Capability

MSP vulnerability management

Many customers, a ranked queue for each, and an answer to which fix comes first for every one of them.

Who this is for

MSPs adding a security service

You want to sell vulnerability management without hiring an analyst to turn scanner output into work.

MSPs already running a scanner

You have the findings for every customer and no shared answer to what to fix first, or whether last month's fixes held.

The problem it addresses

An MSP running vulnerability management inherits each customer's findings separately: thousands per environment, ranked by severity, with no shared answer to what to fix first or whether last month's fixes are still in place. The work that bills is the remediation, and the report rarely says which remediation mattered.

How Exploit Hound handles it

  • 1
    Every customer is its own environment

    Each customer is a separate environment in one console. Every query is scoped to the tenant the signed-in user is authorized for, in the data model rather than only in the interface, and the MSP view ranks customers by how much attention they need.

  • 2
    Work is ranked as actions

    Fix First groups findings into the changes a technician performs and ranks them by the exposure each removes, with the named factors behind every position.

  • 3
    Fixes are re-checked

    After the work, the exposure is re-checked rather than read off a closed ticket, and what could not be checked is reported as unverified.

  • 4
    Each customer gets their own report

    Executive and technical reports, a quarterly business review report and white-labelled output are produced per customer, from that customer's data only.

What the result rests on

  • Discovery and assessment results per customer environment
  • The ranked action list and the factors behind each position
  • Re-check results recorded separately from ticket status
  • Discovered assets are never billed; only assets you enrol as managed are

The words this page uses are defined on the resources page: detected, high confidence and safely validated mean different things, and a claim is never stronger than the evidence behind it.

What is generally available, and what is Beta

Read from the same registry as the integrations page, so this table cannot disagree with it. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant.

CapabilityStatusNotes
MSP multi-tenancy as primary designGenerally Available
Fix First remediation rankingGenerally Available
Remediation verified by re-checkingGenerally Available
MSP quarterly business review reportGenerally AvailableTrend needs two comparable periods of history. Where a period was not measured the report says so instead of estimating one, and it states no financial figures.
White-labelled reportingGenerally AvailableAn MSP's name, logo, colour, contact line and footer note. The authorization notice and the line naming what produced the report are not brandable.
PSA / ITSM ticketingBetaBeta ×5 — HaloPSA, ConnectWise, Autotask, Jira, ServiceNow
RMM remediation orchestrationBetaBeta ×4 — NinjaOne, Datto, Syncro, N-able
Monthly customer reviewBetaEleven sections assembled from services that already own each answer. Exercised against this deployment's own data; no customer has been handed one.
OS client deployment through your RMM, Intune or JamfBetaExploit Hound generates the command or package; it does not push anything. Deployment progress is counted from clients checking in, never from what the deployment tool reported about itself. The token is scoped to one deployment with a use limit and an expiry of at most 30 days. A macOS build exists and has never been observed running in a live deployment. No deployment has been run through a real RMM, Intune or Jamf tenant.

Questions MSPs ask about this

How is Exploit Hound priced for MSPs?

Per environment and managed asset, with published tiers: Single environment $199/month, MSP Starter $299/month, MSP Growth $599/month, MSP Scale $999/month, and Large MSP by quote beyond that. Discovered assets are never billed. The pricing page has the detail.

Can each customer only see their own data?

Every query is scoped to the tenant the signed-in user is authorized for, in the data model rather than only in the interface.

Does it connect to my PSA and RMM?

Connections for HaloPSA, ConnectWise Manage, Datto Autotask, Jira and ServiceNow tickets, and for NinjaOne, Datto RMM, N-able N-central and Syncro remediation, are built and in Beta. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant. Every integration’s status is listed here.

In the console

sniff.exploithound.com/mspDemonstration data · v2.80.8
The Exploit Hound multi-customer console: customers ranked by the attention they need, with exposure, critical findings and overdue remediation for each

The interface is the running application. The data in it is invented — every hostname, finding and customer name shown is fabricated for demonstration, and none of it describes a real estate. The full product tour walks every screen.

See it against your own estate

A guided evaluation runs Exploit Hound against a scope you choose and authorize, and produces a measured result rather than a demonstration.

Request a guided evaluation Pricing Trust Center Integration status Product tour

v2.80.8 Exploit Hound 2.80.8 · Continuous Threat Exposure Management