Look for a small intersection between affected software exposure and observed communications with campaign indicators. If only a narrow set of hosts both appear vulnerable and show traffic related to the exploit activity, that suggests limited scope. Sparse overlap does not prove safety, but it is a strong signal that the campaign may be more targeted than broad opportunistic scanning.
When the Signal Looks Narrow Rather Than Broad
The most useful indicator is a small overlap between the vulnerable population and the systems actually showing exploit-related activity. If only a limited set of hosts both match the affected version or exposure profile and exhibit communications linked to the campaign, the pattern is more consistent with targeted abuse than with indiscriminate Internet-wide exploitation.
That distinction matters because zero-days often move from a tightly scoped initial phase to wider opportunistic scanning only after proof of exploitation spreads. A narrow intersection suggests the attacker may be selecting victims by product mix, exposure path, or follow-on value rather than blasting every reachable instance.
Limited scope also becomes more plausible when the traffic pattern is specific and repeatable, but not broadly distributed across the installed base. For example, a small number of destinations, a narrow set of user agents or beaconing behaviours, and weak presence in general scan telemetry all point away from mass exploitation and toward a campaign with bounded reach.
What Changes the Assessment From “Limited” to “Widespread”
The assessment should shift if the overlap grows across unrelated networks, geographies, or operating patterns, or if the same indicators appear on many hosts with no common operational profile. At that point, the issue is no longer just whether the software is vulnerable, but whether exploitation is propagating beyond a few early targets.
Widespread exploitation usually shows up as an expanding victim set, more generic scanning, and campaign infrastructure that no longer looks selective. If the same exploit-related signals begin appearing across many environments that share only the product exposure, assume the campaign has moved beyond a narrow operation and treat the signal as broadening, even if the absolute number of confirmed compromises is still modest.
For exposure triage, it is also useful to separate affected product data from observed exploitation, because presence in a vulnerability list does not prove active abuse. The practical question is whether your own telemetry shows a meaningful intersection between exposure and campaign indicators, not just whether the software is named in a bulletin.
Reading the Evidence Without Overcalling It
Limited exploitation is a signal, not a guarantee. Sparse overlap can still reflect delayed detection, partial visibility, or attacker patience, especially when the zero-day is valuable or the target set is intentionally small.
Correlating exposure with observed traffic is more reliable when the indicators come from multiple sources, such as endpoint telemetry, proxy logs, DNS records, and external reporting on exploitation. Public prioritisation sources such as FIRST EPSS and the CISA Known Exploited Vulnerabilities Catalog help you frame likelihood and confirmed abuse, but local evidence still decides whether your environment is seeing a narrow campaign or a broader one.
When the evidence set is thin, avoid treating the absence of widespread signals as proof of safety. The better conclusion is that exploitation currently appears constrained, which justifies focused containment and continued monitoring rather than complacency.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-01 — Asset Vulnerabilities Are Identified and Recorded | Exposure assessment depends on identifying which hosts are vulnerable. |
| DE.CM-01 — Networks and Network Services Are Monitored | Exploit-related traffic is a core signal for judging campaign scope. | |
| Recommendation — Inventory exposed systems and record which ones match the vulnerable version. Monitor network telemetry for exploit-related communications and spread. | ||
| CIS Controls v8 | CIS-7 — Continuous Vulnerability Management | Prioritising a zero-day response depends on knowing where vulnerable software exists. |
| Recommendation — Continuously identify and prioritise hosts running the affected software. | ||
| MITRE ATT&CK | T1190 — Exploit Public-Facing Application | An ITSM zero-day is commonly assessed through public-facing exploitation patterns. |
| Recommendation — Map observed access patterns to public-facing exploitation activity and hunt for additional victims. | ||
| NIST SP 800-53 Rev 5 | RA-5 — Vulnerability Monitoring and Scanning | The question relies on combining vulnerability exposure with observed exploitation. |
| Recommendation — Correlate vulnerability data with threat telemetry to gauge exploitation scope. | ||
Practitioner Guidance
What to prioritise: Start with the hosts that sit in the intersection of known exposure and observed campaign traffic. Those systems deserve faster validation, containment, and patching than the rest of the population because they have the strongest evidence of being in the active blast radius.
What to verify: Confirm whether the same indicators recur across independent log sources and whether the traffic is attributable to the exploit campaign or to unrelated noise. If the overlap is only present in one telemetry stream, treat the conclusion as provisional.
Decision rule: If the affected host set stays small and the indicators remain narrowly patterned, handle the event as targeted exploitation with close watch. If the overlap expands quickly or the traffic becomes generic across many exposed systems, reclassify it as broader exploitation and accelerate enterprise-wide response.
Practitioner takeaway: The key judgment is not whether the zero-day exists, but whether your own data shows a tight coupling between exposure and malicious activity, because that coupling is what distinguishes a contained campaign from a spreading one.
Related resources from NHI Mgmt Group
- What are the signs that a SharePoint zero-day exploitation campaign is succeeding?
- What are the signs that a gateway zero-day may already be under active exploitation?
- What are the signs that Exchange zero-day exploitation may already be happening?
- How should security teams respond to browser zero-day exploitation in identity-heavy environments?