Case Study - Exploit Validation (Stop Fixing Ghosts)

540 “criticals” → 58 actually exploitable. The other 482 were ghosts burning sprints.

ILLUSTRATION — VALIDATION FUNNEL
540
Scanner claims
→
210
Reachable
→
58
Verified exploitable

Controlled, scoped, rollback-ready — staging-first, prod only with written approval

Client Context

Telco — 3,000+ network + IT assets, 4 scanners, 2 SOC shifts triaging. Engineers ignored “critical” tickets because 9 of 10 were not reproducible. Board questioned security budget.

Challenge

Distinguish truly exploitable vulnerabilities from false positives with controlled validation — safe, authorized, evidenced — so remediation hits real risk first.

Scope - Snipeyes Exploit Validation

  • Reachability filter (exposure + auth + config context) before any active check
  • Controlled validation playbooks: read-only proof preferred (file read, session proof, non-destructive command); no data alteration in prod
  • Every verified item ships with replay steps, logs, CVSS + exploitability rating; unverified stays labeled as such
  • Output: verified / exploitable findings register

Key Findings (redacted)

  • Only 58 of 540 criticals verified exploitable (11%) — rest: unreachable, compensated control, or version-paranoia FP
  • Top verified: VPN pre-auth RCE chain (validated in lab twin), SSO token replay, S3 write → supply-chain poison path
  • 3 “mediums” upgraded to critical after chaining proof; 12 “criticals” downgraded (WAF + isolation verified)

Outcome

  • Sprint load cut 70%; verified items SLA-met 100% in 30 days — board confidence restored
  • Insurer + regulator accepted validation evidence as risk-reduction proof
  • Validation playbooks now run automatically on every new critical

Relevance for you: If your team fixes CVEs by CVSS alone — validate exploitability first.