# Zero-Day Exploit **Entity class:** Cyber capability **Domain:** Cybersecurity / vulnerability exploitation **Maturity:** Developed ## Definition A **zero-day exploit** is code or a technique that takes advantage of a hardware, firmware, or software vulnerability before defenders have an effective patch or established detection. NIST defines a zero-day attack as one exploiting a previously unknown vulnerability. ## Counterterrorism Relevance Zero-days can provide access to communications, identities, financial systems, logistics, media channels, operational technology, or critical infrastructure. That makes the cyber layer structurally relevant to [[wiki/Counterterrorism|counterterrorism]] and [[wiki/Cyberterrorism|cyberterrorism]], not a decorative add-on. The same capability can be used by states, criminals, researchers, vendors, intelligence services, or terrorists; attribution and intent must be established independently. Zero-day defense includes attack-surface reduction, secure design, segmentation, least privilege, monitoring, incident response, threat intelligence, rapid patching once a fix exists, and resilience when prevention fails. ## Relationships - **security domain:** [[wiki/Cybersecurity|Cybersecurity]]. - **potential operational use:** [[wiki/Cyberterrorism|Cyberterrorism]]. - **detection layer:** [[wiki/Real-Time Observability|Real-Time Observability]]. - **can enable:** data theft affecting [[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]] or disruption of critical infrastructure. ## Sources / Provenance - [NIST Computer Security Resource Center — zero-day attack](https://csrc.nist.gov/glossary/term/zero_day_attack) - [CISA — Cyber Storm VIII after-action report](https://www.cisa.gov/sites/default/files/2023-02/final-cyber-storm-viii-after-action-report-082022.pdf)