Cyver core supports the Cyber Kill Chain framework, a foundational model for identification and prevention of cyber intrusions activity. The model provides security professionals with a means to identify and prevent the stages an adversary must complete to achieve their objective.
General Information on the Cyber Kill Chain
Developed by Lockheed Martin, the Cyber Kill Chain® framework is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective.
The steps of the Cyber Kill Chain® enhance visibility into an attack and enrich an analyst’s understanding of an adversary’s tactics, techniques and procedures (TTPs).
What is Cyber Kill Chain?
The Cyber Kill Chain serves as a structured approach to understand and categorize the sequential stages of a cyber attack, from initial reconnaissance to the final objective. By breaking down the attack into distinct phases, defenders can identify opportunities to interrupt the intrusion.
The framework identifies the following seven phases that an adversary typically progresses through:
- Reconnaissance: The adversary gathers information about the target (e.g., harvesting email addresses, conference information).
- Weaponization: The attacker couples an exploit with a backdoor to create a deliverable payload.
- Delivery: The weaponized bundle is transmitted to the victim (e.g., via email, web, USB).
- Exploitation: The adversary exploits a vulnerability to execute code on the victim's system.
- Installation: Malware is installed on the target asset to establish persistence.
- Command & Control (C2): A command channel is established for the remote manipulation of the victim's system.
- Actions on Objectives: With "Hands on Keyboard" access, intruders accomplish their original goals (e.g., data exfiltration, destruction of systems).
Download
You can directly download the latest Cyber Kill Chain Checklist from our GitHub repository: