Case Study - Exploit Validation (Stop Fixing Ghosts)
540 “criticals” → 58 actually exploitable. The other 482 were ghosts burning sprints.
Scanner claims
Reachable
Verified exploitable
Controlled, scoped, rollback-ready — staging-first, prod only with written approval
Client Context
Telco — 3,000+ network + IT assets, 4 scanners, 2 SOC shifts triaging. Engineers ignored “critical” tickets because 9 of 10 were not reproducible. Board questioned security budget.
Challenge
Distinguish truly exploitable vulnerabilities from false positives with controlled validation — safe, authorized, evidenced — so remediation hits real risk first.
Scope - Snipeyes Exploit Validation
- Reachability filter (exposure + auth + config context) before any active check
- Controlled validation playbooks: read-only proof preferred (file read, session proof, non-destructive command); no data alteration in prod
- Every verified item ships with replay steps, logs, CVSS + exploitability rating; unverified stays labeled as such
- Output: verified / exploitable findings register
Key Findings (redacted)
- Only 58 of 540 criticals verified exploitable (11%) — rest: unreachable, compensated control, or version-paranoia FP
- Top verified: VPN pre-auth RCE chain (validated in lab twin), SSO token replay, S3 write → supply-chain poison path
- 3 “mediums” upgraded to critical after chaining proof; 12 “criticals” downgraded (WAF + isolation verified)
Outcome
- Sprint load cut 70%; verified items SLA-met 100% in 30 days — board confidence restored
- Insurer + regulator accepted validation evidence as risk-reduction proof
- Validation playbooks now run automatically on every new critical
Relevance for you: If your team fixes CVEs by CVSS alone — validate exploitability first.