Cyber Kill Chain is a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives.
Simple definition
Cyber Kill Chain is a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives. It belongs to the Cybersecurity vocabulary and is useful when reading architecture diagrams, product documentation, logs, or administration procedures.
What is it used for?
Its main purpose is to map prevention and detection controls so an intrusion can be disrupted as early as possible. The practical value depends on the surrounding architecture, security model, and operational requirements.
How does it work?
The classic model describes stages such as reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives.
Key points
- Scope: A cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives.
- Operational goal: Map prevention and detection controls so an intrusion can be disrupted as early as possible.
- Implementation: The classic model describes stages such as reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives.
Points to watch
Use it as an analytical framework, not a mandatory timeline: modern attacks can skip, repeat, or parallelize stages.
In short
Cyber Kill Chain = a cybersecurity model that breaks an attack into successive stages from reconnaissance through actions on objectives. Use it when you need to map prevention and detection controls so an intrusion can be disrupted as early as possible.