Exploit Hound: risk scores, Fix First and Threat Radar
For the technician or analyst who works the Exploit Hound queue and has to explain it: the 0-100 risk score as a sum of named, versioned factors, the words detected, high confidence and safely validated, applicability checks before a finding takes anyone's time, how Fix First ranks the actions a technician performs and measures its own predictions afterwards, the change bundle preview, and how to read the public Threat Radar (CISA KEV, EPSS and CVSS) without telling a customer they are affected.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Exploit Hound
Skills you'll practise
- Explain a finding's Exploit Hound risk score from its named factors and stored scoring version
- Use the evidence-strength terms precisely and never claim more than the evidence supports
- Choose the first action from a Fix First worklist and explain what its path counts and estimates mean
- Interpret a Fix First prediction result, including when other remediation overlapped
- Read CISA KEV, EPSS and CVSS on the Threat Radar correctly and avoid telling a customer they are affected from a catalog alone
Course outline
- 1.Exploit Hound: risk scores, Fix First and Threat RadarVideo · 2 min
- 2.How a finding's score is builtLesson · 17 min
- 3.Fix First: rank the work, then check the predictionLesson · 17 min
- 4.Reading the Threat RadarLesson · 16 min
- 5.Exploit Hound: risk scores, Fix First and Threat Radar: knowledge checkKnowledge check · 16 questions
- 6.A known-exploited flaw on the clinic's VPNScenario
- 7.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Exploit Hound: Resources and FAQ (terminology, how the risk score is built)
- Exploit Hound: platform overview (architecture, scoring, attack paths, identity, ticketing, alerting, verification, exceptions)
- Exploit Hound: Vulnerability prioritization
- Exploit Hound: Fix First prioritization
- Exploit Hound: Product tour (twelve console screens on demonstration data)
- Exploit Hound: Interactive demo (illustrative scoring model on synthetic findings)
- Exploit Hound: Integrations and their status (GA, Beta, Not Built)
- Exploit Hound: Threat Radar (public CISA KEV and EPSS view)
- CISA: Known Exploited Vulnerabilities Catalog
- FIRST: Exploit Prediction Scoring System (EPSS)
- FIRST: Common Vulnerability Scoring System (CVSS)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.