Cyber Kill Chain Framework: Steps and Phases
Originating from the pioneering cybersecurity paradigm introduced by Lockheed Martin, the Cyber Kill Chain tracks the multifaceted stages of cyber threats, shedding light on system vulnerabilities, and providing security teams with the strategic advantage to thwart these threats at various junctures.
This ‘Kill Chain process’ parlance is derived from military strategies, encapsulating the structure of an assault. This involves target recognition, mission deployment, decision-making, culminating in target neutralization.
The Cyber Kill Chain is a cybersecurity framework followed by security analysts to recognize the progressive stages of a cyber attack even for Persistent Threats. The process commences with the reconnaissance stage, wherein the threat actor gathers pivotal details about their potential target. Subsequently, the actor moves to the weaponization phase, employing malicious code and exploits to infiltrate the target network or target organization.
The delivery phase follows suit, wherein the malicious software or payload, often in the form of malware or ransomware, is transmitted. The final stages are the exploitation and installation phases, wherein attackers gain comprehensive control over the system, making way for data theft.
The Kill Chain process is envisaged to help security experts pinpoint their defense strategy’s weak links before any cyber attack, even APT attacks can wreak havoc.
The Lockheed Martin Cyber Kill Chain embodies seven critical stages:
The Cyber Kill Chain Steps
Phase 1: Reconnaissance
The reconnaissance stage is characterized by the threat actor gathering information about their target and possible attack vectors, paving the way for a planned assault especially email addresses. This step demands the actor to discern what they are searching for and comprehend the workings of their target. The ultimate goal is to discern the type of data necessary for a successful mission and to establish the resources required to procure this data.
Phase 2: Weaponization
Weaponization in this context refers to the transformation of code into a digital weapon intended for intrusion, disruption, or infiltration of computer systems. For instance, the technique of SQL injection, often termed “SQL injection weaponization”, can be metaphorically referred to as weaponization.
Phase 3: Delivery
In the delivery stage, the threat actor uses a network of computers, already compromised with malware, to disseminate malicious software. The most frequent method employed for this purpose is the use of email attachments personalized for the target by using a type of attack called Social Engineering.
Phase 4: Exploitation
In the exploitation phase, the malware breaches the organization’s security perimeter, providing the attacker an opportunity to penetrate the organization’s system through software installation, script execution, and security certificate manipulation. Usually, the target is weaknesses in applications or operating systems, with common examples being scripting, dynamic data exchange, and local job scheduling.
Phase 5: Installation
In this phase which is a Malware Attack, the malware creates a backdoor Trojan, allowing the attacker remote access to the system. Host-based intrusion prevention systems (HIPS) can potentially thwart the attack at this critical juncture. Threat actors often resort to persistence installation methods to retain backdoor access, including system file and registry key modification and malware installation on startup.
Phase 6: Command and Control
The Command and Control (C2) server is the final juncture in the Cyber Kill Chain. It serves dual functions: enabling remote system intrusion for the attacker and serving as a repository for stolen data. C2 servers form an integral component of any cyber attack by allowing remote system access and data storage.
Phase 7: Actions on Objectives
The final phase of the Cyber Kill Chain involves Actions on Objectives. The primary objective in this phase is data destruction and ensuring irrecoverable damage to the target. The attacker often retrieves encrypted data from deleted files using recovery programs, further validating the value of encryption as an additional protection measure against deletion.
Kill Chain Process Controls Implementation:
Based on the aforementioned phases, the following control implementation stages are proposed for the Cyber Kill Chain model:
- Detection: Identifying intrusion attempts.
- Denial: Preventing attacks in real-time by using perimeter security and host security.
- Disrupt: Interfering with the attacker’s data communication.
- Degrade: Diminishing the efficacy of a cyber assault to limit its potential damage.
- Deviate: Misleading the attacker with false information.
- Contain: Restricting the spread of the attack to a limited segment of the organization.
The Kill Chain Process in Defense Against Cyber Threats
The Cyber Kill Chain Framework provides robust defense against cyber threats by implementing a Cybersecurity strategy:
1. Simulating Real-World Cybersecurity Threats:
This involves testing real cybersecurity threats across various channels to detect vulnerabilities similar to an external attack. The channels include email gateways, web gateways, web application firewalls, among others.
2. Evaluating Controls to Recognize Security Gaps:
Simulations are evaluated and risks are identified. Simulation platforms provide a comprehensive risk report and score on each aspect.
3. Remediation of Cybersecurity Gaps:
The final step involves rectifying the security vulnerabilities identified in the initial stage to reduce the attack surface. Measures could include patch application or modifying security controls to reduce security threats within the business system.
Conclusion and Summary
This Cybersecurity Kill Chain is one of the best and efficacious Cybersecurity models that provides insight into the progression of cyber threats. This article offers an understanding of the seven stages in the Kill Chain Process and their significance.
Starting with the reconnaissance stage, it involves amassing as much information about a potential target as possible. The following scanning stage sees threat actors scanning networks to determine the software versions running and existing vulnerabilities.
From here, the attackers attempt to exploit these vulnerabilities, for instance, the infamous WannaCry malware utilized a vulnerability in Microsoft Windows discovered in March 2017 but remained unpatched until the following month.
Hackers can then pilfer data and even gain control of the infected machines. The exploitation stage involves transmitting malicious code to infect a system or spread malware across networks.
The next phase is the installation stage, where threat actors install malicious software on the victim’s computer. The final parts of the attack include persistence, where the attackers ensure the malware remains installed on the computer, impervious to removal to maintain persistent access. This is followed by Data exfiltration.


