Integrations

What connects, and how far along it is.

Every integration below carries a status, and each status means something specific.

Generally available

6 capabilities are generally available. Validated end to end in a live deployment and approved for production use. They are the platform’s own work and need no third-party account to function.

Deception / honeypots

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
None recorded.
Last validated
Not recorded.
Validation record and technical detail
Validation
First-party: exercised end to end in this platform's own running deployment. No vendor tenant applies.

Fix First prediction accuracy

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
Measures predictions somebody acted on, after the exposure graph is rebuilt. Where other remediation was in flight at the same time the paths are reported gone without attributing which change removed them, and no financial value is estimated.
Last validated
Not recorded.
Validation record and technical detail
Validation
First-party: exercised end to end in this platform's own running deployment. No vendor tenant applies.

Fix First remediation ranking

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
None recorded.
Last validated
Not recorded.
Validation record and technical detail
Validation
First-party: exercised end to end in this platform's own running deployment. No vendor tenant applies.

Passive network telemetry

NetFlow

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
None recorded.
Last validated
Not recorded.
Validation record and technical detail
Validation
First-party: exercised end to end in this platform's own running deployment. No vendor tenant applies.

Remediation verified by re-checking

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
None recorded.
Last validated
Not recorded.
Validation record and technical detail
Validation
First-party: exercised end to end in this platform's own running deployment. No vendor tenant applies.

Verification worklist

Six states between a claim and a check, with bounded retries. Exercised against this deployment's own data; no customer has worked a queue from it.

Availability
Generally available.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
Six states between "somebody says it is fixed" and "a check says so". A check that could not tell carries its own reason, and retries are bounded at three before the finding needs a person. A finding closed by a rescan is labelled as closed by a rescan rather than as a targeted re-check.
Last validated
Not recorded.
Validation record and technical detail
Validation
Validated against a live system we own. No customer environment has been involved.

Exists because a verification check that timed out used to return "gone" and move the finding to VERIFIED. Silence is now undetermined and changes nothing; a refused connection is an answer and still closes. Kept at Beta deliberately: three comparable first-party features built on 10 September are Beta, and a feature four days old that nobody outside this deployment has used is not more proven than they are. The only difference was who wrote the row.

Beta — available for guided evaluation

Production validation is still in progress for these, for one of two reasons. Every third-party integration is Beta. Third-party integrations marked Beta are implemented and tested but have not yet completed validation against a live vendor tenant. They are not represented as generally available until that validation is complete and the result is approved.

A first-party capability here is Beta for a different reason: it is built and exercised in this platform’s own running deployment, and nobody outside it has used it yet. There is no vendor tenant to validate against — what is missing is a customer’s month, not somebody else’s API. Each card says which of the two applies.

Active Directory exposure

Beta — no live directory assessed

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
A read-only directory account and written authorization.
Limitations
None recorded.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Change bundle preview

Beta — built 12 September 2026. Set-union estimates for several selected actions. Exercised against this deployment's own graph; no customer has planned a maintenance window from it.

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Supported platforms
Runs in the hosted platform. Nothing to install.
Needs
None. Available as soon as you sign in.
Limitations
Estimates what several proposed actions cover together over the current graph. Every total is a set union, so two actions removing the same modeled path are counted once and the preview states what adding their figures would have given. It executes nothing, and an action on an asset with no graph relationships is excluded from the path figures rather than counted as zero.
Validation record and technical detail
Validation
Validated against a live system we own. No customer environment has been involved.

Capped at twelve actions: a maintenance window rather than a plan for the estate. The request carries which actions; what they are worth is recomputed from the engine. Kept at Beta deliberately: three comparable first-party features built on 10 September are Beta, and a feature four days old that nobody outside this deployment has used is not more proven than they are. The only difference was who wrote the row.

Cloud posture (Azure, AWS, Google Cloud)

Beta ×3 — never run against a live account

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Varies by provider. Each is listed with its own.
Limitations
Posture and identity relationships. No container, Kubernetes or DSPM coverage.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

DNS mail authentication

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
The domain's DNS must be hosted by this platform.
Limitations
Only for domains whose DNS this platform hosts. Records can be added, amended and removed; the panel queues each change for an operator to approve rather than applying it immediately, and a submitted change cannot be withdrawn through the API. DKIM keys are never generated: the key must come from the mail server that signs the mail.
Validation record and technical detail
Validation
Validated against a live system we own. No customer environment has been involved.
Last validated
2026-09-10

Validated against the live control panel on 8 September 2026 and again on 10 September when record removal and amendment were added: the key was accepted, 14 zones listed, exploithound.com read, SPF, DKIM and DMARC confirmed to resolve in public DNS, and the DMARC policy moved from p=none to p=quarantine through the change-set endpoint. The panel is one we operate, so this is validation against our own system rather than a customer's.

Email delivery

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
An SMTP server you provide.
Limitations
Outbound only. Needs an SMTP server you provide. The one confirmed delivery was to a mailbox belonging to the operator, not to a customer.
Validation record and technical detail
Validation
Validated against a live system we own. No customer environment has been involved.
Last validated
2026-09-09

A message has been delivered to a real mailbox through a configured SMTP server and confirmed to have arrived in the inbox by the recipient. The mailbox belongs to the operator, not to a customer.

Entra ID / Microsoft 365 exposure

Beta — Graph payload mapping unproven

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Varies by provider. Each is listed with its own.
Limitations
None recorded.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Google Workspace exposure

Beta — built 18 August 2026

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Domain-wide delegation you add and revoke in your own Admin console.
Limitations
Third-party OAuth grants need a scope Google publishes no read-only form of; declined by default and reported unassessed.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

OS client deployment through your RMM, Intune or Jamf

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Supported platforms
Commands and packages for Linux, Windows and macOS — see agent platform support.
Needs
An RMM, Intune or Jamf tenant of your own to run the generated command or package.
Limitations
Exploit Hound generates the command or package; it does not push anything. Deployment progress is counted from clients checking in, never from what the deployment tool reported about itself. The token is scoped to one deployment with a use limit and an expiry of at most 30 days. A macOS build exists and has never been observed running in a live deployment. No deployment has been run through a real RMM, Intune or Jamf tenant.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

PSA / ITSM ticketing

Beta ×5 — HaloPSA, ConnectWise, Autotask, Jira, ServiceNow

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Varies by provider. Each is listed with its own.
Limitations
Ticket create, update and dedup. Close depends on the provider's own capability.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Pushover delivery

Beta — implemented and tested; no account holds Pushover credentials and no notification has been delivered to a real device

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
A Pushover user key and API token.
Limitations
Outbound only. Needs a Pushover user key and API token per account; none is set.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

RMM remediation orchestration

Beta ×4 — NinjaOne, Datto, Syncro, N-able

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Varies by provider. Each is listed with its own.
Limitations
Named actions from a fixed catalogue only. Never arbitrary script text.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Slack and Teams notifications

Beta — never sent to a live workspace

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
Varies by provider. Each is listed with its own.
Limitations
None recorded.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Syslog export to a SIEM

Beta — RFC 5424 and CEF; never validated against a customer SIEM

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
A syslog collector reachable from the platform.
Limitations
One-way delivery to syslog ports only. Link-local, loopback and multicast refused.
Validation record and technical detail
Validation
Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

Webhook delivery

Beta — signed and retried, and a signed event has now been delivered to a real endpoint over the public internet and verified against the shared secret at the receiver. The receiver is our own infrastructure and no customer endpoint has received an event, so this is validated rather than proven in production

Availability
Beta — available for guided evaluation. Production validation is still in progress.
Needs
An HTTPS endpoint and a signing secret.
Limitations
Outbound only. Every attempt is recorded in webhook_deliveries. The one delivery on record went to a receiver this platform hosts.
Validation record and technical detail
Validation
Validated against a live system we own. No customer environment has been involved.
Last validated
2026-09-08

Not Built

Not implemented and not represented as available. Listed here because each one is a reasonable thing to ask about.

ConnectWise RMM

blocked on published API documentation

Availability
Not built, and not available.

Container and Kubernetes security (CNAPP)

Availability
Not built, and not available.

Native patching

Availability
Not built, and not available.

What the statuses mean

Generally Available

Validated end to end in a live deployment and approved for production use.

Production Validation

Live validation has been completed, with final approval still pending.

Beta

Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

Not Built

Not implemented and not represented as available.

General availability requires successful validation against a live provider environment, documented evidence and operator approval.

Every status on this page is read from one shared registry, which is also what the comparison page renders from, so the two cannot disagree.

PSA — where the work gets tracked

A Fix First recommendation becomes a ticket in the system your technicians already work in. Re-running the recommendation updates that ticket rather than opening a second one.

IntegrationStatusNotes
HaloPSABeta

Raise and update tickets for remediation work in HaloPSA.

BetaNeeds: A HaloPSA instance and an API application you create.

Limitation: Status and priority ids are per-instance and must be set on first connection.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live HaloPSA tenant has been connected.

Supported operations

  • Create ticket
  • Update ticket
  • Close ticket
  • Map status and priority
ConnectWise ManageBeta

Raise and update tickets for remediation work in ConnectWise Manage.

BetaNeeds: A ConnectWise Manage instance and API member keys.

Limitation: Status and priority ids are per-instance and must be set on first connection.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live ConnectWise Manage tenant has been connected.

Supported operations

  • Create ticket
  • Update ticket
  • Close ticket
  • Map status and priority
Datto AutotaskBeta

Raise and update tickets for remediation work in Datto Autotask.

BetaNeeds: A Datto Autotask instance and an API user.

Limitation: Priority and status ids are numeric and per-instance; they must be set on first connection.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live Autotask tenant has been connected.

Supported operations

  • Create ticket
  • Update ticket
  • Close ticket
  • Map status and priority
JiraBeta

Raise and update tickets for remediation work in Jira.

BetaNeeds: A Jira project and an API token.

Limitation: Issue types and transitions are per-project and must be mapped on first connection.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live Jira site has been connected.

Supported operations

  • Create ticket
  • Update ticket
  • Close ticket
  • Map status and priority
ServiceNowBeta

Raise and update tickets for remediation work in ServiceNow.

BetaNeeds: A ServiceNow instance and an integration user.

Limitation: Table and state values are per-instance and must be mapped on first connection.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live ServiceNow instance has been connected.

Supported operations

  • Create ticket
  • Update ticket
  • Close ticket
  • Map status and priority

All five are built on one provider abstraction with declared capabilities, so a PSA that cannot close a ticket through its API says so before a technician clicks the button rather than failing at it.

RMM — where approved remediation runs

Exploit Hound is not an RMM and does not patch anything itself. It submits named actions from a fixed catalogue to the endpoint tool you already run.

IntegrationStatusNotes
NinjaOneBeta

Read device inventory and run approved remediation scripts.

BetaNeeds: A NinjaOne tenant and API credentials.

Limitation: Remediation runs only from the approved action catalogue; devices are matched on hostname and identifiers, never IP alone.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live NinjaOne tenant has been connected.

Supported operations

  • List devices
  • Match devices to assets
  • Run an approved script
  • Read result
Datto RMMBeta

Read device inventory and run approved remediation components.

BetaNeeds: A Datto RMM account and API keys.

Limitation: Remediation runs only from the approved action catalogue.

Technical detail

Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

No live Datto RMM tenant has been connected.

Supported operations

  • List devices
  • Match devices to assets
  • Run an approved component
  • Read result
ConnectWise RMM / AutomateNot Built

Not implemented. Listed because it is asked for.

Not BuiltNeeds: Nothing — there is nothing to connect to yet.

Limitation: Not built. No inventory read and no remediation for this vendor.

Technical detail

Validation: Not exercised outside the unit tests.

Named here so its absence is visible rather than inferred from a gap in a list.

Supported operations

    N-able N-centralBeta

    Read device inventory and run approved remediation scripts.

    BetaNeeds: An N-central server and API credentials.

    Limitation: Remediation runs only from the approved action catalogue.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No live N-central tenant has been connected.

    Supported operations

    • List devices
    • Match devices to assets
    • Run an approved script
    • Read result
    SyncroBeta

    Read device inventory and run approved remediation scripts.

    BetaNeeds: A Syncro account and an API token.

    Limitation: Remediation runs only from the approved action catalogue.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No live Syncro tenant has been connected.

    Supported operations

    • List devices
    • Match devices to assets
    • Run an approved script
    • Read result

    The console will not present a beta provider as generally available: the lifecycle travels with the integration, and a test asserts that no provider claims GA until it has completed a real patch-and-verify cycle.

    Identity

    IntegrationStatusNotes
    Active DirectoryBeta

    Read-only assessment of directory exposure and privilege relationships.

    BetaNeeds: A read-only directory account and written authorization.

    Limitation: Read-only. Gated behind written authorization before any bind.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No live directory has been assessed in a production deployment.

    Supported operations

    • Bind read-only over LDAP
    • Read users, groups and delegations
    • Map privilege paths
    Microsoft Entra IDBeta

    Read-only assessment of Entra ID exposure and privilege relationships.

    BetaNeeds: An Entra ID tenant and consent to read-only Graph scopes.

    Limitation: Read-only.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    The OAuth path is validated against Microsoft; the mapping of live Graph payloads is not. No live tenant has been assessed.

    Supported operations

    • Authorize read-only Graph access
    • Read users, roles and applications
    • Map privilege paths
    Microsoft 365Beta

    Assessed through the same Entra ID connection.

    BetaNeeds: The same Entra ID connection.

    Limitation: Read-only, and shares the Entra ID connection's limits.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No live tenant has been assessed.

    Supported operations

    • Authorize read-only Graph access
    • Read users, roles and applications
    Google WorkspaceBeta

    Read-only assessment of Workspace exposure and privilege relationships.

    BetaNeeds: Domain-wide delegation you add and revoke in your own Admin console.

    Limitation: Read-only, made as the administrator you nominate and logged under that name. Third-party application grants are optional and reported as unassessed rather than clean when left off.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Reading application grants needs a scope Google publishes in no read-only form. No live Workspace customer has been assessed.

    Supported operations

    • Delegate read-only Admin SDK access
    • Read users, groups and roles
    • Optionally read third-party application grants
    Single sign-on (OpenID Connect)Beta

    Sign in to Exploit Hound with your own identity provider.

    BetaNeeds: An identity provider publishing an OIDC discovery document.

    Limitation: OIDC only — SAML and SCIM are not implemented. A connection names the email domains it may authenticate.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No live identity provider has signed anybody in.

    Supported operations

    • OIDC discovery
    • Authorization code flow with PKCE
    • Verify ID tokens against published keys
    • Restrict a connection to named email domains

    Cloud

    IntegrationStatusNotes
    Microsoft AzureBeta

    Read-only assessment of cloud exposure and privilege relationships.

    BetaNeeds: A Reader role assignment on the subscription.

    Limitation: Assesses exposure and privilege relationships; it is not a cloud posture platform.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Not yet run against a live subscription.

    Supported operations

    • Assume a Reader role
    • Read resources and role assignments
    • Map privilege paths
    Amazon Web ServicesBeta

    Read-only assessment of cloud exposure and privilege relationships.

    BetaNeeds: A read-only role with a required external ID.

    Limitation: Uses AWS's SecurityAudit policy. Assesses exposure and privilege relationships; it is not a cloud posture platform.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Not yet run against a live account.

    Supported operations

    • Assume a read-only role with a required external ID
    • Read resources and IAM relationships
    • Map privilege paths
    Google CloudBeta

    Read-only assessment of cloud exposure and privilege relationships.

    BetaNeeds: Five narrow read-only role grants.

    Limitation: Assesses exposure and privilege relationships; it is not a cloud posture platform.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Narrow roles are used rather than basic Viewer, because Viewer also grants the ability to read object contents. Not yet run against a live project.

    Supported operations

    • Grant five narrow read-only roles
    • Read resources and IAM relationships
    • Map privilege paths

    Notifications

    IntegrationStatusNotes
    EmailBeta

    Report delivery and alerting over an SMTP server you provide.

    BetaNeeds: An SMTP server you provide.

    Limitation: Outbound only. The one live run delivered to an operator's mailbox, never a customer's.

    Technical detail

    Validation: Validated against a live system we own. No customer environment has been involved. Last verified 2026-09-09.

    Arrival was confirmed at the mailbox by hand; the stored run records receipt confirmation as skipped, because only the receiving mailbox can answer it.

    provider_validations #4 (platform 2.76.4): configure, destination_restrictions, smtp_host_allowed, send and cleanup passed; confirm_receipt skipped.

    Supported operations

    • Configure an SMTP server
    • Send a message
    • Record every attempt
    • Retry a failure
    WebhooksBeta

    HMAC-signed events for findings, tickets, remediation and verification.

    BetaNeeds: An HTTPS endpoint and a signing secret.

    Limitation: Outbound only. The one live run delivered to a receiver this platform hosts, never a customer endpoint.

    Technical detail

    Validation: Validated against a live system we own. No customer environment has been involved. Last verified 2026-09-08.

    Arrival and the HMAC signature were both checked at that receiver by hand; the stored run records those two steps as skipped, because only the receiving system can answer them and nobody wrote the answer back.

    provider_validations #2 (platform 2.73.0): configure, destination_restrictions, send and cleanup passed; confirm_receipt and signature_verified skipped.

    Supported operations

    • Configure a destination and signing secret
    • Sign and send an event
    • Record every attempt
    • Retry a failure
    SlackBeta

    Post findings and remediation updates to a Slack channel.

    BetaNeeds: A Slack app and an incoming webhook or bot token.

    Limitation: Message formatting only.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Never exercised against a live workspace.

    Supported operations

    • Format a message
    • Post to a channel
    Microsoft TeamsBeta

    Post findings and remediation updates to a Teams channel.

    BetaNeeds: A Teams incoming webhook.

    Limitation: Message formatting only.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Never exercised against a live workspace.

    Supported operations

    • Format a message
    • Post to a channel
    PushoverBeta

    Push notifications to a device through Pushover.

    BetaNeeds: A Pushover user key and API token.

    Limitation: One device target per account.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    No account holds Pushover credentials and no notification has been delivered to a real device.

    Supported operations

    • Configure a user key and API token
    • Send a notification

    All of these share one deduplicated event pipeline rather than each feature growing its own notifier, so a burst of related findings does not become a burst of messages.

    API and data out

    IntegrationStatusNotes
    REST APIGA

    The API the console itself runs on, available to you directly.

    GANeeds: An account and an API token.

    Limitation: None material — the console runs on it.

    Technical detail

    Validation: Validated against a live system we own. No customer environment has been involved.

    Exercised continuously because the console is a first-party client of every endpoint it calls. That is our own use of it, not a customer integration built against it.

    The console is a first-party client of every endpoint it calls; the end-to-end suite drives it on every run.

    Supported operations

    • Authenticate
    • Read findings, assets and reports
    • Drive remediation workflows
    WebhooksBeta

    The same signed event delivery listed under Notifications.

    BetaNeeds: An HTTPS endpoint and a signing secret.

    Limitation: Outbound only. The one live run delivered to a receiver this platform hosts, never a customer endpoint.

    Technical detail

    Validation: Validated against a live system we own. No customer environment has been involved. Last verified 2026-09-08.

    The same delivery listed under Notifications. Arrival and the signature were checked at that receiver by hand; the stored run records both steps as skipped.

    provider_validations #2 (platform 2.73.0): configure, destination_restrictions, send and cleanup passed; confirm_receipt and signature_verified skipped.

    Supported operations

    • Configure a destination and signing secret
    • Sign and send an event
    • Record every attempt
    • Retry a failure
    Syslog exportBeta

    Forward events to a SIEM collector.

    BetaNeeds: A syslog collector reachable from the platform.

    Limitation: Destinations are limited to syslog ports and cannot be pointed at link-local or metadata addresses.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Never validated against a customer SIEM.

    Supported operations

    • Send over UDP, TCP or TLS
    • Format as RFC 5424 with a JSON message
    • Format as CEF

    Agent platform support

    Three builds of one agent. Built and served is not the same claim as observed running, and one platform’s live run is never evidence for another’s — so each is listed with what has actually been done to it.

    PlatformStatusNotes
    LinuxBeta

    Endpoint inventory and local assessment on Linux.

    BetaNeeds: A host you are authorized to enrol, and an enrolment token.

    Limitation: Reports the host it runs on. Evidence about the Linux build and nothing else.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Demoted from GA on 13 September 2026. The registry's own rule is that nothing may claim a scope without a record to match, and this row claimed owned_live with last_verified null. The observation behind it was real and is undated, and the one agent in the database last checked in on 8 February 2026 with status INACTIVE. scripts/validate_agent_platform.py reports all eight host steps as needing a machine. Restoring GA needs a Linux host and a dated run, not a change to this file.

    Built and served, and covered by the Go suite. The build was observed enrolled and reporting on this platform's own hosts, on a date nothing recorded; no host has checked in since 8 February 2026, so that run cannot be dated or re-run.

    Supported operations

    • Enrol with a one-time token
    • Report OS and patch level
    • Report installed packages and running services
    • Run an authorized local scan
    • Self-update
    WindowsBeta

    Endpoint inventory and local assessment on Windows.

    BetaNeeds: A host you are authorized to enrol, and an enrolment token.

    Limitation: Built and served, but never observed running in a live deployment.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Checksummed and served by the upgrade endpoint, and covered by the Go test suite. The Linux build's live run is not evidence for this one. The platform side is checked on every run of scripts/validate_agent_platform.py: the binary is published at the advertised version and its SHA-256 matches the checksum an updater verifies against. The eight host steps -- install, enrol, inventory, assess, reboot, upgrade, survive an outage, uninstall and lose the credential -- need an authorised Windows host and are recorded as outstanding until one runs them. See docs/LIVE_VALIDATION_REQUIRED.md.

    Supported operations

    • Enrol with a one-time token
    • Report OS and patch level
    • Report installed packages and running services
    • Run an authorized local scan
    • Self-update
    macOSBeta

    Endpoint inventory and local assessment on macOS.

    BetaNeeds: A host you are authorized to enrol, and an enrolment token.

    Limitation: Built and served, but never observed running in a live deployment.

    Technical detail

    Validation: Exercised against recorded provider behaviour in the test suite. No live vendor system has been contacted.

    Checksummed and served by the upgrade endpoint, and covered by the Go test suite. The Linux build's live run is not evidence for this one. The platform side is checked on every run of scripts/validate_agent_platform.py: the binary is published at the advertised version and its SHA-256 matches the checksum an updater verifies against. The eight host steps -- install, enrol, inventory, assess, reboot, upgrade, survive an outage, uninstall and lose the credential -- need an authorised macOS host and are recorded as outstanding until one runs them. See docs/LIVE_VALIDATION_REQUIRED.md.

    Supported operations

    • Enrol with a one-time token
    • Report OS and patch level
    • Report installed packages and running services
    • Run an authorized local scan
    • Self-update

    Need one we have not built?

    The PSA and RMM layers are provider abstractions, so adding a vendor is one implementation against a declared interface rather than a change spread through the application. If an integration we have not built is what decides your evaluation, say so — it is a useful thing for us to know and a reasonable thing to prioritise.

    Tell us what you need

    Start with what's actually exposed.

    Point Exploit Hound at the assets you are authorized to assess and see the connected picture, ranked by what removes the most exposure.

    v2.80.1 Exploit Hound 2.80.1 · Continuous Threat Exposure Management