Cyber Security Basics 📂 Slides · 19 of 19 44 min read

Delivery & Exploitation: How Attacks Get In and Fire

A visual, defense-first tutorial on two pivotal cyber kill chain phases. Delivery carries the weapon to the target by borrowing trusted channels — phishing, drive-by, USB, supply chain. Exploitation is the moment a flaw is triggered and input becomes control. Learn the vectors, the trigger, current methods, and every layer of defense.

Delivery & Exploitation

The moment the weapon leaves the workshop. Delivery carries it to the target; Exploitation is the split-second it fires and a flaw becomes a foothold. Learn the channels, the trigger, current methods — and every layer of defense that breaks the chain.
Delivery Vectors Vulnerability Trigger DEP · ASLR · CFG Defense in Depth

Press Next → or use ← → arrow keys

The Big Picture

Phases 3 & 4 of the Kill Chain

Reconnaissance found the target. Weaponization built the weapon. Now the chain reaches its loudest, most catchable moment: getting the weapon in (Delivery) and making it fire (Exploitation).

1 · Reconfind target 2 · Weaponizebuild weapon 3 · Deliveryget it to target 4 · Exploitationflaw fires 5 · Install→ persist You are here → the noisy middle of the chain
🛡️
Why defenders love these two phases

Weaponization was invisible. Delivery and exploitation are not — a payload crosses your email gateway, a browser touches a bad site, a process behaves strangely. This is where most attacks are actually caught. Break the chain here and everything downstream never happens.

Story

The Horse at the Gate

The wall was never breached. The gate was opened from inside.

Troy's walls stood for ten years. No siege engine broke them. What won the war was a gift — a giant wooden horse wheeled in by the Trojans themselves, because it looked like a trophy, not a threat. That is delivery: the weapon doesn't smash the perimeter, it gets invited through it, disguised as something wanted.

And the horse alone did nothing. It sat there until night, when the hidden soldiers acted — that trigger moment is exploitation. Delivery gets the weapon to the right place; exploitation is the instant it comes alive and turns a harmless-looking object into control of the city.

⚠️
The modern version

Swap the horse for an email attachment, a link, a USB stick, or a compromised software update. The psychology is identical — make the target carry the weapon in themselves. Firewalls guard the wall; delivery walks through the gate you hold open every day.

Delivery · Part 1

What Delivery Really Is

Delivery is transmission of the weapon to the target environment. The attacker picks a channel the target trusts and rides it inward.

Attackerholds the weapon Trusted Channelemail · web · USBupdate · message Targetuser / serverreceives it disguised looks trusted The weapon travels a road the target already trusts
🧭
The core insight

Attackers rarely force their way in. They borrow your trust — the inbox you read, the site you visit, the vendor you update from. Defense means treating every inbound channel as a potential delivery road, not just the obvious ones.

Delivery · Part 1

The Delivery Vectors

📧
Email / Phishing
#1 vector
Attachment or link in a message. Still the most common way in — because everyone opens email.
🌐
Malicious Websites
drive-by
A booby-trapped page fires at the browser on visit — no click needed beyond arriving.
💧
Watering Hole
targeted
Compromise a site the target group already visits, and wait for them to come to you.
🔌
Removable Media
USB drop
A "lost" USB stick in a car park. Human curiosity delivers it past every firewall.
📦
Supply Chain
high impact
Poison a trusted software update or dependency; every customer installs it themselves.
🛰️
Direct Network
server-side
Aim straight at an exposed, vulnerable service — no human in the loop at all.
💡
Two families

Human-triggered (email, web, USB) needs someone to act. Machine-triggered (direct network, supply chain) doesn't. Different vectors, different defenses — awareness training vs. patching and segmentation.

Delivery · Part 2

Anatomy of a Phishing Delivery

The most common delivery, step by step — and every step is a place to break it.

1 · The Lure"invoice overdue" 2 · The Trustlooks like a vendor 3 · The Clickuser acts 4 · The Fetchpayload pulled in Lure → Trust → Click → Fetch Break ANY link and the delivery fails
🎣
Why it keeps working

It targets emotion and routine, not technology — urgency ("account suspended"), authority ("from the CEO"), or habit ("another invoice"). No patch fixes human trust, which is exactly why layered technical defenses have to catch what people miss.

Delivery · Current

How Delivery Looks in 2024–2025

📈
On the rise

• Quishing — QR codes in emails to jump to a phone, off the corporate defenses
• Collaboration-app lures — Teams / Slack / chat, not just email
• Malvertising — poisoned search ads for popular software
• Cloud-hosted payloads on trusted domains (SharePoint, Drive)

📉
Fading

• Naked .exe attachments — filtered everywhere
• Obvious typo-ridden spam — users & filters learned it
• Internet macros — blocked by default since 2022
Attackers move to whatever still gets trusted

🧠
The pattern

Every new method chases the same goal: reach the user on a channel that isn't being scanned, from a source that is trusted. When email got hard, they moved to QR and chat. Defense has to widen with them — protection can't stop at the inbox.

Delivery · Defense

Breaking the Delivery

🛡️ STOP THE WEAPON AT THE GATE
1
Secure email gateway — filter attachments, rewrite & detonate links, flag external senders.
2
Strip & rebuild active content (CDR) and honour Mark-of-the-Web so downloaded files stay untrusted.
3
Block risky file types & containers — ISO, IMG, HTA, LNK — before they ever reach a user.
4
Web & DNS filtering — block known-bad and newly-registered domains; isolate risky browsing.
5
Device control — disable USB autorun, restrict removable media.
6
Train the human — the last filter. Report-phish button, real drills, no blame.
The Trigger Moment

It Arrived. Now It Fires.

Delivery only puts the weapon in place. Nothing has happened yet. Exploitation is the instant a flaw is triggered and the attacker's data becomes the attacker's control.

From "a file on disk" to "code that runs."

A malicious document sitting in a downloads folder is harmless. The danger is the instant a vulnerable program opens it and mishandles what's inside — that single moment when input the program was only supposed to read ends up steering what it does. That flip is exploitation.

🔑
The one idea to hold onto

Exploitation always abuses a gap between what software expects and what it actually accepts. Close the gap — patch the flaw, validate the input, sandbox the program — and the delivered weapon is just a dud file.

Exploitation · Part 1

What Exploitation Is

Exploitation is triggering a vulnerability to make software do something it was never meant to — most often, to run the attacker's code or grant access it shouldn't.

Malicious Inputthe delivered file Vulnerable Programmishandles the inputexpectation ≠ reality ✔ Intended path ✗ Hijacked pathattacker's code Input meant to be read ends up steering execution
💡
Success ≠ smart attacker, it = unpatched defender

Most real-world exploitation uses known flaws (n-days) with public patches available. The exploit works because the fix wasn't applied. Patching is not housekeeping — it is the single highest-value exploitation defense there is.

Exploitation · Part 1

What Attackers Exploit

🧠
Memory flaws
Buffer overflows, use-after-free — the program mismanages memory and control flow bends.
🧩
Logic flaws
Auth bypass, path traversal, injection — the code's rules can be tricked without breaking memory.
⚙️
Misconfiguration
Default creds, open shares, exposed admin panels — nothing to "exploit," just walk in.
👤
The human
"Enable content," "allow this app" — the user is persuaded to trigger it themselves.
🎯
Not all exploitation is exotic

The most common real-world "exploit" isn't a memory-corruption masterpiece — it's a default password or an unpatched public service. Glamour lives in the CVE writeups; breaches live in the basics.

Exploitation · Concept

Memory Corruption, in One Picture

The classic memory bug, at concept level: a program sets aside a fixed box for input, but never checks the size. Too much input spills past the box and overwrites the note that says "where to go next."

A fixed box + no size check = spillover data data data ← the box the program reserved → spill spill "Where next?"return pointergets overwritten Controlflow diverts
🧠
The lesson, not the recipe

You don't need to write one to defend it. The takeaway: unchecked input size lets data reach places meant for control. That's why input validation, safe languages, and the memory protections on the next slide exist — they each attack this one idea from a different angle.

Exploitation · Part 2

Three Places It Happens

🖥️
Client-side
needs a user
A browser, PDF reader, or Office app opens attacker content. Paired with phishing delivery. The most common route today.
🛰️
Server-side
no user
An exposed service (web, VPN, mail) is hit directly over the network. No click required — worms and mass-scanners live here.
⬆️
Local / Privilege
already in
Attacker has low access and exploits a local flaw to become admin/root. The bridge from foothold to full control.
🔗
Real attacks chain them

Client-side to get in → local privilege escalation to take over → server-side to spread. One exploit is rarely the whole story; defense in depth assumes any single layer will eventually fail.

Exploitation · Defense

The Defenses Built Into Modern Systems

Decades of exploitation pushed OS and compiler makers to bake in protections. Each one targets a different step of the attack.

ProtectionWhat it doesAttack step it breaks
DEP / NXMarks data memory as non-executableStops delivered data from running as code
ASLRRandomizes where things load in memoryAttacker can't predict the address to jump to
Stack canaryGuard value checked before a function returnsDetects the overflow before control transfers
CFG / CETEnforces valid control-flow targetsBlocks jumps to attacker-chosen locations
SandboxingIsolates risky code (browser tabs, apps)Contains a successful exploit to a cage
PatchingRemoves the flaw entirelyThere is nothing left to trigger
🛡️
Why so many?

No single protection is perfect — attackers find ways around each one. Stacked together they turn a one-step exploit into a chain of hard problems, and every extra step is another chance to fail and get caught. That's defense in depth at the memory level.

Case Study

A Historical Lesson: The Cursor That Ran Code

Even a tiny animation file was "input" — and input wasn't checked.

Years ago, Windows had a flaw in how it read animated-cursor files. The code that displayed them trusted the file's declared sizes and never validated them. A malformed cursor — delivered simply by viewing a folder or a web page — could spill past its buffer and divert execution. It's the exact picture from two slides back, in a real product used by hundreds of millions.

The fix taught the whole industry three things at once: anything you parse is untrusted input, a flaw in one core library exposes everyone, and a single vendor patch can protect the entire world overnight. It's now a museum piece — which is exactly why it's safe and perfect to teach with.

🧭
The through-line to today

Modern equivalents still surface in image parsers, fonts, PDF engines, and messaging apps — anywhere software silently opens attacker-supplied files. The bug names change; the lesson (validate input, patch fast, sandbox parsers) does not.

Exploitation · Current

Exploitation Trends Now

📈
What's growing

• Edge-device n-days — VPNs, firewalls, mail gateways hit within days of a patch
• Living-off-the-land — abuse built-in tools, no custom exploit needed
• Rapid weaponization — public PoC to mass-exploitation in hours
• Identity as the target — steal tokens/sessions instead of memory

📉
What's harder for attackers

• Classic memory exploits — DEP + ASLR + CFG raised the cost
• Browser drive-bys — modern sandboxes are tough
• Commodity exploit kits — largely collapsed
So attackers shifted to identity & unpatched edges

⏱️
The window is shrinking

The gap between a patch release and mass exploitation is now measured in hours to days. "We'll patch next maintenance window" is, for internet-facing systems, an invitation. Prioritize exposed and edge devices first.

Exploitation · Defense

What Exploitation Looks Like to a Defender

You can't always see the flaw being triggered — but you can see the behavior right after. That's what modern detection watches.

🌱
Odd child processes
A document or browser suddenly spawns a script host or shell. Almost never legitimate.
📡
Unexpected network calls
A freshly opened file reaching out to an unknown host to pull the next stage.
🧬
Memory anomalies
Code running from data regions, or a process behaving unlike itself — classic post-exploit signals.
🔎
Why behavior beats signatures here

EDR catches the action, not the file. The exploit may be novel and the payload obfuscated, but "Word launched PowerShell that called the internet" is suspicious no matter how it was built. Behavior is the attacker's hardest thing to hide.

The Model

Defense in Depth — Layers That Catch

No single control stops everything. The whole chain — delivery through exploitation — is defeated by overlapping layers, each backing up the last.

Email / Web filtering Patching & hardening OS protections + sandbox EDR watches Protected asset Each ring the attacker must pass is a chance to be stopped
🧱
The mindset

Assume every layer will eventually fail. Build so that when one does, the next still catches the attack. One control is a wall; layered controls are a maze.

Recap

Golden Rules — Both Phases

🏆 CARRY THESE OUT OF THE ROOM
1
Delivery borrows trust. The weapon rides a channel you already trust — inbox, browser, update, USB.
2
Every inbound channel is a gate. Protection can't stop at email — QR, chat, and ads are gates too.
3
Exploitation abuses a gap between what software expects and what it accepts. Close the gap.
4
Most exploits are n-days. They work because the patch wasn't applied — patch fast, patch edges first.
5
Layers beat any single wall. DEP, ASLR, sandbox, EDR — each a fresh chance to stop the chain.
6
Watch behavior, not just files. "This program did something it never does" is the hardest thing to fake.
FINAL

Break the Chain in the Middle

Phishing#1 delivery vector
n-dayMost exploits, not 0-day
hoursPatch → mass-exploit gap
layersHow you win
🎯
The whole idea

Delivery gets the weapon in by borrowing your trust; exploitation is the split-second a flaw turns that weapon live. These are the most visible, most defendable phases of the whole chain — filter the channels, patch the flaws, layer the protections, and watch the behavior. Break the chain here and the attacker never reaches installation, persistence, or their goal.

🧠
One sentence to remember

Delivery is the horse at the gate; exploitation is the soldiers climbing out. Next in the kill chain: Installation & Command-and-Control — where the attacker digs in and phones home.

🎯 End of tutorial · Press ← to review, or click Restart

You have completed Slides. View all sections →