The threat landscape doesn't wait for your next pentest

The Exposure Clock counts everything that's gone public since your last pentest, and shows how much is already being exploited in the wild.

Find out what changed since your last pentest

Hadrian uses autonomous pentesting to test your internet-facing systems, validate exploitable risks and provide evidence your team can act on.

FAQs

What does the Exposure Clock measure?

The Exposure Clock counts publicly disclosed vulnerabilities within your selected date range. It also shows how many may be remotely exploitable and how many have been added to CISA’s Known Exploited Vulnerabilities catalogue.

How should I use the clock?

Pick any date you choose, we recommend the date since your last pentest was completed. The Exposure Clock will show what has been publicly disclosed since then.

What does “externally exploitable” mean?

A vulnerability is classified as externally exploitable when its CVSS data lists the attack vector as Network. This indicates that exploitation may be possible remotely, but does not confirm that the affected technology is exposed in your environment.

What is a CISA KEV?

The Known Exploited Vulnerabilities catalogue is maintained by the US Cybersecurity and Infrastructure Security Agency. It lists vulnerabilities for which there is reliable evidence of exploitation in the wild.

How is the average time between disclosures calculated?

The tool divides the length of your selected window by the number of CVEs published during that period. This provides an average interval between new vulnerability disclosures.

Why might a KEV have an older publication date?

A vulnerability may be added to the CISA KEV catalogue long after it was originally disclosed. The Exposure Clock counts KEV additions according to when they entered the catalogue within your selected window.

Does the Exposure Clock scan my systems?

No. The tool uses public vulnerability data and does not scan your domains, applications or infrastructure.

Does this show which vulnerabilities affect my organisation?

No. The results show vulnerabilities disclosed across the technologies included in your filters. Determining whether a vulnerability affects your organisation requires an up-to-date understanding of your assets, exposures and deployed software.

Is any information stored?

No. The date range and filters you select are not stored on our servers or in your browser.