Precursor Security
Precursor Intelligence

Vulnerability prioritisation
that shows you what to fix first.

Tens of thousands of CVEs a year. Our platform scores every one by real exploitation risk, so you fix what matters, not what is loud.

Precursor Intelligence delivers continuous threat exposure management (CTEM). It fuses EPSS, CVSS, CISA KEV and Shadowserver honeypot exploitation data into the exploitation risk score to rank vulnerabilities by real-world exploitation likelihood, monitors external attack surface, and tracks ransomware groups and threat actors, from an API-first, single-token data platform with a production MCP server.

Free tier available. No sales call required.See how the score works
2 to 5%
of published CVEs are ever exploited in the wild
60%
of CVEs score CVSS 7.0+, so severity alone cannot sequence them
Days
from disclosure to exploitation for KEV-listed CVEs
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Accredited by the industry's bestCREST Penetration TestingCREST Vulnerability AssessmentCREST Security Operations CentreCyber Essentials Plus
Continuous Threat Exposure Management

Know what to fix first, and prove why

CTEM is Gartner’s five-stage framework for continuously reducing exploitable exposure, instead of scanning and patching once a year. We run the stages where prioritisation actually happens.

01
Scoping
Define what actually matters to the business, and the boundaries of the attack surface worth defending.
02
Discovery
Passive external discovery of your internet-facing assets, plus your scanner output and declared technology stack.
03
Prioritisation
Risk-based vulnerability management: rank exposures by the exploitation risk score, fusing EPSS, CISA KEV, CVSS, CWE impact, honeypot data and threat-actor signal.
04
Validation
Confirm genuine exploitability by using multiple independent sources, not theoretical severity.
05
Mobilisation
Route fixes into your existing tooling and owners, with serious findings escalated to a CREST-certified team.
One Platform

Fix what matters. Ignore the noise.

Vulnerability prioritisation, threat intelligence, and attack surface monitoring in one continuous layer, live between your annual tests.

For AI agents

Query it all from Claude, Cursor or any MCP client

The Precursor Intelligence MCP server exposes 41 read-only tools, so your coding agent can ask which CVEs actually matter, and get an evidenced answer.

Explore the MCP server
Why Precursor Intelligence

Everyone resells the same three feeds. We fuse in what they ignore.

Fixes, not just findings

Most tools hand you a list and leave. Precursor gives you the exact CLI commands and patch links to remediate, MITRE ATT&CK context on every alert, and a weekly PDF report that shows your risk going down.

Agentless and exploitation-led

No agents to deploy. We fingerprint your tech stack and rank by real exploitation likelihood, using EPSS, CISA KEV and Shadowserver honeypot signal, so you fix the 2 to 5 percent attackers actually use.

API-first and agent-native

Every dataset over one bearer-token REST API, a 41-tool MCP server for AI agents like Claude, and webhooks. Free forever tier, UK and EU data residency, and a CREST-accredited team behind it.

Pricing

Start free. Scale when you are ready.

Transparent, usage-based pricing. No sales call required to get started, and no card for the free tier.

Free
£0forever

For getting started

  • Score your backlog
  • EPSS, CISA KEV and CVSS lookups
  • CVE search
  • Community support
ProMost popular
Usage-basedpay per use

For security teams

  • Full 5-dimension exploitation risk score
  • REST API and MCP server access
  • EdgeProtect attack surface scans
  • Brand impersonation monitoring
  • Priority support
Enterprise
Customannual

For larger teams and estates

  • Organisation and team access
  • UK and EU data residency
  • SSO and audit logging
  • Dedicated support
  • Volume and partner pricing

Put intelligence to work

Precursor Intelligence is the continuous bookend to point-in-time penetration testing and 24/7 managed SOC. Test, monitor, and prioritise from one closed loop.

Enterprise or MSSP? Talk to sales.

Exposure management, explained

CTEM, exposure management and vulnerability prioritisation, in plain English.

CTEM is a Gartner-defined five-stage framework (scoping, discovery, prioritisation, validation and mobilisation) that continuously reduces exploitable exposure across an organisation’s attack surface, rather than relying on point-in-time scans or annual tests. Precursor Intelligence delivers the discovery, prioritisation and validation stages with an evidenced exposure score.

Exposure management is the continuous practice of discovering, prioritising and reducing everything an attacker could exploit across your attack surface. It extends traditional vulnerability management with real-world exploitation context, so teams fix what attackers actually use rather than working down a list by severity.

Traditional vulnerability management identifies and patches CVEs, usually ordered by CVSS severity. CTEM adds continuous discovery, exploitability-based prioritisation, and validation, and aligns the whole cycle to business risk. In practice, roughly 60 percent of CVEs score 7.0 or above, so a severity-only queue tells you almost everything is critical. CTEM fixes the ordering.

Vulnerability prioritisation ranks your vulnerabilities by how likely they are to actually be exploited, not just how severe they are. Precursor Intelligence combines EPSS likelihood, CISA KEV exploitation status, CVSS impact, CWE weighting and threat-actor attribution into one exploitation risk score.

The exploitation risk score is a 0 to 100 exposure score, evidenced on every ranking, which uses live exploitation data from Shadowserver honeypot sensors. The full production score adds CWE-based impact weighting and threat-actor attribution across five dimensions.

No. Precursor Intelligence is a prioritisation and intelligence layer, not a scanner or patch orchestrator. It takes your scanner output or declared technology stack and hands back a defensible, evidenced queue, so your existing tooling keeps working and you finally know what to fix first.

Precursor Intelligence offers UK and EU data residency for organisations with residency or sovereignty requirements, and is used by teams worldwide. It is built on Shadowserver honeypot exploitation data, with transparent tiered pricing and a production MCP server for AI agents.