The Nagomi Method: Every Exposure Gets a Full Investigation, Not a Guess
.png)
A CVSS score is a suspicion. It names a suspect but never places them at the scene. Security teams have become accustomed to triaging exposures on suspicion alone, sorting stacks of static scores that say nothing about what's actually occurring on the machine in front of them.
As Sherlock Holmes warned, "It is a capital mistake to theorize before one has data. Insensibly one begins to twist facts to suit theories, instead of theories to suit facts." Exposure management teams have been theorizing for years.
Today, to change that paradigm, Nagomi is introducing Forensic Analyst, the newest capability inside our Agentic Exposure Operations platform. It's the first release under a new standard we call The Nagomi Method: every exposure gets a full investigation, not a guess.
What Triggers a Forensic Investigation
It all starts with identifying exposure. Nagomi’s AI Exposure Eliminators are designed to trigger on specific environmental changes: a fresh scan result, a changed configuration, a control that's failed. When one of those signals is detected, the Eliminator opens a case and runs the investigation autonomously — the way a senior analyst would, but at any hour and at full scale.
The first capability inside that investigation, and the one launching this week, is Exploitability Assessment.
What is an Exploitablity Assessment? Nine Evidence Checks Explained
An Exploitability Assessment is the process of investigating telemetry through deterministic checks to confirm whether a threat actor can execute an attack on a specific vulnerability in the given environment, under present conditions.
Nagomi’s agentic Exploitability Assessment reads the user’s own EDR telemetry, the same data the organization’s endpoint tools already collect.
"Data! Data! Data!" Holmes has famously declared. Nagomi's agents operate under the same premise: exploitability isn't asserted, it's built, condition by condition, from six checks on the host:
- Vulnerable software installed
- Vulnerable component actively running
- Compensating controls
- Listed in CISA KEV catalog
- Exploited in the wild — yes or no
- EPSS probability
Each condition returns a clear “yes” or “no,” substantiated by the specific evidence found on that system. Nothing is inferred from a network model, and nothing relies on static CVSS base scores. The evidence comes directly from customers’ environments, observed on the entity in question.
Two deterministic rules convert these conditions into a final verdict.
- First, dormant risk remains capped at Medium if the vulnerable component never executes.
- Second, live exposure escalates priority. When a network-accessible CVE displays two or more exposure indicators, such as open ports or active traffic, Nagomi elevates the exploitability rating by one band.
"When you have eliminated the impossible, whatever remains, however improbable, must be the truth," Holmes said. That logic governs how Forensic Investigations operate: check six conditions, apply two rules, and deliver a rating backed strictly by direct host telemetry.
The result is a ratings scale that shows the probability of exploitation as Low, Medium, or High (determined from the six checks listed above) rather than a numerical score. The distinction is critical: Severity scores measure theoretical impact. Evidence-backed exploitability answers a much tighter question: Can an attacker execute this specific CVE, on this specific host, right now?
How Exploitability Ratings Differ From Severity Scores
Every rating is accompanied by full evidence and a one-line explanation of how the severity category was calculated. An analyst doesn't have to defend an ambiguously assigned number. They can pinpoint the process that was or wasn't running, the compensating controls that mitigate the likelihood of compromise in their environment, and whether or not the known vulnerability details classify this exposure as active. This is the evidence that allows them to confidently communicate and manage exposure elimination.
This operational shift defines The Nagomi Method. A queue full of opaque High or Critical findings creates urgency without direction. A queue in which each finding is accompanied by its own inspectable case file creates confidence because the security team knows which issues are indicative of business-impacting risk before they dedicate time and resources to closing a case.
Where the evidence supports a true exposure, Nagomi generates a verified remediation path. Where it doesn't, the platform provides an explanation and moves to an exposure that actually warrants the next investigation. "I never guess," Holmes said. "It is a shocking habit, destructive to the logical faculty." No dramatic hunches. No busywork. Just a verdict a security leader can act on and defend.
This isn't the exploitability analysis your team already suspects. It's not a scanner that extrapolates from a version number. And it's not an unexplainable score that depends on blind trust. It's an agent that runs the same investigation a skilled analyst would run, at every hour, on every host, and shows its work every time.
The result is an exhaustive investigation, at AI speed, that dramatically decreases the human time and effort involved in analyzing complex cases. Purpose built for AI-native environments, deep forensic analysis becomes elementary, my dear reader!
The game's afoot. Forensic Analyst launches August 2026, inside Nagomi's Agentic Exposure Operations platform.
Want to see how Nagomi’s Agentic Exposure Ops Platform handles your environment? Request a demo.
See Nagomi in action at nagomisecurity.com


