Quick answer: The Cyber Kill Chain is a defense model developed by Lockheed Martin that defines the seven stages a cyber attack goes through from start to finish. The stages in order are: 1) Reconnaissance (researching the target), 2) Weaponization (preparing the malicious payload), 3) Delivery (getting the payload to the target, e.g. phishing), 4) Exploitation (triggering a flaw), 5) Installation (establishing persistence), 6) Command and Control (connecting to the attacker), 7) Actions on Objectives (data theft, encryption, sabotage). The model's defensive value is this: the earlier you stop the attack, the farther it stays from its objective. The earlier you break the chain, the less the damage; stopping it at the last stage is almost too late. So defense is built layered, placing a separate control at each stage.

To defend against an attack you must first understand how it works. The Cyber Kill Chain provides exactly this: it breaks a complex attack into seven understandable steps and makes it possible to ask "how do I stop it here" at each step. This guide explains the kill chain and the defense at each stage with world class clarity.

Cyber Kill Chain: the 7 stages

CYBER KILL CHAIN · THE 7 STAGES OF AN ATTACK 1Recon2Weaponize3Delivery4Exploit5Install6C27Actions Breaking the chain early is cheapest: an attack stopped at any stage never reaches its objective.

The model's strongest idea is that an attack is not a single moment but a process. The attacker must complete all seven steps; the defender defeats the whole attack by breaking just one of them. This is the defender's advantage.

The seven stages and defense at each

# Stage What the attacker does Defense
1 Reconnaissance Researches the target and staff Reduce attack surface, OSINT monitoring
2 Weaponization Prepares the malicious payload (On the attacker side, not directly seen)
3 Delivery Delivers the payload (phishing, USB) Email filtering, awareness training
4 Exploitation Triggers a flaw Patching, secure code, least privilege
5 Installation Establishes persistence EDR, application allowlisting
6 Command and Control Connects to the attacker Network monitoring, egress filtering
7 Actions on Objectives Steals, encrypts, sabotages Segmentation, DLP, backups

How to use the kill chain

  • Map your defense. Make sure at least one control falls on each stage; a stage left empty is the attacker's open door.
  • Invest in early stages. Stopping at the first stages is many times cheaper than at the last.
  • Pair with detection. Each stage has a trace; search for these with threat hunting and SIEM/SOC.
  • Deepen with MITRE ATT&CK. The kill chain stages are a broad frame; MITRE ATT&CK gives the concrete techniques at each stage.

Frequently asked questions

What is the difference between the kill chain and MITRE ATT&CK? The kill chain breaks an attack into 7 broad stages (a high level map); ATT&CK details hundreds of concrete techniques at each stage. They are used together: kill chain is the frame, ATT&CK the detail.

Does every attack follow all 7 stages? Classic targeted attacks usually do, but some (for example an automated attack exploiting a flaw directly) may skip stages. The model is a thinking frame, not a strict rule.

At which stage is it best to stop? The earlier the better. Stopping at reconnaissance and delivery is cheapest; if it has reached actions on objectives the damage has already begun.

Does the kill chain apply to ransomware? Yes. Ransomware typically follows phishing (delivery), exploitation, installation, spread and encryption (actions). Breaking the chain at installation or spread prevents encryption.

Sources

To assess your organization's defense against each stage of the kill chain and close the gaps, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide cybersecurity, penetration testing and incident response.