Glossary · simply explained

Cyber kill chain

The cyber kill chain is a phase model for targeted attacks: from reconnaissance via weaponisation, delivery, exploitation and installation to command-and-control and the actual objective — such as data theft or encryption.

The central message is optimistic: an attack is a chain, and the defender only has to cut it in one place. Every phase offers its own detection and defence points.

The phases and their countermeasures

Early in the chain, prevention and hygiene act: attack surface management against reconnaissance, email and web protection against delivery, patching and hardening against exploitation. From installation onwards, EDR and application controls take over; DNS filters and NDR catch command-and-control traffic; segmentation, privilege concepts and backups limit the impact.

Read in a modern way, the chain is not a rigid sequence — real attacks jump, repeat phases and run in parallel. As a mental model for defence in depth it remains valuable: covering every phase with at least one control forces attackers to succeed several times instead of once.

Using the model practically

  • Map controls to phases: where are we strong, where blind?
  • Reconstruct incidents along the chain: how far did the attacker get — and why?
  • Balance investments: not everything into prevention, enough into detection and containment.
  • Refine with MITRE ATT&CK when technique-level precision is needed.

Frequently asked questions about Cyber kill chain

Which phases does the cyber kill chain have?

Classically seven: reconnaissance, weaponisation, delivery, exploitation, installation, command-and-control and actions on objectives. Real attacks do not always keep the order — as a grid for defence in depth the model still works.

Is the kill chain still current?

As a mental model yes, as an exact description of modern attacks only partly: ransomware groups and cloud attacks jump between phases and use legitimate tools. That is why it is combined today with ATT&CK, which catalogues concrete techniques.

What does the model give me concretely?

A simple completeness check: every phase should have at least one detection or defence control. This mapping reveals typical imbalances — such as heavy prevention at the perimeter but hardly any detection of lateral movement inside.

Where is cutting the chain most effective?

There is no single best point — the strength lies in depth. Early interruption (delivery, exploitation) prevents damage most cheaply; late controls (segmentation, backups) limit it when everything else fails. Both belong together.

How does the kill chain relate to ATT&CK?

The kill chain provides the rough sequence, ATT&CK the fine vocabulary: every phase can be backed with concrete ATT&CK techniques. Many teams use the chain for management communication and ATT&CK for the technical work.

Wondering how this looks in your own network? Talk to KAEMI: we plan, build and manage the right solution with you.