Resources
How to read what Exploit Hound tells you.
Security tooling earns trust by being precise about what it knows. These are the words we use and what each one is allowed to mean.
Terminology
| Term | What it means |
|---|---|
| Detected | Evidence indicates the exposure likely exists. |
| High confidence | Multiple reliable signals support the finding. |
| Safely validated | An approved non-destructive check confirmed the exposure. |
| Potential attack path | Graph analysis indicates a possible route through related exposures. |
| Validated evidence | The stored artefact — a probe result, a banner, a negotiated protocol — behind a claim. |
Two words we do not use loosely: compromised is reserved for cases where evidence actually proves compromise, and exploited is reserved for cases where validation or evidence actually proves exploitation. Graph analysis alone never earns either word.
How the risk score is built
The Exploit Hound Risk Score runs 0–100 and is always the sum of named factors.
| Factor group | Inputs |
|---|---|
| Base severity | CVSS where available, otherwise scanner severity |
| Exploitation likelihood | EPSS, CISA KEV listing, public exploit availability |
| Exposure | Internet reachability, exposure category |
| Business context | Asset criticality and role |
| Connectivity | Number of attack paths the finding participates in |
| Observed activity | Threat intelligence matches and deception interactions on the asset |
| Evidence strength | Detected, high confidence or safely validated |
| Ageing | How long the exposure has been open, and whether it has been reopened |
| Compensating controls | Recorded risk acceptance or operator flag, which reduce the score |
Every scored finding stores the factor list and the scoring version used, so a score can still be explained after the methodology changes.
Releases
Exploit Hound ships continuously. The version in the corner of this site is always the release the hosted platform is running now.
Selected customer-visible changes are published on the releases page. The console carries the full changelog for anyone with an account, and customers on a support agreement receive a summary of security-relevant changes with each release.
What Exploit Hound will not do
This is a defensive platform for systems you own or are authorized to assess.
Validation is read-only
Automated verification is limited to non-destructive checks: connectivity tests, protocol negotiation, configuration confirmation and banner reads. No payloads, no persistence, no configuration changes, no credential dumping.
Scope is enforced
Assets must be marked authorized before they can be re-checked, verification targets are derived from the asset record rather than from the request, and loopback and cloud metadata addresses are refused outright.
Common questions
The questions we are asked most, answered in the same terms as the rest of this page.
What does Exploit Hound mean by “detected”, “high confidence” and “safely validated”?
Detected means evidence indicates the exposure likely exists. High confidence means multiple reliable signals support the finding. Safely validated means an approved non-destructive check confirmed it. The words are deliberately separate so that a claim is never stronger than the evidence behind it.
Does Exploit Hound say a system has been compromised or exploited?
Only where evidence proves it. “Compromised” is reserved for cases where evidence actually proves compromise, and “exploited” for cases where validation or evidence proves exploitation. Graph analysis alone never earns either word, and observed probing against a service is reported as observed probing — not as exploitation of the vulnerability on it.
How is the Exploit Hound risk score calculated?
It runs 0–100 and is always the sum of named factors: base severity, exploitation likelihood (EPSS, CISA KEV, public exploit availability), exposure, business context from asset criticality and role, connectivity through attack paths, observed activity, and evidence strength. Every point is attributable, so a score can be argued with rather than taken on trust.
Which compliance frameworks does Exploit Hound map findings to?
PCI DSS, the HIPAA Security Rule, NIST CSF, CIS Controls, ISO/IEC 27001 Annex A and the SOC 2 Trust Services Criteria. Findings are mapped to the controls they bear on, with the reason each applies. Exploit Hound does not determine compliance — that is an assessor's conclusion drawn from scope, compensating controls and process it cannot observe.
Which PSA and ticketing systems does Exploit Hound integrate with?
HaloPSA, ConnectWise Manage, Datto Autotask, Jira and ServiceNow — all five Beta. Implemented and tested, including against recorded provider behavior, but not yet validated against a live vendor tenant. Remediation work raises one ticket per action; re-running the prioritization updates that ticket rather than opening another. Every integration’s status is listed here.
How is Exploit Hound priced?
Published, per environment: Single environment $199/month, MSP Starter $299/month, MSP Growth $599/month, MSP Scale $999/month, and Large MSP by quote beyond that. Only assets you enrol for monitoring are billed — discovered assets never are. The pricing page has the tiers, what counts as a managed asset, and what happens when you exceed one.
Start with what's actually exposed.
Point Exploit Hound at the assets you are authorized to assess and see the connected picture, ranked by what removes the most exposure.