Core Feature

Two-Axis Exploit Scoring

Every vulnerability is rated on two axes — the impact it carries in your industry, and hard evidence that it's actually being exploited — then fused into one transparent, explainable score. No black box, no EPSS guesswork.

  • Industry impact × evidence-based threat
  • Deterministic and fully explainable — every score shows its reasons
  • Ranks findings far beyond a static CVSS base score
  • Configurable weights and thresholds to match your risk tolerance
Prioritized vulnerability table ranked by Exploit Score with severity and remediation deadlines
Intelligence

Evidence-Based Threat Intelligence

Priority is driven by what's happening in the real world, not by probability estimates. Exploit Score watches the signals that prove a vulnerability is a live threat.

  • CISA Known Exploited Vulnerabilities (KEV)
  • Active ransomware campaign association
  • Public exploit availability & NVD enrichment
  • ML Exploit Intelligence lens re-ranks findings vs. CVSS
Exploit Intelligence chart comparing ML exploit score against CVSS base score across findings
Remediation

POA&M & Remediation Tracking

Turn scores into accountable action. Exploit Score auto-generates Plans of Action & Milestones, assigns team ownership, and tracks every remediation against its deadline.

  • Auto-populated POA&M with points of contact per subnet/team
  • Configurable fix-by deadlines and overdue tracking
  • Milestone tracking with a personal “My POA&M” view
  • One-click FedRAMP POA&M Excel export
Plan of Action and Milestones dashboard with status counts, team ownership and FedRAMP export
Governance

Exemptions, Waivers & Deviations

Not every finding can be fixed on the clock. Analysts request a documented exemption, waiver, or deviation, and every selected approver must sign off before it takes effect — with a full audit trail.

  • Request & approval workflow with multi-approver sign-off
  • Human-readable exemption references (e.g. ABC-2026-08-0001)
  • Exempted findings excluded from scores, POA&M & compliance
  • Awaiting-approval, active, rejected & my-requests views
Security Exemptions console with request and approval workflow tabs and active exemption counts
Compliance

Patch Compliance & Framework Mapping

Measure how well unpatched vulnerabilities are being remediated within each framework's required timeframes — scored and weighted by severity so critical gaps carry the most weight.

  • Severity-weighted compliance score (critical rules count 4×)
  • PCI-DSS, HIPAA, and SOC 2 control mapping
  • Industry-specific rule sets and custom frameworks
  • Per-rule pass/fail visibility with non-compliant asset drill-down
Patch Compliance dashboard with weighted score, rule pass/fail counts and non-compliant items
CISA Directive

BOD 26-04 & SSVC

Meet CISA Binding Operational Directive 26-04 head-on. Exploit Score classifies findings with the SSVC decision model, tracks remediation SLAs, and runs a guided forensic triage for the 3-day-forensic bucket.

  • SSVC classification into 3-day, 14-day, and 60-day buckets
  • Remediation SLA clocks with overdue and due-soon alerts
  • Guided 9-step forensic triage with cross-team assignees
  • Evidence upload and escalation decisions per case
BOD 26-04 forensic triage board with case cards, team ownership, step progress and SLA countdowns
Exposure

Network Vulnerability Map

See your risk as a topology, not a spreadsheet. Every subnet and asset is mapped and color-coded by exposure, so you can spot the hotspots at a glance.

  • Interactive subnet and device topology
  • Filter by exploitable, CISA KEV, critical ETS, or active ransomware
  • Per-device risk counts and drill-down
  • AI insights per subnet
Network Vulnerability Map showing subnets and devices color-coded by exposure with risk filters
Reporting

Scheduled Reports & Security Hub

Get the right picture to the right people. Send on-demand or recurring reports by email, and build a personalized Security Hub from dozens of drag-and-drop widgets.

  • Executive, deadline, POA&M, patch-compliance & BOD report types
  • Daily, weekly, or monthly scheduling to teams or individuals
  • Customizable Security Hub with team-filtered widgets
  • Conversational “Ask Echo” assistant over your live data
Reports console with report types, recipients and scheduling options

All Features

A comprehensive toolkit for modern vulnerability management

Intuitive Dashboard

Clean, actionable views with drill-down capabilities for deep analysis.

Easy Data Import

Import from Qualys, Nessus, Rapid7, or CSV. Scheduled imports supported.

Trend Analysis

Track vulnerability trends over time and measure remediation progress.

Team Management

Role-based access control with team assignments and permissions.

Scheduled Scoring

Automate ML scoring runs on your schedule for always-current data.

Export & Reporting

Generate reports and export data in multiple formats for stakeholders.

Secure Authentication

Two-factor authentication, password policies, session idle timeout, and audit logging.

Configurable Scoring

Customize scoring weights and thresholds to match your risk tolerance.

Flexible Deployment

Deploy on-premise via Docker on Windows, Linux, or Windows Server. Your data stays in your environment.

AI Insights & Ask Echo

Rule-based AI insights across vulnerabilities, POA&M and compliance, plus a conversational assistant over your live data.

Exemptions & Waivers

Request, review, and approve exemptions, waivers, and deviations with human-readable IDs and a full approval trail.

Optional Modules

Turn capabilities like BOD 26-04, Network Map, POA&M, Exemptions, and Ask Echo on or off per deployment.

Ready to See These Features in Action?

Schedule a personalized demo and see how Exploit Score can transform your vulnerability management.