Exploit
An exploit is code or a method that deliberately exploits a security vulnerability to compromise a system or gain higher privileges.
An exploit is code or a method used to specifically take advantage of a vulnerability. It turns a theoretical flaw into a real attack.
How it works
An exploit takes advantage of a flaw in software, configuration, or a protocol. The result can be the execution of arbitrary code, elevated privileges, or data access. After a vulnerability is disclosed, a public exploit often appears within days. Some are built into tools that less experienced attackers can use.
A practical example: a public exploit is released for a web server vulnerability. A few hours later, a customer's logs show the first scans. The attackers are automatically searching for vulnerable servers. The customer's server is already patched, but the SOC still checks if an attempt was successful.
What to look out for
- A public exploit greatly increases a vulnerability's risk. Prioritise your response accordingly.
- Pay special attention to systems that are accessible from the internet.
- An exploit often leaves traces, like unusual processes or error messages. Monitor for these signs.
- Implement temporary protective measures if a patch is not yet possible.
Types of exploits
There is a distinction between remote exploits and those requiring local access. Remote exploits are particularly dangerous because they need no prior system access. Local exploits are often used to gain higher privileges after an initial breach.
Relevance for the SOC
Detection rules identify many exploits by their subsequent behaviour, such as a web server launching a command line. These rules remain effective even against new vulnerabilities. Additionally, information from CTI sources helps to search specifically for known patterns.
Typical mistakes
A common mistake is patching without checking if the vulnerability was previously exploited. Another error involves older systems that cannot be patched. These systems are often left without extra monitoring.
How we implement it
Our detection identifies the exploitation of vulnerabilities by the behaviour of affected systems. For new exploits affecting widespread products, we specifically search for traces.