Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an exploit?

An exploit is code, a request, command or technique designed to take advantage of a particular vulnerability. Possessing exploit material shows possible capability or preparation; it does not prove delivery or success against a victim.

Exploits range from public proof-of-concept scripts to crafted documents, network requests and features within larger frameworks. Widely shared code is not a reliable identifier of its user.

MethodExploit code / request / techniqueShows a possible way to use the weakness.
Target fitRight version and conditions?The system must actually meet the exploit's prerequisites.
DeliveryDid it reach the target?Target-side records may show the attempt.
OutcomeDid exploitation succeed?Look for the intended unauthorised effect.

Match the method to the target

Determine which weakness the exploit targets, the versions and configuration it expects, its prerequisites and intended effect. Then test whether the affected system met those conditions at the relevant time.

Target-side web, application, network, crash and process records may show delivery and outcome even if the exploit code itself is never recovered. Conversely, code on a suspect device may never have reached the target. Its download, modification and execution history help distinguish research, possession and deployment.

Capability is not successful exploitation

Establish whether the method reached the target, was processed by the vulnerable component and produced its expected effect. A failed request and successful code execution should not be reported under the same broad label.

Product-specific behaviour should be assessed against contemporaneous vendor or authoritative analysis. Personal attribution requires evidence linking delivery and target activity to the relevant controller, not merely similarity to public code.

Key takeaway

Treat an exploit as a method: prove separately that the target was vulnerable, the method reached it and the intended unauthorised effect occurred.

Reference: CIM-095Cyber Incidents & Offender Methods