Mastodon Mastodon Mastodon Mastodon

Kill Chain

Updated: · CyberSecureFox Editorial Team

The kill chain (Cyber Kill Chain) is a model that describes a cyberattack as a sequence of stages, from reconnaissance to achieving the attacker’s goal, so that defenders can detect and break it at any step.

The stages of the Cyber Kill Chain

The model was published by Lockheed Martin in 2011, adapting a military concept. It has seven stages:

  • Reconnaissance – researching targets, employees and exposed systems.
  • Weaponization – preparing the exploit and payload, for example a malicious document.
  • Delivery – sending it via email, a website or another attack vector.
  • Exploitation – triggering the vulnerability or tricking the user into running code.
  • Installation – establishing malware and persistence.
  • Command and control – connecting to the attacker’s C2 server.
  • Actions on objectives – stealing data, encrypting systems, sabotage.

Why the kill chain matters

The key idea is that an attacker must succeed at every stage, while a defender needs to stop them at only one. The earlier the chain is broken, the less damage is done. Mapping controls to stages shows gaps: for example, strong email filtering at delivery, EDR at installation, egress filtering at command and control. The model also helps analysts describe and compare intrusions by APT groups.

Limitations and alternatives

Critics note that the original kill chain focuses on malware and the network perimeter and fits poorly with insider threats, cloud attacks or intrusions that use only stolen credentials. Later models address this: the Unified Kill Chain extends it with internal stages such as lateral movement, and MITRE ATT&CK describes hundreds of concrete techniques instead of seven broad phases. In practice, teams often use the kill chain for a high-level view and ATT&CK for detailed detection work.

Synonyms:
cyber kill chain