Skip to content
Exposure hunting

A new CVE drops.
Know where it actually reaches.

Launch a Run to hunt it. Unizo finds every place it is present, qualifies what is reachable, and opens the work that matters.

23.4%

of known exploited vulnerabilities in the first half of 2026 showed exploitation on or before the day their CVE was published.

Source: VulnCheck, State of Exploitation 1H 2026

The first question

Every new CVE starts with the same question: where do we have it?

A Run answers from the model Unizo already keeps current. There is no new scan to wait for.

Two ways to hunt

Hunt by CVE. Built to hunt beyond it.

Whichever way a hunt starts, it follows through the same way.

Qualification

Present is a list. Reachable is the work.

Every instance is qualified against Live Security Context. Reachable ones become Exposures. For the rest, you can stand down with evidence.

Your policy

Your policy decides what opens. You can override it at launch.

Qualified Exposures open Investigations as your policy sets. Each Investigation drafts its Plan, including a compensating control when a patch can't land yet.

How Plans are drafted

A hunt doesn't end at the list. It ends at verified closure.

The record

Answer "are we exposed?" with evidence.

Every Run leaves a Report: what was present, what was reachable, what opened, and when it was checked.

Common questions

Where does a hunt look?

Across the environment Unizo is connected to. The connected tools are listed on Integrations, and a tool with an API can be connected during setup.

How current is the answer?

A Run answers from Live Security Context, which is kept current from your connected tools on a refresh you can tune. There is no new scan to wait for.

Does a hunt change anything in our environment?

No. A Run finds, qualifies and records. Investigations open as your policy sets, and the accountable owner applies every change.

Can we choose whether Investigations open?

Yes. Your policy sets the default, and you can override it when you launch the Run.

What if the CVE comes back after we close it?

Once an Exposure is closed, Unizo reopens it if the root cause comes back.

What about threats that don't have a CVE?

Beyond a specific CVE, exposure hunting is built to hunt a vulnerable or compromised package, and follow it the same way, from where it is present to verified closure.

Bring us the CVE you're chasing right now.

We will show you where it is present, where it actually reaches, and who owns the fix.