Cyber Kill Chain
Definition
A seven-phase linear model of an intrusion developed by Lockheed Martin in 2011. The phases are: Reconnaissance, Weaponisation, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. Breaking the chain at any phase prevents the attacker from reaching their goal.
- Developer
- Lockheed Martin
- Year
- 2011
- Number of phases
- 7
- Final phase
- Actions on Objectives
- Defensive principle
- Breaking any phase stops the intrusion
Common questions
What is the main criticism of the Cyber Kill Chain model in modern incident response?+
It models intrusions as a strictly linear sequence, which fits traditional malware delivery but fits poorly with living-off-the-land attacks, insider threats, or cloud compromises that do not follow a clean weaponisation-and-delivery pattern, which is why frameworks like MITRE ATT&CK are often used alongside it.
Which phase gives defenders the cheapest opportunity to stop an attack?+
Earlier phases such as Reconnaissance and Delivery are generally cheaper to disrupt, for example by blocking phishing emails or restricting information exposure, than later phases like Command and Control where the attacker already has a foothold.
Related terms
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- TTP (Tactics, Techniques, and Procedures)
- The three levels of specificity used to describe attacker behaviour. Tactics are the goal (e.g., persistence). Techniques are the method (e.g., scheduled...
- Unified Kill Chain
- An 18-phase model by Paul Pols (2017, updated 2021) that extends the Cyber Kill Chain by integrating MITRE ATT&CK and adding coverage...