What is generally available, and what is Beta
Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.
| Capability | Status | Notes |
|---|---|---|
| Exposure graph | Generally Available | |
| Attack paths and choke points | Generally Available | |
| Active Directory exposure | Beta | Beta — no live directory assessed |
| Entra ID / Microsoft 365 exposure | Beta | Beta — Graph payload mapping unproven |
| Google Workspace exposure | Beta | Beta — built 18 August 2026 |
| Single sign-on (OpenID Connect) | Beta | OpenID Connect authorization code flow with PKCE. SAML and SCIM provisioning are not implemented. An email address is unique across a deployment, so one address cannot hold accounts in two tenants. |
In the console
See it against your own estate
A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.
Request a guided evaluation Pricing Trust Center Integration status Product tour