The cyber kill chain is a framework describing the seven stages of a cyberattack, from initial reconnaissance through data exfiltration, used to build defensive strategies.
The Lockheed Martin cyber kill chain comprises reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. Each stage represents an attacker progression point where defenders can detect, disrupt, or deny the attack. Breaking any single link theoretically stops the attack, enabling defense-in-depth strategy development.
Organizations map their security controls to each kill chain stage, identifying gaps in detection and prevention capabilities. This framework enables investment prioritization, incident response planning, and threat intelligence integration. Security teams develop specific countermeasures for each stage: threat intelligence for reconnaissance, email filtering for delivery, endpoint protection for installation, and network monitoring for command and control.
The traditional kill chain was designed around perimeter-focused, malware-centric attacks and struggles with insider threats, cloud-native attacks, supply chain compromises, and attacks that skip stages. It assumes a linear progression when modern attacks often occur in parallel or iteratively. Critics note it focuses on prevention rather than detection and response, and may not adequately address fileless attacks.
MITRE ATT&CK expands upon the kill chain concept by providing a detailed matrix of adversary tactics, techniques, and procedures based on real-world observations. While the kill chain offers a high-level strategic framework, ATT&CK provides granular technical detail for each attack phase. Many organizations use both frameworks complementarily for strategic planning and tactical detection engineering.
The unified kill chain combines the Lockheed Martin kill chain with MITRE ATT&CK into a comprehensive model with 18 phases spanning initial foothold, network propagation, and action on objectives. It addresses limitations of the original model by incorporating lateral movement, defense evasion, and persistence phases that better represent modern multi-stage attack campaigns targeting enterprise environments.
Red teams structure engagements around kill chain stages, testing organizational defenses at each phase. This includes conducting realistic reconnaissance, developing custom tooling for weaponization, testing delivery mechanisms across multiple vectors, validating exploitation capabilities, establishing persistent access, deploying command and control infrastructure, and simulating data exfiltration to evaluate defensive detection coverage.
Threat intelligence enhances kill chain defense by providing indicators of compromise mapped to specific stages, identifying adversary tactics and tooling preferences, enabling proactive hunting for pre-attack reconnaissance indicators, and informing defensive priorities based on relevant threat actor profiles. Intelligence-driven defense transforms the kill chain from a reactive to a predictive security framework.
Incident responders use the kill chain to determine attack progression during active incidents, identify which stages have been completed to assess impact scope, guide evidence collection priorities, predict likely next steps based on current stage identification, and develop containment strategies that address the specific point in the attack lifecycle where detection occurred.