Does a vulnerable system prove it was exploited?¶
No. A vulnerable system proves that a route may have been available; it does not prove that an exploit reached the system or succeeded. The incident may have begun through credentials, phishing or another service instead.
A vulnerable component might not have been reachable, required conditions may have been absent, an attempt may have failed, or a control may have blocked its effect.
Test the historical opportunity¶
Establish the component version and configuration during the incident, not merely when it was later scanned. Determine whether the service was exposed to the suspected source, which prerequisites applied and whether the vulnerable function was enabled.
Patch-management, configuration and network records can reconstruct that state. Patching, rebuilding or containment before examination may make later testing an unreliable guide, so record responder changes and their timing.
Look for the expected exploitation chain¶
Matching requests, errors, crashes, process creation, files, accounts, commands or data access can connect opportunity to an actual event. The expected traces depend on the flaw and may be spread across application, network and endpoint records.
A scanner report produced after the event is useful evidence of exposure but cannot substitute for those incident records. Where the route remains plausible but unproved, report it as a hypothesis and identify the evidential gap rather than presenting it as the confirmed point of entry.
Key takeaway
Vulnerability is evidence of opportunity; conclude exploitation only when historical reachability and incident-specific effects support that route.