A model breaking a cyberattack down into successive stages, from initial reconnaissance to the final action on the target.
The cyber kill chain is an analytical framework, formalized by Lockheed Martin in 2011, that breaks a targeted cyberattack down into an ordered sequence of stages: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and finally action on the objective. The model's value is defensive, as it holds that interrupting the chain at any stage is enough to neutralize the attack, which helps prioritize security efforts. For the insurer and risk manager, this breakdown offers a common language to assess an insured's defensive maturity and to locate a given incident within its progression. Its limits should nonetheless be understood, since the model was designed for linear intrusions and poorly describes modern attacks, which are more iterative and rely on access bought from brokers or on non-sequential lateral movement. Competing frameworks, notably the MITRE ATT&CK matrix, are now often preferred for mapping observed techniques in detail. The kill chain nevertheless retains genuine instructive and structuring value for communicating about risk.
An incident-response team reconstructs that an attacker passed the delivery and exploitation stages through a booby-trapped email but was stopped at the command-and-control stage by effective network segmentation.
chaîne d'attaque cyber, kill chain