Delivery & Exploitation
Press Next → or use ← → arrow keys
Phases 3 & 4 of the Kill Chain
Reconnaissance found the target. Weaponization built the weapon. Now the chain reaches its loudest, most catchable moment: getting the weapon in (Delivery) and making it fire (Exploitation).
Weaponization was invisible. Delivery and exploitation are not — a payload crosses your email gateway, a browser touches a bad site, a process behaves strangely. This is where most attacks are actually caught. Break the chain here and everything downstream never happens.
The Horse at the Gate
Troy's walls stood for ten years. No siege engine broke them. What won the war was a gift — a giant wooden horse wheeled in by the Trojans themselves, because it looked like a trophy, not a threat. That is delivery: the weapon doesn't smash the perimeter, it gets invited through it, disguised as something wanted.
And the horse alone did nothing. It sat there until night, when the hidden soldiers acted — that trigger moment is exploitation. Delivery gets the weapon to the right place; exploitation is the instant it comes alive and turns a harmless-looking object into control of the city.
Swap the horse for an email attachment, a link, a USB stick, or a compromised software update. The psychology is identical — make the target carry the weapon in themselves. Firewalls guard the wall; delivery walks through the gate you hold open every day.
What Delivery Really Is
Delivery is transmission of the weapon to the target environment. The attacker picks a channel the target trusts and rides it inward.
Attackers rarely force their way in. They borrow your trust — the inbox you read, the site you visit, the vendor you update from. Defense means treating every inbound channel as a potential delivery road, not just the obvious ones.
The Delivery Vectors
Human-triggered (email, web, USB) needs someone to act. Machine-triggered (direct network, supply chain) doesn't. Different vectors, different defenses — awareness training vs. patching and segmentation.
Anatomy of a Phishing Delivery
The most common delivery, step by step — and every step is a place to break it.
It targets emotion and routine, not technology — urgency ("account suspended"), authority ("from the CEO"), or habit ("another invoice"). No patch fixes human trust, which is exactly why layered technical defenses have to catch what people miss.
How Delivery Looks in 2024–2025
• Quishing — QR codes in emails to jump to a phone, off the corporate defenses
• Collaboration-app lures — Teams / Slack / chat, not just email
• Malvertising — poisoned search ads for popular software
• Cloud-hosted payloads on trusted domains (SharePoint, Drive)
• Naked .exe attachments — filtered everywhere
• Obvious typo-ridden spam — users & filters learned it
• Internet macros — blocked by default since 2022
Attackers move to whatever still gets trusted
Every new method chases the same goal: reach the user on a channel that isn't being scanned, from a source that is trusted. When email got hard, they moved to QR and chat. Defense has to widen with them — protection can't stop at the inbox.
Breaking the Delivery
It Arrived. Now It Fires.
Delivery only puts the weapon in place. Nothing has happened yet. Exploitation is the instant a flaw is triggered and the attacker's data becomes the attacker's control.
A malicious document sitting in a downloads folder is harmless. The danger is the instant a vulnerable program opens it and mishandles what's inside — that single moment when input the program was only supposed to read ends up steering what it does. That flip is exploitation.
Exploitation always abuses a gap between what software expects and what it actually accepts. Close the gap — patch the flaw, validate the input, sandbox the program — and the delivered weapon is just a dud file.
What Exploitation Is
Exploitation is triggering a vulnerability to make software do something it was never meant to — most often, to run the attacker's code or grant access it shouldn't.
Most real-world exploitation uses known flaws (n-days) with public patches available. The exploit works because the fix wasn't applied. Patching is not housekeeping — it is the single highest-value exploitation defense there is.
What Attackers Exploit
The most common real-world "exploit" isn't a memory-corruption masterpiece — it's a default password or an unpatched public service. Glamour lives in the CVE writeups; breaches live in the basics.
Memory Corruption, in One Picture
The classic memory bug, at concept level: a program sets aside a fixed box for input, but never checks the size. Too much input spills past the box and overwrites the note that says "where to go next."
You don't need to write one to defend it. The takeaway: unchecked input size lets data reach places meant for control. That's why input validation, safe languages, and the memory protections on the next slide exist — they each attack this one idea from a different angle.
Three Places It Happens
Client-side to get in → local privilege escalation to take over → server-side to spread. One exploit is rarely the whole story; defense in depth assumes any single layer will eventually fail.
The Defenses Built Into Modern Systems
Decades of exploitation pushed OS and compiler makers to bake in protections. Each one targets a different step of the attack.
| Protection | What it does | Attack step it breaks |
|---|---|---|
| DEP / NX | Marks data memory as non-executable | Stops delivered data from running as code |
| ASLR | Randomizes where things load in memory | Attacker can't predict the address to jump to |
| Stack canary | Guard value checked before a function returns | Detects the overflow before control transfers |
| CFG / CET | Enforces valid control-flow targets | Blocks jumps to attacker-chosen locations |
| Sandboxing | Isolates risky code (browser tabs, apps) | Contains a successful exploit to a cage |
| Patching | Removes the flaw entirely | There is nothing left to trigger |
No single protection is perfect — attackers find ways around each one. Stacked together they turn a one-step exploit into a chain of hard problems, and every extra step is another chance to fail and get caught. That's defense in depth at the memory level.
A Historical Lesson: The Cursor That Ran Code
Years ago, Windows had a flaw in how it read animated-cursor files. The code that displayed them trusted the file's declared sizes and never validated them. A malformed cursor — delivered simply by viewing a folder or a web page — could spill past its buffer and divert execution. It's the exact picture from two slides back, in a real product used by hundreds of millions.
The fix taught the whole industry three things at once: anything you parse is untrusted input, a flaw in one core library exposes everyone, and a single vendor patch can protect the entire world overnight. It's now a museum piece — which is exactly why it's safe and perfect to teach with.
Modern equivalents still surface in image parsers, fonts, PDF engines, and messaging apps — anywhere software silently opens attacker-supplied files. The bug names change; the lesson (validate input, patch fast, sandbox parsers) does not.
Exploitation Trends Now
• Edge-device n-days — VPNs, firewalls, mail gateways hit within days of a patch
• Living-off-the-land — abuse built-in tools, no custom exploit needed
• Rapid weaponization — public PoC to mass-exploitation in hours
• Identity as the target — steal tokens/sessions instead of memory
• Classic memory exploits — DEP + ASLR + CFG raised the cost
• Browser drive-bys — modern sandboxes are tough
• Commodity exploit kits — largely collapsed
So attackers shifted to identity & unpatched edges
The gap between a patch release and mass exploitation is now measured in hours to days. "We'll patch next maintenance window" is, for internet-facing systems, an invitation. Prioritize exposed and edge devices first.
What Exploitation Looks Like to a Defender
You can't always see the flaw being triggered — but you can see the behavior right after. That's what modern detection watches.
EDR catches the action, not the file. The exploit may be novel and the payload obfuscated, but "Word launched PowerShell that called the internet" is suspicious no matter how it was built. Behavior is the attacker's hardest thing to hide.
Defense in Depth — Layers That Catch
No single control stops everything. The whole chain — delivery through exploitation — is defeated by overlapping layers, each backing up the last.
Assume every layer will eventually fail. Build so that when one does, the next still catches the attack. One control is a wall; layered controls are a maze.
Golden Rules — Both Phases
Break the Chain in the Middle
Delivery gets the weapon in by borrowing your trust; exploitation is the split-second a flaw turns that weapon live. These are the most visible, most defendable phases of the whole chain — filter the channels, patch the flaws, layer the protections, and watch the behavior. Break the chain here and the attacker never reaches installation, persistence, or their goal.
Delivery is the horse at the gate; exploitation is the soldiers climbing out. Next in the kill chain: Installation & Command-and-Control — where the attacker digs in and phones home.
🎯 End of tutorial · Press ← to review, or click Restart