Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is exploitation?

Exploitation is the use of a vulnerability or weakness to make a system behave in an unintended way. It may use complex code, but it can also be a crafted request, manipulated authentication flow or simple abuse of insecure configuration.

The result might be code execution, authentication bypass, data access, changed privileges, file upload or disruption.

Vulnerable condition
Exploit attempt reaches target
Target processes it
Attempt succeeds
Observable effect

Prove the stages separately

Keep five propositions distinct: the vulnerability existed; an exploit method was available; an attempt reached the target; the attempt succeeded; and a particular effect followed.

A request pattern may show an attempt. An error or crash may show unexpected processing. A child process, new file, account change or unauthorised data response may demonstrate success and effect. Application, web, network, process and endpoint records should be correlated to connect those stages.

Finding no malware file does not exclude exploitation: the effect may be memory-resident, account-based or limited to reading data. Equally, a known vulnerability on the target does not prove that a matching exploit was used.

Follow access beyond the first host

Where several systems are affected, one successful exploit may create credentials or access reused elsewhere. Do not describe every later host as directly exploited without evidence. Preserve the first affected instance, routing records and subsequent movement so the entry event remains distinguishable from expansion.

Key takeaway

Demonstrate exploitation as a sequence from vulnerable condition through attempt and success to observable effect; no one stage automatically proves the next.

Reference: CIM-094Cyber Incidents & Offender Methods