Module 06: Exploit and Vulnerability Brokers
Exploit and zero-day supply layer enabling credential-free intrusion paths. Node 16 in the EDP Dependency Map, assessed CRITICAL tier with HIGH replace difficulty.
CRITICAL TierNode 16 / M06Phase PDownload PDF
Position in Ecosystem: Node 16, Exploit Brokers Open the full ecosystem map ↗
Exploit-driven intrusions can be converted into validated access sold by IABs.Initial Access BrokersPrimary dependencyExploit-sourced access can feed RaaS operators directly when speed or target value justifies bypassing markets.RaaS OperatorPrimary dependencyExploit footholds may be followed by loader deployment to scale persistence and downstream monetization.Loaders & BotnetsPartial dependencyExploit and zero-day supply layer enabling credential-free intrusion paths.EXPLOIT BROKERSNode 16 / M06CRITICAL TIER / REPLACE: HIGH
Primary dependency Partial dependency State protection / dual use First-degree connections as assessed in the current ecosystem map (v3.0). Hover any node for the dependency note. Left side: what this node draws on or is protected by. Right side: what depends on it.
Module Number06
Module NameExploit and Vulnerability Brokers
EDP Node ReferenceNo dedicated node — cross-reference Nodes 04, 05, 07; new node recommended (see Section 8)
Ecosystem LayerInitial Access Enablement / Pre-IAB Supply
Upstream ConnectionsCriminal vulnerability research community; state-adjacent researchers; gray-market exploit vendors (Zerodium, Crowdfense); legitimate bug bounty ecosystem (supply overspill)
Downstream ConnectionsNode 04 (IABs — exploits enable credential-free access acquisition), Module 07 (RaaS Groups — direct buyers for mass exploitation campaigns), Node 05 (Loaders/Botnets — exploit-based malware delivery)
Research DateApril 2026
Primary ResearcherReno
Source Tools UsedPerplexity AI; ThreatDown/Malwarebytes; Cyfirma; Dark Reading; SecurityAffairs; DeepStrike; IBM; Wikipedia; ManageEngine
ClassificationINTERAGENCY

Section 1: What It Is

Definition

Exploit and vulnerability brokers are intermediaries who buy, sell, or broker access to zero-day exploits and unpatched vulnerability intelligence for profit. They operate across a spectrum from legitimate government-facing vendors to gray-market brokers and criminal dark web operators. For EDP purposes, this module focuses on the criminal and gray-market segment: entities that knowingly supply exploit capability to ransomware groups, IABs, or other threat actors operating against Western targets. CONFIRMED

A zero-day exploit weaponizes an unknown or unpatched software vulnerability. Unlike credential-based access (the IAB model), zero-day exploits do not require prior credential acquisition — they enable direct, authenticated access to targeted systems through software flaws. This capability is qualitatively more powerful than stealer-log-derived access and enables mass exploitation of entire software user populations simultaneously. CONFIRMED

How It Functions: Step-by-Step

Role in the Ransomware Ecosystem

Exploit brokers sit upstream of IABs in the supply chain, enabling access acquisition that bypasses the credential-based model entirely. The mass exploitation model — best exemplified by CL0p's industrial-scale 0-day campaigns against MOVEit and GoAnywhere MFT — demonstrates that a single 0-day purchase can generate access to thousands of organizations simultaneously, replacing what would otherwise require months of IAB market activity. This capability makes exploit brokers a force multiplier for the entire ransomware supply chain. CONFIRMED

Critically, the exploit broker layer also enables ransomware groups to bypass the IAB market entirely for specific campaigns. This has structural implications for disruption: degrading Node 04 (IABs) without also addressing the exploit supply layer leaves a high-capacity alternative access pathway intact. ANALYST INFERENCE

Market Segments

Section 2: Key Actors and Examples

Named Actors and Archetypes

Actor / ArchetypeTypeKey RoleConfidence
Zerodium / Crowdfense / Exodus Intelligence (government-facing brokers)Legitimate / gray-market brokersAcquire 0-days from researchers; sell to government intelligence and LE agencies. Set reference pricing for the entire 0-day market. Do not formally service criminal buyers, but their pricing tiers inform criminal market expectations.CONFIRMED
CL0p (TA505) (direct-acquisition mass exploitation operator)RaaS group acting as exploit buyer and deployerAcquires enterprise software 0-days (MOVEit, GoAnywhere MFT, Accellion FTA) directly from researchers or brokers. Deploys at industrial scale against thousands of organizations in a single campaign. Estimated ~$100M+ from MOVEit campaign alone.CONFIRMED
Criminal forum exploit brokers (Exploit.in / XSS / RAMP operators)Dark web exploit market intermediariesFacilitate exploit transactions in RU-language criminal forums. Post "seeking" threads on behalf of ransomware groups; match buyers with sellers. High-value deals moved off-forum to encrypted channels.CREDIBLE
Anonymous vulnerability researchers (dark web sellers)Individual exploit developersSecurity researchers who sell discoveries to criminal markets rather than bug bounty programs for higher returns. May sell non-exclusively to multiple buyers, reducing exploit value but maximizing revenue.CREDIBLE
State-adjacent exploit brokers (FSB-affiliated or protected)Gray-market / state-adjacent suppliersBrokers operating with implicit Russian state knowledge or protection. May supply both FSB/GRU operations and criminal ransomware groups. Represents the highest-risk attribution target due to Dark Covenant protections.ANALYST INFERENCE

Notable Exploit Deployments — Case Examples

Exploit / CVEDeploying GroupImpact ScaleOutcome
MOVEit Transfer 0-day (CVE-2023-34362)CL0p (TA505)Approx. 2,000+ organizations across 60+ countries; multiple critical infrastructure sectorsCL0p estimated $100M+ in extortion revenue; multiple CISA/FBI advisories; widely considered highest-impact single 0-day ransomware campaign to date
GoAnywhere MFT 0-day (CVE-2023-0669)CL0p (TA505)Approx. 130 organizations within 10 days of exploitationDemonstrated CL0p model of rapid mass exploitation; enterprise file-transfer software targeted pattern established
Accellion FTA 0-day (CVE-2021-27101 etc.)CL0p (TA505)Approx. 100+ organizations globallyPrecursor to MOVEit model; established CL0p as specialist in file-transfer software 0-day exploitation
Log4Shell (CVE-2021-44228)Multiple groups including ransomware affiliatesHundreds of millions of vulnerable instances; exploited within hours of public disclosureDemonstrated speed-of-exploitation dynamic; ransomware groups exploited within days; patch adoption lagged months

All case examples above: CONFIRMED Sources: Cyfirma, ThreatDown, SecurityAffairs, multiple vendor advisories.

Market Pricing Tiers

Exploit CategoryCriminal Market RangeGovernment-Facing Range (Zerodium / Crowdfense)Confidence
Critical infrastructure / ICS 0-days$2.5M–$10M+$1M–$2.5M (classified ceiling unknown)CREDIBLE
iOS / Android full-chain 0-days$1M–$3M$2.5M (Zerodium published pricing)CONFIRMED
Browser 0-days (Chrome, Firefox)$500K–$1.5M$500K (Chrome renderer — Zerodium published)CONFIRMED
Enterprise software 0-days (file transfer, VPN, cloud)$100K–$1M$100K–$500K depending on user baseCREDIBLE
Network device 0-days (firewalls, VPN appliances)$50K–$500K$50K–$250KCREDIBLE
Dated CVE exploits (known but unpatched env.)$5K–$50KNot typically acquired (patched vulnerability)CREDIBLE

Note: Criminal market pricing is derived from dark web market reporting (SecurityAffairs, DeepStrike). Verified transaction prices are rarely observable; figures represent reported ranges. Government-facing pricing based on Zerodium published acquisition schedule and Crowdfense public statements.

Geographic Concentration

The criminal exploit broker market is concentrated in RU-language dark web forums, with significant additional supply from Eastern European, Chinese, and Middle Eastern research communities. Russia and CIS-based operators dominate the market for enterprise software and network device exploits most relevant to ransomware operations. CREDIBLE

Russian state intelligence services (FSB, GRU, SVR) are known to maintain parallel vulnerability research and acquisition operations, creating a structural overlap between state and criminal exploit supply chains. Some criminal-market exploit brokers may operate with implicit FSB awareness or protection, particularly for high-value enterprise 0-days. Dark Covenant 3.0 screening required before any attribution of Russia-based exploit brokers. ANALYST INFERENCE

Scale and Market Dynamics

MetricValueSourceYear
MOVEit 0-day victim countApprox. 2,000+ organizations, 60+ countriesCyfirma, ThreatDown, multiple advisories2023
CL0p estimated MOVEit campaign revenue~$100M+ in extortion receipts (estimated)Multiple threat intelligence vendors2023
Ransomware use of 0-day exploits (DBIR 2024)Vulnerability exploitation grew 180% as initial access vector YoYVerizon DBIR 2024 (via ThreatDown)2024
Highest reported criminal 0-day priceUp to $10M for critical infrastructure targetsSecurityAffairs2024–2025
Zerodium iOS full-chain acquisition price$2.5M (published)Zerodium published acquisition schedule2023–2025
Log4Shell CVE instances at disclosureHundreds of millions of vulnerable instancesIBM, multiple vendors2021
Ransomware groups actively seeking 0-daysMultiple RaaS programs posting "seeking" threads on Exploit.in, XSS, RAMPCyfirma dark web analysis2023–2025

State Adjacency

The exploit broker market has a higher degree of state adjacency than any other EDP node. Russian state intelligence services maintain active vulnerability research programs and are known to retain discovered 0-days for operational use rather than reporting them to vendors. The overlap between state and criminal exploit supply chains means that criminal exploit brokers may simultaneously or sequentially supply both FSB/GRU operations and ransomware groups. CREDIBLE

This dual-supply dynamic is the primary source of the MEDIUM backfire risk for any disruption action targeting exploit brokers — higher than any other Phase B or C node. Attribution of criminal exploit brokers without prior confirmation that the broker does not hold an FSB or GRU relationship carries a real risk of inadvertently exposing protected assets or triggering a protection reflex. Dark Covenant 3.0 screening is not just recommended — it is operationally mandatory before any public attribution in this node. ANALYST INFERENCE

Section 3: Infrastructure Dependencies

Upstream Dependencies

Downstream Outputs

Critical Chokepoints

ChokepointWhy CriticalWho Owns Disruption
Software vendor patch velocityThe single most effective exploit mitigation is patching. Every day a critical vulnerability remains unpatched is a day it can be sold and deployed. Reducing average time-to-patch from 30+ days to <7 days fundamentally degrades the exploit value proposition.CISA (KEV catalog), NIST (NVD), software vendors, enterprise IT operations — not LE or IC
Bug bounty economics gapWhen criminal market prices routinely exceed vendor bug bounty caps by 10x–100x, researchers rationally sell to criminal markets. Closing this gap would reduce supply overspill without any law enforcement action.Software vendors (Microsoft, Google, Apple, Cisco) and bug bounty platforms (HackerOne, Bugcrowd) — not LE
Forum "seeking" thread infrastructureCriminal forum threads advertising 0-day acquisition intent provide early warning of attack campaigns and matchmaking infrastructure for broker-to-buyer transactions. Disrupting this reduces transaction discovery and increases buyer sourcing overhead.FVEY LE + Intel 471, Flashpoint (forum monitoring and infiltration)
RaaS group exploit acquisition pipeline (direct)High-value RaaS groups (CL0p model) maintain near-exclusive researcher relationships outside the open market. This pipeline is opaque and not forum-observable; disruption requires intelligence-level penetration.FVEY IC (signals intelligence, human intelligence) — not traditional LE action

Cross-Module Linkages

ModuleNodeRelationshipDirection
05 — IABsNode 04Exploits enable IABs to acquire privileged access without credential sourcing; boutique IABs may use 0-days for domain admin accessUpstream to IABs
07 — RaaS GroupsNonePrimary direct buyers; 0-day acquisition enables mass exploitation campaigns that bypass IAB market entirely (CL0p model)Upstream to RaaS
02 — LoadersNode 05Exploits enable drive-by malware delivery; browser and OS 0-days used in loader delivery chainsUpstream to Loaders
10 — Underground ForumsNode 07Forum infrastructure provides "seeking" thread matchmaking and escrow for criminal exploit transactionsUpstream to Exploit Brokers
12 — OTC BrokersNode 01High-value exploit transactions require OTC intermediation for fiat conversion of cryptocurrency proceedsDownstream from Exploit Brokers

Technical Infrastructure

Unlike most EDP nodes, the exploit broker layer does not depend on stable physical infrastructure. Brokers operate through encrypted messaging channels (Telegram, TOX, Signal), forum accounts, and cryptocurrency wallets. The intellectual property (the exploit itself) is typically delivered as a code file or proof-of-concept demonstration and requires no ongoing infrastructure to maintain value. This absence of persistent infrastructure dependency makes the exploit broker layer uniquely resistant to infrastructure-based disruption.

The transient infrastructure profile of exploit brokers means that standard FVEY LE tools — sinkholing, domain seizure, BPH pressure — are largely inapplicable. The primary disruption vectors are economic (bug bounty economics, financial designation) and intelligence-based (early warning, attribution, monitoring) rather than infrastructure-focused. ANALYST INFERENCE

Section 4: Disruption Leverage Points

EDP Node Reference

No dedicated node in current Dependency Map. Cross-reference: Nodes 04, 05, 07. Recommended new node: Exploit/Vulnerability Markets — see Section 8. Assessed tier: CRITICAL. Backfire: MEDIUM.

The CRITICAL tier assessment reflects the mass exploitation capability enabled by this node. A single well-placed 0-day purchase can produce thousands of victim accesses in days — a capability that no other node in the map approaches in per-unit impact. The MEDIUM backfire risk is unique in the EDP framework: it reflects state adjacency rather than operational concern. ANALYST INFERENCE

Primary Disruption Levers

Who Owns Disruption

LeverBest MethodPrimary OwnerBackfire Risk
Patch velocity accelerationCISA KEV catalog enforcement; federal procurement mandates; vendor-direct patch deployment acceleration programsCISA + software vendors (non-IC, non-LE)LOW
Bug bounty economics reformVendor-side bounty cap increases for critical infrastructure-relevant 0-days; coordinated industry actionSoftware vendors, HackerOne, Bugcrowd (non-government action)LOW
Forum "seeking" thread disruptionNode 07 coordinated takedown of exploit-specific market sections on RAMP, DarkForums, XSSFVEY LE + Intel 471, FlashpointLOW
Financial designation (criminal brokers — post-screening)Dark Covenant screening first; OFAC SDN designation for confirmed criminal-only operators; USDT/crypto tracingOFAC + Chainalysis, TRM Labs (post-screening only)MEDIUM (screening mandatory)
Intelligence early warning (RaaS 0-day acquisition)SIGINT/HUMINT monitoring of RaaS-researcher channels; pre-deployment victim notification via CISA/sector CERTsFVEY IC (NSA, GCHQ, CSE)LOW (passive, non-attributive action)

Compounding Actions

Section 5: Resilience and Replace Difficulty

Assessed Replace Difficulty: HIGH

Unlike most EDP nodes where replace difficulty is measured by infrastructure or forum reconstitution time, exploit broker replace difficulty is determined by the intellectual labor required to produce a new 0-day. A disrupted broker cannot simply stand up a new forum account — the supply input (the exploit itself) must be newly discovered and weaponized. This makes the exploit broker layer uniquely resilient in one dimension (the supply process cannot be seized or sinkholed) and uniquely fragile in another (once patched, an exploit is permanently worthless). CONFIRMED

Resilience Factors

Historical Reconstitution

Disruption EventOutcomeReconstitution Assessment
Zerodium price cap reductions (selective, 2019–2023)Some researchers shifted to Crowdfense, gray-market buyers, or criminal markets; supply did not leave market, it redirectedImmediate (days to weeks) — supply redirected, not disrupted
Hacking Team breach (2015) — state broker infrastructure exposedHacking Team operations collapsed; tools and clients exposed; criminal adoption of leaked exploits followed6–12 months for equivalent state broker to emerge; leaked tools immediately adopted by criminal community
Shadow Brokers release of NSA tools (2017)EternalBlue and DoublePulsar became foundation of WannaCry and NotPetya; criminal exploit capability surgedN/A — disruption event increased criminal capability rather than degrading it; patching was the only effective response

Historical note: Both major exploit broker exposure events (Hacking Team, Shadow Brokers) resulted in criminal capability increase, not decrease, due to immediate adoption of leaked material. This is a key asymmetry unique to the exploit broker node.

Durability Assessment

FactorAssessmentConfidence
Technical barrier to supply (discovery)HIGH — requires deep technical skill; global researcher population but elite tier is smallCONFIRMED
Infrastructure dependencyLOW — brokers operate through messaging apps and forum accounts; no stable infrastructure to seizeCONFIRMED
Geographic concentration (primary criminal supply)Russia/CIS dominant; high state protection likely for top-tier researchers; limited Western LE reachCREDIBLE
Price differential persistenceHIGH — criminal prices routinely exceed bug bounty caps by 10x–100x; no evidence this gap is closingCONFIRMED
Patch velocity as countermeasureMEDIUM effectiveness — CISA KEV improves enterprise patching; but patch adoption averages 30–60 days; window remains exploitableCONFIRMED
State adjacency as resilience factorHIGH — implied FSB/GRU protection likely extends to top-tier researchers; attribution risk is realANALYST INFERENCE

Ecosystem Adaptation

The exploit broker ecosystem adapts to disruption differently from all other EDP nodes. Forum takedowns shift transactions to encrypted channels but do not reduce supply or demand. Financial designation of individual brokers shifts buyers to new brokers but does not reduce the researcher incentive to sell. The only disruption vectors that do not trigger market-equivalent adaptation are patch velocity acceleration (degrades all exploit value simultaneously) and bug bounty economics reform (alters researcher incentive structure). ANALYST INFERENCE

The CL0p mass exploitation model also reveals a critical ecosystem evolution: when a ransomware group acquires 0-day research capability internally or through near-exclusive researcher relationships, the criminal broker market becomes irrelevant for that group's access acquisition. This off-market evolution is not observable through standard forum monitoring and represents a growing blind spot. CREDIBLE

Section 6: Indicators and KPIs

Health Indicators

IndicatorNormal StateUnder Pressure
Forum "seeking 0-day" thread volume (Exploit.in, XSS, RAMP, DarkForums)Regular postings from RaaS affiliates and IABs seeking specific exploit types30%+ decline in seeking thread volume — may indicate off-forum migration or demand reduction
Mass exploitation campaign frequency (CL0p-model events)Periodic large-scale campaigns (1–3 per year, CL0p model); targets file transfer and enterprise softwareAbsence of campaigns: may indicate supply disruption OR successful early warning (victim patching). Spike: indicates new 0-day acquisition.
Time-to-exploitation after CVE disclosureDays to weeks for commodity CVEs; near-zero for pre-disclosure 0-daysLengthening time-to-exploitation signals either improved patch velocity or reduced exploit market activity
Criminal market pricing trendsPrices stable or rising; $100K–$1M for enterprise software; $10M+ ceiling for critical infraSudden price drops may signal increased supply; sudden spikes signal scarcity
Bug bounty vs. criminal market price gapCriminal prices 10x–100x above vendor bounty caps for enterprise software exploitsGap narrowing signals effective bug bounty reform — a positive indicator for disruption
Volume of known state-attributed 0-day useModerate; FSB/GRU/APT groups use 0-days in parallel to criminal marketSpike in state-attributed 0-day use may signal criminal market supply disruption (criminal groups unable to acquire; state groups unaffected)

Disruption KPIs

KPIBaselineTargetCollection Method
Average enterprise patch deployment time (critical CVEs)30–60 days average post-disclosureBelow 14 days for CISA KEV itemsCISA KEV catalog tracking; Qualys/Tenable patch velocity data
Bug bounty cap vs. criminal market ratio (enterprise software)Criminal prices 10x–100x above bug bounty capsRatio below 5x for enterprise software categoryVendor bounty program published pricing; dark web market monitoring
Forum "seeking 0-day" thread volume (monthly)Establish from Exploit.in/XSS/RAMP/DarkForums monitoring30% reduction sustained over 60 daysIntel 471, Flashpoint, Recorded Future forum monitoring
Mass exploitation campaign frequency (CL0p-model)Approx. 1–3 large campaigns per year (2021–2024 baseline)0 confirmed new campaigns in rolling 12-month windowCISA advisories, FBI flash reports, vendor IR reporting
Time-to-exploitation after disclosure (enterprise software CVEs)Days to weeks (commodity CVEs); near-zero (0-days)Average time-to-exploit >30 days for most CVEsCISA KEV, Qualys ThreatPROTECT, Mandiant/CrowdStrike CTI

Collection Methods

Baseline Data

MetricValueSourceDate
MOVEit 0-day victimsApprox. 2,000+ organizationsCyfirma, ThreatDown2023
CL0p MOVEit estimated revenue~$100M+ (estimated)Multiple vendors2023
Vuln exploitation growth (DBIR)+180% YoY as initial access vectorVerizon DBIR 20242024
Highest reported criminal 0-day priceUp to $10M (critical infrastructure targets)SecurityAffairs2024–25
Zerodium iOS full-chain price$2.5M (published)Zerodium2023–25
Average enterprise patch deployment30–60 days post-disclosureQualys, Tenable (industry)2023–25
Log4Shell exploitable instancesHundreds of millions at disclosureIBM, multiple vendors2021

Alert Thresholds

IndicatorAlert ThresholdPriority
New large-scale exploitation campaign (file transfer, VPN, enterprise software)First credible report of mass exploitation of any widely-used enterprise softwareCRITICAL — CISA KEV immediate, sector CERT notification, victim outreach
Forum "seeking 0-day" thread spike>50% increase in seeking thread volume over 30-day baselineHIGH — signals imminent acquisition and deployment planning
CISA KEV addition (actively exploited)Any addition of enterprise software CVE not yet at 80% patch deploymentHIGH — exploitation window is active
Criminal market price spike>100% price increase for any exploit category (scarcity or high-demand signal)MEDIUM — may indicate specific RaaS group preparation for major campaign
CL0p or CL0p-model group forum activityAny forum signals of CL0p seeking enterprise file-transfer or managed file-transfer software 0-daysCRITICAL — historical pattern of rapid deployment following acquisition

Section 7: Sources and Confidence

Primary Sources

Secondary Sources

Gaps and Uncertainties

Confidence Notes

ClaimConfidenceBasis
MOVEit 0-day (CVE-2023-34362) compromised approx. 2,000+ organizationsCONFIRMEDMultiple independent vendor reports; CISA advisories; FBI flash reports
Verizon DBIR 2024: vulnerability exploitation +180% YoY as initial access vectorCONFIRMEDVerizon DBIR 2024 primary dataset (via ThreatDown reporting)
Criminal 0-day prices up to $10M for critical infrastructure targetsCREDIBLESecurityAffairs single-source; consistent with Zerodium government-tier pricing but criminal transaction verification unavailable
Zerodium iOS full-chain acquisition price: $2.5MCONFIRMEDZerodium published acquisition schedule (public)
CL0p estimated MOVEit campaign revenue ~$100M+CREDIBLEMultiple vendor estimates; no verified payment records; figure is aggregate inference
Criminal market prices routinely exceed vendor bug bounty caps by 10x–100xCONFIRMEDZerodium/Crowdfense published pricing vs. HackerOne/Bugcrowd program caps; multiple vendor reports
State-adjacent exploit brokers may supply both FSB/GRU operations and criminal groupsANALYST INFERENCEStructural inference from observed state-criminal overlap in other EDP nodes; no confirmed dual-supply reporting for exploit brokers specifically
CL0p maintains near-exclusive researcher relationships outside the open criminal marketCREDIBLEInferred from consistency and novelty of CL0p exploit acquisitions; single-source analyst assessments; no direct confirmation

Section 8: Analyst Assessment

Generated by Claude (Anthropic) — April 2026 | EDP Module 06 — Exploit and Vulnerability Brokers

Key Takeaway

The exploit broker layer is the highest-impact, lowest-interdictability node in the ransomware supply chain. A single 0-day acquisition by CL0p produced more victim access than months of IAB market activity across the entire ecosystem. The absence of this node from the current Dependency Map is the most significant structural gap in the EDP framework. More critically, the primary disruption levers for this node — patch velocity and bug bounty economics reform — are not law enforcement or intelligence actions. They are software industry and government procurement actions. This requires a different set of owners and mechanisms than any other module in the project. ANALYST INFERENCE

Priority Recommendation

Two distinct action streams are required, operating on different timelines:

Critical Node Map Gap

The absence of an Exploit/Vulnerability Markets node from the current Dependency Map creates a structural analytical gap with direct operational consequences. Node 04 (IABs) is rated Phase B, implying it is a priority interdiction target. But if CL0p-model groups can bypass Node 04 entirely through 0-day acquisition, degrading Node 04 without addressing exploit supply leaves the highest-impact access pathway intact. The playbook phases assume IAB access as the primary intrusion pathway — this assumption requires revision. ANALYST INFERENCE

Connection to EDP Playbook

The exploit broker node does not map cleanly to Phase A, B, or C as currently structured. Phase A targets financial and infrastructure foundation; Phase B targets market and trust infrastructure; Phase C targets delivery and monetization. Exploit brokers are pre-Phase B — they supply the capability that makes Phase B markets valuable. The recommended insertion point is a new Phase A+ or Phase B-pre designation: exploit broker disruption should be initiated simultaneously with Phase A financial pressure, not sequenced after it.

The MEDIUM backfire risk for this node is the highest in the Phase B/pre-B range and is driven entirely by state adjacency considerations. This is distinct from every other EDP node where backfire risk reflects operational concern. The state adjacency risk means that Dark Covenant 3.0 screening is not just recommended — it is a hard prerequisite for any attribution action in this node.

Dependency Map Update Recommendations

NodeCurrent StatusRecommended UpdateRationale
New dedicated node: Exploit / Vulnerability MarketsNot in Dependency MapAdd as new node — recommended designation: Node 16 (or renumber as Phase A+ element). Tier: CRITICAL. Replace Difficulty: HIGH. Backfire: MEDIUM. Primary Owner: CISA + FVEY IC; secondary: FVEY LE for criminal-facing brokers only (post-screening). Phase: A+ (pre-Phase B insertion)Absence of this node is the most significant structural gap in the EDP framework. Mass exploitation capability (CL0p model) cannot be addressed by any existing node.
Node 04 — IAB MarketsHIGH tier, Phase BAdd cross-reference: "Note — exploit acquisition by RaaS groups can bypass Node 04 entirely; exploit supply degradation is a prerequisite for sustained Node 04 disruption effectiveness"Without addressing exploit supply, IAB market disruption is incomplete for groups with 0-day capability (CL0p model)
Phase structure (A/B/C)Three phases covering financial, market, and delivery layersAdd Phase A+ (pre-market): Exploit/Vulnerability Markets and patch velocity; bug bounty economics reform. Phase A+ actions should be initiated simultaneously with Phase A, not sequenced after.Current phase structure does not account for access pathways that bypass the IAB market entirely

Follow-On Research