Part three of a series on understanding the processes and tools behind an APT-based incident, CSO examines the process of exploitation and installation. At this stage, things have started to go wrong, as the attacker(s) have been successful in delivering their malicious payload. If the attacker’s campaign has made it this far, you have a problem, but you also have a chance to fix it. The other topics covered in this series are reconnaissance, weaponization and delivery, command and control, and exfiltration.”]