GRC Careers

HomeResourcesThe Cyber Kill Chain

CS-007 · Foundations

The Cyber Kill Chain

The stages of an intrusion, and how breaking any one stage can stop the whole attack.

Executive Summary

The cyber kill chain is a model that breaks a targeted intrusion into ordered stages, from early reconnaissance to the attacker's final objective. Its defensive value is that disrupting any single stage can stop the entire attack. It gives teams a structured way to think about detection and prevention across the whole intrusion, not just the moment of breach.

What It Is

The cyber kill chain, originally described by Lockheed Martin, models a targeted attack as a sequence of steps an adversary must complete to succeed. The commonly cited stages are reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. The key insight is that an attacker has to move through these stages in order, so a defender who detects and disrupts the chain at any point can prevent the attacker from reaching the goal. It reframes defense from a single wall to a series of opportunities to intervene.

Why It Matters

Thinking in stages helps teams spread their defenses across the whole intrusion rather than concentrating only on prevention at the perimeter. It shows that even if early stages are missed, later stages such as command and control or data exfiltration offer more chances to detect and respond. It also helps analysts communicate where in an attack an incident was caught and what an attacker still needed to do. For professionals, the kill chain is a common interview topic and a mental model used constantly in security operations and incident response.

How It Works

Defenders map their detective and preventive controls to each stage of the chain. Reconnaissance might be countered by reducing public exposure. Delivery is targeted by email filtering and web protection. Exploitation is reduced by patching and hardening. Installation and command and control are caught by endpoint detection and network monitoring. Actions on objectives, such as data theft, are limited by segmentation, access control, and egress monitoring. Analysts also use the chain in reverse during investigation, working backward from what they observed to understand how far the attacker progressed. The model pairs well with MITRE ATT&CK, which describes the specific techniques used within these stages.

Architecture Diagram

Reconnaissance: research the targetDelivery and exploitation: get in and run codeInstallation: establish a footholdCommand and control: attacker directs the footholdActions on objectives: steal, encrypt, or disrupt
An intrusion moves through ordered stages, and a defender can break the attack by disrupting any single stage.

Visual Workflow

Understand the ordered stages an attacker must pass through.Map existing detective and preventive controls to each stage.Find stages where you have little or no coverage.Add controls so no stage is a free pass for the attacker.During an incident, place observed activity on the chain to gauge progress.Use the position in the chain to guide containment and response priorities.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Email and web security gateways
Disrupt the delivery stage of intrusions
Endpoint Detection and Response (EDR)
Catches installation and post-exploitation activity
Network detection and monitoring
Surfaces command and control and exfiltration
SIEM
Correlates activity across stages into a coherent picture

Industry Standards

MITRE ATT&CK
Technique-level detail that complements the kill chain stages
NIST SP 800-61
Incident handling guidance that uses staged thinking
NIST Cybersecurity Framework (CSF) 2.0
Detect and Respond functions align with breaking the chain

Career Relevance

The cyber kill chain is core knowledge for SOC analysts, incident responders, threat hunters, and red teamers, who use it to structure detection and investigation. GRC analysts and risk professionals use it to reason about where controls sit in an attack. It is a frequent interview question and a shared vocabulary across defensive and offensive roles.

Interview Questions

Related Certifications

CompTIA Security+ GIAC Certified Incident Handler (GCIH) CompTIA CySA+

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is the kill chain the same as MITRE ATT&CK?

No. The kill chain describes the high-level stages of an intrusion in order. MITRE ATT&CK is a detailed knowledge base of the specific techniques attackers use, many of which occur within those stages. They complement each other.

Do real attacks always follow the kill chain in order?

Not exactly. The model is a useful simplification. Real intrusions can skip, repeat, or reorder steps, and some stages blur together. It is still valuable as a framework for organizing defense and investigation.

Why focus on later stages if I can stop attacks early?

Because early prevention will sometimes fail. If the only defenses are at delivery and exploitation, a single miss lets the attacker run unopposed. Later-stage detection provides additional chances to catch and contain the intrusion.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+GIAC Certified Incident Handler (GCIH)CompTIA CySA+

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: The Cyber Kill Chain
  3. Go deeper: Cybersecurity
  4. Go deeper: Threat Actors
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Foundations

Share this LinkedIn Facebook X Email