Back to glossaryCyber

Cyber kill chain

A model breaking a cyberattack down into successive stages, from initial reconnaissance to the final action on the target.

Definition

The cyber kill chain is an analytical framework, formalized by Lockheed Martin in 2011, that breaks a targeted cyberattack down into an ordered sequence of stages: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and finally action on the objective. The model's value is defensive, as it holds that interrupting the chain at any stage is enough to neutralize the attack, which helps prioritize security efforts. For the insurer and risk manager, this breakdown offers a common language to assess an insured's defensive maturity and to locate a given incident within its progression. Its limits should nonetheless be understood, since the model was designed for linear intrusions and poorly describes modern attacks, which are more iterative and rely on access bought from brokers or on non-sequential lateral movement. Competing frameworks, notably the MITRE ATT&CK matrix, are now often preferred for mapping observed techniques in detail. The kill chain nevertheless retains genuine instructive and structuring value for communicating about risk.

Example

An incident-response team reconstructs that an attacker passed the delivery and exploitation stages through a booby-trapped email but was stopped at the command-and-control stage by effective network segmentation.

Related terms
Related articles
Also known as

chaîne d'attaque cyber, kill chain