Key facts
- Zero-day refers to the defender's knowledge, not the attack's sophistication; the exploit may be old in attacker circles before discovery.
- Delivery is mundane even when the exploit is exotic: a crafted attachment or link, sent by phishing or spear phishing.
- Defense that works pre-patch is behavioral: anomalous senders, anomalous files, anomalous intent.
The zero-day lifecycle
A vulnerability exists unnoticed; someone finds it (researcher or attacker); an exploit is built and used or sold; eventually the vendor learns, patches, and the window closes. The dangerous interval is between exploitation and patch, and organizations extend it themselves by patching slowly. During that window, the only detection surface is behavior: the exploit is unknown, but the phishing email carrying it, the strange sender, the odd attachment type from an unexpected relationship, is not. See also spear phishing and AI-native security.
How to defend
Rapid patching shrinks the window after disclosure. Before disclosure: reduce attack surface, isolate and sandbox risky content, apply least privilege so one exploited client does not open the network, and put behavioral detection on the delivery channel, because stopping the carrier email stops the exploit unexamined.
How Sentaro helps
Sentaro is AI-native: verdicts come from models evaluating sender infrastructure, relationship history, content intent and attachment anomalies, not from signature lists. A zero-day payload has no signature, but its delivery email almost always deviates somewhere, and that deviation is detectable. This is precisely the attack class where rule-based gateways have nothing to match against.