Well, I am one of the many people who theoretically can hack someone's system while not leaving evidences of it, at least not evidences pointing to myself.
I do have people I dislike, and yet I don't hack in their systems to plant false evidences.
I do have people I dislike, and yet I don't hack in their systems to plant false evidences.
My point is this: There is no defense against 0-day/X-day exploits in the wild. But the second best thing against being patched is logging and properly tuned alerting. In my 20-ish years of working in this field I've caught half a dozen attackers/intruders via logs and anomaly alerts. Without those 2nd best things in place the entire network(s) would probably have been compromised.
Cheers.