Terme informatique

Cyber Kill Chain

A cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives.

⌚ About 2 min read
View my favorites

Cyber Kill Chain is a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives.

Simple definition

Cyber Kill Chain is a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives. It belongs to the Cybersecurity vocabulary and is useful when reading architecture diagrams, product documentation, logs, or administration procedures.

What is it used for?

Its main purpose is to map prevention and detection controls so an intrusion can be disrupted as early as possible. The practical value depends on the surrounding architecture, security model, and operational requirements.

How does it work?

The classic model describes stages such as reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives.

Key points

  • Scope: A cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives.
  • Operational goal: Map prevention and detection controls so an intrusion can be disrupted as early as possible.
  • Implementation: The classic model describes stages such as reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives.

Points to watch

Use it as an analytical framework, not a mandatory timeline: modern attacks can skip, repeat, or parallelize stages.

In short

Cyber Kill Chain = a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives. Use it when you need to map prevention and detection controls so an intrusion can be disrupted as early as possible.

♡ 0