Cyber Kill Chain: The 7 Stages of an Attack and Defense
The Cyber Kill Chain defines the seven stages of a cyber attack (recon, weaponization, delivery, exploitation, installation, C2, actions). A 7 stage infographic, a defense per stage table, how to use it, the MITRE ATT&CK difference and FAQs.
Quick answer: The Cyber Kill Chain is a defense model developed by Lockheed Martin that defines the seven stages a cyber attack goes through from start to finish. The stages in order are: 1) Reconnaissance (researching the target), 2) Weaponization (preparing the malicious payload), 3) Delivery (getting the payload to the target, e.g. phishing), 4) Exploitation (triggering a flaw), 5) Installation (establishing persistence), 6) Command and Control (connecting to the attacker), 7) Actions on Objectives (data theft, encryption, sabotage). The model's defensive value is this: the earlier you stop the attack, the farther it stays from its objective. The earlier you break the chain, the less the damage; stopping it at the last stage is almost too late. So defense is built layered, placing a separate control at each stage.
To defend against an attack you must first understand how it works. The Cyber Kill Chain provides exactly this: it breaks a complex attack into seven understandable steps and makes it possible to ask "how do I stop it here" at each step. This guide explains the kill chain and the defense at each stage with world class clarity.
Cyber Kill Chain: the 7 stages
The model's strongest idea is that an attack is not a single moment but a process. The attacker must complete all seven steps; the defender defeats the whole attack by breaking just one of them. This is the defender's advantage.
The seven stages and defense at each
| # | Stage | What the attacker does | Defense |
|---|---|---|---|
| 1 | Reconnaissance | Researches the target and staff | Reduce attack surface, OSINT monitoring |
| 2 | Weaponization | Prepares the malicious payload | (On the attacker side, not directly seen) |
| 3 | Delivery | Delivers the payload (phishing, USB) | Email filtering, awareness training |
| 4 | Exploitation | Triggers a flaw | Patching, secure code, least privilege |
| 5 | Installation | Establishes persistence | EDR, application allowlisting |
| 6 | Command and Control | Connects to the attacker | Network monitoring, egress filtering |
| 7 | Actions on Objectives | Steals, encrypts, sabotages | Segmentation, DLP, backups |
How to use the kill chain
- Map your defense. Make sure at least one control falls on each stage; a stage left empty is the attacker's open door.
- Invest in early stages. Stopping at the first stages is many times cheaper than at the last.
- Pair with detection. Each stage has a trace; search for these with threat hunting and SIEM/SOC.
- Deepen with MITRE ATT&CK. The kill chain stages are a broad frame; MITRE ATT&CK gives the concrete techniques at each stage.
Frequently asked questions
What is the difference between the kill chain and MITRE ATT&CK? The kill chain breaks an attack into 7 broad stages (a high level map); ATT&CK details hundreds of concrete techniques at each stage. They are used together: kill chain is the frame, ATT&CK the detail.
Does every attack follow all 7 stages? Classic targeted attacks usually do, but some (for example an automated attack exploiting a flaw directly) may skip stages. The model is a thinking frame, not a strict rule.
At which stage is it best to stop? The earlier the better. Stopping at reconnaissance and delivery is cheapest; if it has reached actions on objectives the damage has already begun.
Does the kill chain apply to ransomware? Yes. Ransomware typically follows phishing (delivery), exploitation, installation, spread and encryption (actions). Breaking the chain at installation or spread prevents encryption.
Sources
- Lockheed Martin, Cyber Kill Chain: https://www.lockheedmartin.com
- MITRE ATT&CK: https://attack.mitre.org
- NIST SP 800 61, Incident Handling: https://csrc.nist.gov
- CISA, Understanding the Attack Lifecycle: https://www.cisa.gov
To assess your organization's defense against each stage of the kill chain and close the gaps, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide cybersecurity, penetration testing and incident response.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.