Vulnerability prioritisation
that shows you what to fix first.
Tens of thousands of CVEs a year. Our platform scores every one by real exploitation risk, so you fix what matters, not what is loud.
Precursor Intelligence delivers continuous threat exposure management (CTEM). It fuses EPSS, CVSS, CISA KEV and Shadowserver honeypot exploitation data into the exploitation risk score to rank vulnerabilities by real-world exploitation likelihood, monitors external attack surface, and tracks ransomware groups and threat actors, from an API-first, single-token data platform with a production MCP server.




Know what to fix first, and prove why
CTEM is Gartner’s five-stage framework for continuously reducing exploitable exposure, instead of scanning and patching once a year. We run the stages where prioritisation actually happens.
Fix what matters. Ignore the noise.
Vulnerability prioritisation, threat intelligence, and attack surface monitoring in one continuous layer, live between your annual tests.
Track your whole tech stack, agentless
Define the vendors, libraries and versions you run. Get a real-time alert the moment a CVE lands in the NVD. No agents to install, no waiting for the monthly scan.
Know what will actually be exploited
One exploitation risk score fuses EPSS, CISA KEV, CVSS and threat-actor signal, plus a plain-English AI read on every vulnerability, so you fix the 2 to 5 percent that matter.
Get the fix, not just the finding
Step-by-step remediation with the exact CLI commands and patch links, MITRE ATT&CK context on every alert, and notifications straight to Email, Slack, Teams or a webhook.
Curated feeds, not a firehose
Aggregated, curated threat feeds and IOCs, ransomware and threat-actor tracking, all mapped to MITRE ATT&CK and queryable over the API and MCP server.
Catch impersonation before the phish
Detect lookalike domains, monitor your domains, subdomains and Microsoft 365, and track SSL certificate expiry across your estate.
See what an attacker sees
Launch EdgeProtect scans from the dashboard to discover shadow IT, map assets and network topology, and surface exposed credentials.
Query it all from Claude, Cursor or any MCP client
The Precursor Intelligence MCP server exposes 41 read-only tools, so your coding agent can ask which CVEs actually matter, and get an evidenced answer.
Everyone resells the same three feeds. We fuse in what they ignore.
Fixes, not just findings
Most tools hand you a list and leave. Precursor gives you the exact CLI commands and patch links to remediate, MITRE ATT&CK context on every alert, and a weekly PDF report that shows your risk going down.
Agentless and exploitation-led
No agents to deploy. We fingerprint your tech stack and rank by real exploitation likelihood, using EPSS, CISA KEV and Shadowserver honeypot signal, so you fix the 2 to 5 percent attackers actually use.
API-first and agent-native
Every dataset over one bearer-token REST API, a 41-tool MCP server for AI agents like Claude, and webhooks. Free forever tier, UK and EU data residency, and a CREST-accredited team behind it.
Start free. Scale when you are ready.
Transparent, usage-based pricing. No sales call required to get started, and no card for the free tier.
For getting started
- Score your backlog
- EPSS, CISA KEV and CVSS lookups
- CVE search
- Community support
For security teams
- Full 5-dimension exploitation risk score
- REST API and MCP server access
- EdgeProtect attack surface scans
- Brand impersonation monitoring
- Priority support
For larger teams and estates
- Organisation and team access
- UK and EU data residency
- SSO and audit logging
- Dedicated support
- Volume and partner pricing
Put intelligence to work
Precursor Intelligence is the continuous bookend to point-in-time penetration testing and 24/7 managed SOC. Test, monitor, and prioritise from one closed loop.
Enterprise or MSSP? Talk to sales.
Exposure management, explained
CTEM, exposure management and vulnerability prioritisation, in plain English.
CTEM is a Gartner-defined five-stage framework (scoping, discovery, prioritisation, validation and mobilisation) that continuously reduces exploitable exposure across an organisation’s attack surface, rather than relying on point-in-time scans or annual tests. Precursor Intelligence delivers the discovery, prioritisation and validation stages with an evidenced exposure score.
Exposure management is the continuous practice of discovering, prioritising and reducing everything an attacker could exploit across your attack surface. It extends traditional vulnerability management with real-world exploitation context, so teams fix what attackers actually use rather than working down a list by severity.
Traditional vulnerability management identifies and patches CVEs, usually ordered by CVSS severity. CTEM adds continuous discovery, exploitability-based prioritisation, and validation, and aligns the whole cycle to business risk. In practice, roughly 60 percent of CVEs score 7.0 or above, so a severity-only queue tells you almost everything is critical. CTEM fixes the ordering.
Vulnerability prioritisation ranks your vulnerabilities by how likely they are to actually be exploited, not just how severe they are. Precursor Intelligence combines EPSS likelihood, CISA KEV exploitation status, CVSS impact, CWE weighting and threat-actor attribution into one exploitation risk score.
The exploitation risk score is a 0 to 100 exposure score, evidenced on every ranking, which uses live exploitation data from Shadowserver honeypot sensors. The full production score adds CWE-based impact weighting and threat-actor attribution across five dimensions.
No. Precursor Intelligence is a prioritisation and intelligence layer, not a scanner or patch orchestrator. It takes your scanner output or declared technology stack and hands back a defensible, evidenced queue, so your existing tooling keeps working and you finally know what to fix first.
Precursor Intelligence offers UK and EU data residency for organisations with residency or sovereignty requirements, and is used by teams worldwide. It is built on Shadowserver honeypot exploitation data, with transparent tiered pricing and a production MCP server for AI agents.