Skip to content
Back to home
2025-06-15Security Fundamentals4 min read

Cyber Kill Chain

A breakdown of the Cyber Kill Chain framework — the seven stages Lockheed Martin introduced in 2011 to identify and mitigate attacks, from reconnaissance through to actions on objectives.

Cyber Kill Chain is a security framework for identifying and mitigating attacks by breaking the attack into various stages. Kill Chain is the term that is taken from military concept. This framework was introduced by Lockheed Martin in 2011. The attack is divided into 7 stages.

  • Reconnaissance
  • Weaponization
  • Delivery
  • Exploitation
  • Installation
  • Command & Control
  • Actions on Objectives

1. Reconnaissance

Reconnaissance is the initial stage where the attacker gathers information about the target. This can be divided into 2 types.

Active Reconnaissance: In this type of reconnaissance, the attacker directly interacts with the target by using certain tools (like Nmap, Nessus) and techniques to identify the vulnerabilities. This includes Port scanning (entry point), ping sweeping, Network mapping, vulnerability scanning, etc.

Passive Reconnaissance: At this, instead of directly engaging with target, the attacker gathers publicly available information about it. The Open-Source Intelligent (OSINT) tools also fall under this category. This includes Search Engine Dorking, Email harvesting, etc., by using some tools (Shodan, hunter, etc.) and commands (like whois).

2. Weaponization

In this stage, the attacker decides the type of weapon, like whether it would be a virus, trojan, rootkit or any other, to use against the target. Sometimes, the attacker designs his/her own weapon. Alternatively, the attacker can buy existing weapons from the sources like Dark Web. A weapon is usually a malware.

3. Delivery

This stage is about delivering the malware to the victim. This could be done by various methods such as phishing, social engineering attacks, compromised websites (watering hole attack), infected attachments, etc. Once the victim executes the malware, the attacker will gain access to the target.

4. Exploitation

This phase, the attacker gained access to the target by the malware he/she delivered. The malware takes the advantage of a vulnerability and break into it. So now, the attacker exploits the vulnerabilities that was found in reconnaissance. This includes software vulnerability, weak configurations, human errors, etc.

5. Installation

After gaining access, the attacker creates an entry point, called backdoor, through which she/he can control the target in future (persistence entry). The attacker can also install other malwares like trojan horses to gain full control over target.

6. Command & Control

Now, attacker has full control over the target. So, the attacker establishes command and control over the access and control of the target user network, by which she/he can monitor and guide the malwares installed. This stage is about setting a communication channel between the attacker and the target device. The attacker can turn the affected system into Zombie computer for conducting DDOS attack by controlling it remotely.

7. Actions on Objectives

This is the final stage where the attacker really achieves his/her main goal on target. It could be data theft, encrypting, supply chain attack, privilege escalation, etc. Later the attacker erases the traces of attack for being undetected (like deleting shadow file which usually contains all logs).

These are the 7 phases of Cyber Kill Chain. Understanding this is very important for any role in Cyber Security. Also, the traditional Kill Chain has some pros and cons (like there is no mention about insider threats). Although it is very crucial to study.