Exploitation
Using a discovered weakness to gain access or execute code on a target.
This is the moment a theoretical finding becomes demonstrated impact, and it is what separates a penetration test from a scan. It might be a software exploit, a valid credential, or a misconfiguration that grants more than intended.
Reputable testers weigh disruption carefully here, and some exploits are demonstrated in a controlled way rather than run fully against production.
Where this comes up
Exploitation sits inside our penetration testing work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.