An exploit broker is an intermediary that buys and sells exploit capabilities, often matching researchers, criminal buyers, and state-aligned buyers in opaque markets. The broker adds liquidity to a market that lacks public pricing, making it harder for defenders to understand demand, value, and likely threat activity.
What an exploit broker does
An exploit broker is not the same as a vulnerability researcher or a simple reseller. The broker sits between supply and demand, turning exploit capabilities into a tradable commodity and often obscuring who ultimately receives the capability.
That intermediary role matters because it changes how exploit value is discovered, packaged, and exchanged. The broker may aggregate proof-of-concept code, working chains, access, or weaponised exploits, then present them to buyers who want speed, discretion, or a specific target fit.
How exploit brokering changes the market
Exploit brokering adds liquidity to a market that is usually fragmented and opaque. Instead of one-off direct deals, brokers can create repeatable channels where researchers, criminal groups, and state-aligned buyers transact through intermediated relationships.
This can widen the reach of a single exploit capability. A broker may not write the exploit, but by finding the right buyer and sometimes the right disclosure timing, the broker can determine whether the capability is used for responsible remediation, espionage, extortion, or broader criminal access.
Why brokers are strategically important
For defenders, the broker matters because it signals demand. If a broker is active around a product class, feature, or exploitation technique, that often suggests the underlying capability has market value and may be operationally useful to multiple threat groups.
Exploit brokering can also shorten the time between discovery and real-world abuse. Public visibility into pricing and ownership is limited, so a broker can help normalise a private market in which the same capability is repurposed across campaigns. Research and incident tracking that capture real exploitation patterns, such as The 52 NHI Breaches Report, are useful for understanding how quickly valuable capabilities tend to move once they become operationally attractive.
What the term means for security teams
Exploit brokering is a reminder that defenders are not only facing isolated attackers, they are facing a market. When exploit supply becomes brokered, security teams should think in terms of demand signals, likely buyer profiles, and the commercial value of a given weakness rather than treating every exploit as a one-off event.
That is why exploitability, active exploitation, and exposure prioritisation matter. A capability that is easy to weaponise, easy to resell, or useful against a widely deployed product can spread quickly once a broker can move it through the right channels. Sources that track active exploitation and prioritisation, such as CISA Known Exploited Vulnerabilities Catalog and FIRST EPSS, help frame that market pressure more realistically than raw vulnerability counts alone.
Risk and Threat Considerations
Exploit brokers increase the risk that a newly discovered weakness becomes monetised before defenders can respond. They also make it easier for multiple buyers to obtain the same capability, which can accelerate exploitation, broaden targeting, and reduce the chance that a single disclosure cycle contains the damage.
Failure mechanism: A broker concentrates access to weaponised capability, then matches it to buyers who value speed, stealth, or target specificity. That market structure can preserve exploit secrets, hide buyer intent, and keep dangerous chains circulating after defenders believe a patch window has closed.
Impact: Organisations may face faster exploitation, wider campaign repetition, and more uncertainty about who can access a working exploit. The result is a harder prioritisation problem for patching, exposure management, and threat hunting, especially when the exploit is already present in active vulnerability catalogs or exploitation intelligence feeds.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1588.005 — Exploit Development | Exploit brokering depends on monetised exploit capability as an attacker resource. |
| T1595 — Active Scanning | Brokered exploits often follow exposure discovery and target selection before use. | |
| Recommendation — Track exploit acquisition patterns as attacker capability development and prioritise exposed systems accordingly. Correlate scan activity with vulnerable assets to detect likely brokered-exploit targeting. | ||
| CIS Controls v8 | CIS-7 — Continuous Vulnerability Management | Exploit brokers raise the value of rapidly exploitable weaknesses that need continuous prioritisation. |
| Recommendation — Prioritise remediation based on exploitability and active threat use, not just CVSS. | ||
| NIST SP 800-53 Rev 5 | RA-5 — Vulnerability Monitoring and Scanning | Brokered exploits make timely vulnerability discovery and response materially more urgent. |
| Recommendation — Continuously monitor exposed assets and rapidly act on vulnerabilities with likely exploitation paths. | ||
| NIST CSF 2.0 | ID.RA-01 — Vulnerabilities are identified and documented | Exploit brokerage changes which vulnerabilities become strategically important to document and track. |
| Recommendation — Document exploitable weaknesses and tie them to threat intelligence for prioritisation. | ||
Practitioner Guidance
Why practitioners should care: Treat exploit-broker activity as a demand indicator, not just a criminal trade curiosity. When a broker appears around a product or technique, it is often a sign that the capability is valuable enough to be operationalised by more than one threat actor.
What to watch for: Prioritise weaknesses that are both exploitable and marketable, especially those with public proof-of-concept code, clear remote execution paths, or confirmed active exploitation. Practitioner triage is stronger when it combines exploitability data, exposure data, and active-threat reporting rather than relying on severity scores alone.
Practitioner takeaway: A brokered exploit market means your response window is governed as much by attacker economics as by technical severity.
Related resources from NHI Mgmt Group
- How should security teams handle a cloud exploit that may have abused NHI credentials?
- What breaks when a vulnerability is judged hard to exploit but AI can chain exploitation automatically?
- How should security teams govern third-party access when OAuth is abstracted away by a broker?
- How should security teams reduce lateral movement risk after a fast exploit chain succeeds?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org