Kill Chain Model
Jump to:
Overview
The Kill Chain Model is a cybersecurity framework that outlines the sequential stages of a cyberattack, enabling organizations to understand and disrupt adversary operations. It helps security teams identify attack phases and implement targeted defenses to prevent or mitigate breaches.
Primary Objectives
- Enhance threat detection and response consistency by breaking down attacks into discrete phases
- Benefit security operations centers (SOC), incident responders, threat analysts, and executives by providing a structured view of adversary behavior
- Support decision-making and accountability by mapping defensive measures to specific attack stages
Scope & Applicability
- Applicable across industries with cybersecurity risk exposure, including government, finance, healthcare, and critical infrastructure
- Covers threat lifecycle management and intrusion detection; excludes broader governance or compliance domains
- Requires foundational capabilities such as asset inventory, network visibility, and incident response processes
Core Structure
- Consists of sequential phases: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives
- Organized as a linear progression representing attacker tactics and techniques to facilitate targeted defense strategies
- Terminology aligns with cyber kill chain phases; mappings exist to threat intelligence taxonomies and mitigation controls
How It Is Used
- Adopted initially as a baseline model for threat analysis, often piloted within SOC workflows before broader integration
- Supports assessment workflows such as gap analysis in detection capabilities and incident investigation audits
- Incorporated into engineering processes for threat modeling, security design reviews, and prioritizing defensive controls in the SDLC
Implementation Artifacts
- Derived policies include incident response playbooks and detection strategy guidelines aligned to kill chain phases
- Control libraries map defensive measures to each attack stage, often cross-referenced with frameworks like MITRE ATT&CK and NIST
- Evidence artifacts encompass alert logs, forensic data, incident tickets, and network traffic captures supporting kill chain analysis
Measurement & Maturity
- Key performance indicators include detection rates per kill chain phase and mean time to detect/respond
- Maturity models assess capabilities from ad hoc detection to proactive threat hunting and automated response
- Common baselines define minimum controls for early attack phase detection progressing to advanced containment and remediation
Common Pitfalls
- Focusing on checklist compliance without aligning defenses to actual threat risks and attack behaviors
- Overextending scope leading to complexity and dilution of actionable insights (“framework sprawl”)
- Unassigned responsibilities for controls, insufficient evidence collection, and outdated documentation impair effectiveness
Integration & Mapping
- Maps to frameworks such as MITRE ATT&CK, NIST Cybersecurity Framework, and ISO 27001 through control and tactic alignment
- Integrates with governance, risk, and compliance (GRC) platforms, SOC monitoring, incident response (IR) workflows, and secure SDLC processes
- Tooling considerations include SIEM systems for detection, SOAR platforms for response automation, and threat intelligence feeds for enrichment
When Not to Use It
- Less suitable for organizations seeking lightweight or compliance-only frameworks without focus on attacker behavior
- Alternative staged approaches or simpler models may be preferred where resources or threat sophistication are limited
Standards & References
- Originally developed by Lockheed Martin; primary references include the Lockheed Martin Cyber Kill Chain documentation
- Companion materials include MITRE ATT&CK framework, NIST SP 800-61 incident response guide, and various implementation guides
More in Threat Models