The platform
One correlated model of your exposure.
Exploit Hound collects from the outside in and the inside out, stores what it finds as an evidence-backed graph, and reasons over that graph to answer the only question that matters on a Monday morning: what do we fix first?
Attack surface
Discovery from both directions
External
Domains, subdomains, public addresses, exposed ports and services, TLS posture and certificate state. Everything discovered is recorded with when it was first and last seen, so new exposure is obvious.
Internal
Network Sentry discovers devices on the LAN, tracks them by MAC and address over time, and flags devices that are not authorized. Endpoint agents report operating system, installed software and services.
Vulnerability management
Prioritization you can explain to a customer
Findings carry an Exploit Hound Risk Score from 0 to 100 built from named factors — never a single opaque number.
Exploitability
CVSS, EPSS probability, CISA Known Exploited Vulnerabilities and public exploit availability.
Reachability
Whether the affected service is reachable from the Internet, and whether it sits on a route toward something valuable.
Business context
Asset criticality and role, observed threat activity, finding age, reopen history and any compensating control you have recorded.
Scores are versioned. When the methodology changes, older scores remain interpretable because the factors that produced them are stored alongside the number.
Configuration assessment
Beyond CVEs
A great deal of real exposure is configuration, not a missing patch. Exploit Hound derives configuration findings from evidence it has already collected.
- Plaintext administrative protocols
- Internet-reachable database ports
- Internet-reachable administrative interfaces
- File sharing exposed to the Internet
- SNMP exposure
- Deprecated TLS versions
- Weak TLS cipher suites
- Certificate problems
Findings are mapped to CIS Control, NIST CSF and MITRE ATT&CK identifiers, with remediation guidance written for this product. No proprietary benchmark text is redistributed.
Attack paths
How the pieces connect
Attack path analysis walks the exposure graph from entry points — the Internet, an untrusted network, a workstation assumed to be under attacker control — toward the systems worth protecting.
Evidence per hop
Each hop states why it exists, what evidence supports it, its confidence, the finding behind it and the recommended remediation.
Honest labels
Potential High confidence Safely validated
A path is never described as exploited or as evidence of compromise.
Choke points
The systems that the largest number of distinct routes pass through — usually where a single change buys the most.
Threat detection
Signals, not just inventory
Network telemetry
NetFlow collection with DNS, TLS and ASN enrichment, baselines and service drift alerting.
Deception
Deployable honeypots that record interactions with services nobody legitimate should be touching.
Threat intelligence
Indicator matching against observed traffic and DNS, correlated back to the internal host involved.
These signals feed prioritization directly: an exposure on an asset with recent suspicious activity scores higher than the same exposure on a quiet one.
Identity exposure
Identity is part of your attack surface
Attackers don't stop at software vulnerabilities. Exploit Hound reads your Active Directory and combines identity and privilege relationships with network and asset exposure, so the dangerous combinations become visible.
Read-only, and explicitly authorized
The assessment reads attributes any authenticated domain user can already see. It never cracks or sprays passwords, never reads password hashes, never requests Kerberos tickets for offline cracking, and never writes to the directory. It stays disabled until a named person authorizes it with a written reason, and that record is kept.
What it looks for
Unconstrained and dangerous delegation, privileged accounts exposed to Kerberoasting, accounts with pre-authentication disabled, dormant privileged accounts, reversible password storage, nested privilege, weak password policy, stale krbtgt, LDAP and SMB signing posture, LLMNR and NBT-NS exposure, and certificate templates that let a requester choose their own identity.
Identity findings are not a separate report. They join the same exposure graph as everything else, so a server trusted for unconstrained delegation shows up as what it actually is: a route toward a domain controller.
Alerting
One event pipeline, not an integration per feature
Critical exposures, known exploited vulnerabilities, new attack paths to critical systems, reopened findings, verified fixes and overdue remediation all flow through one pipeline to email, Slack, Microsoft Teams or a webhook.
Repeats of the same condition are folded into one event with a count rather than a hundred alerts, and a destination is not notified again about something it already acknowledged. Events are recorded even when nothing is sent, so “we knew and chose not to page” stays auditable.
AI Security Analyst
Ask questions about a customer’s exposure
What should I fix first? What changed this week? What is the shortest potential route from the Internet to a critical system? Answers are grounded in that customer’s own data.
Every finding, asset and attack path the answer cites is checked against the records it was actually given — anything else is flagged rather than presented as fact. With no data, it says so instead of producing something plausible. You can see the exact evidence it was handed.
Remediation & verification
Fix First, then prove the fix
Fix First
Findings are grouped into the actions a person actually performs, and each action reports the attack paths it removes, the critical systems it protects, the known exploited vulnerabilities it clears and the findings it closes at once. Path counts are exact over the current graph; percentages are labeled as estimates.
Verify Fix
Request a targeted, non-destructive recheck of one finding. Exploit Hound selects the narrowest safe check for that finding type, runs it against the finding's own authorized asset, records the evidence, and only then moves the finding to verified.
Verification checks are read-only by design: a TCP connect test, a TLS handshake inspection, a response-header read or a banner read. Verify Fix cannot be pointed at a target of your choosing — the target is derived from the finding's own authorized asset record.
Business context
Not every asset is worth the same
A critical vulnerability on a spare laptop and the same vulnerability on the domain controller are not the same problem. Criticality feeds risk scoring, which systems attack path analysis treats as worth reaching, Fix First ranking and what the report says.
Exploit Hound can suggest a role and criticality from what it has observed — a machine answering as a domain controller, a database listening on its standard port, a host that many others depend on. Suggestions are proposals, not silent edits: you confirm them, and an explicit setting is never overwritten by inference.
Change detection
What changed since last week
Added, removed, worsened, improved — over whatever window you pick. New exposure is the thing worth a person’s attention; a finding that has been open and unchanged for a month is not news.
There is no separate capture pipeline behind this. It reads the first-seen, last-seen and active bookkeeping the exposure graph, findings and attack paths already maintain, which means it cannot disagree with the rest of the platform about what is true.
False positives
Does this finding actually apply?
A version banner is not proof. Before a finding consumes anyone’s time, Exploit Hound checks whether the vulnerability genuinely applies to that target — the right product, the affected version range, the configuration that makes it reachable.
This matters more for MSPs than for anyone else. You are reporting to customers who did not choose the tool, and a queue padded with findings that do not apply costs you credibility long before it costs you time.
Start with what's actually exposed.
Point Exploit Hound at the assets you are authorized to assess and see the connected picture — not another list.