# What is the Cyber Kill Chain?

> The cyber kill chain is a staged model of intrusion progression — reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives — originally published by Lockheed Martin.

- Canonical URL: https://yellowcube.eu/glossary/cyber-kill-chain/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The model frames an intrusion as a chain of dependent phases: interrupting any link can, in principle, frustrate the attacker’s objective. It gave defenders a shared structure for mapping detections, mitigations, and intelligence to points in an attack’s lifecycle rather than only to tools or indicators.

Its limits are structural. Real intrusions iterate, skip stages, blend with legitimate activity, and move through cloud, identity, and supply-chain paths the original host- and malware-centric model did not describe. Later work such as the Unified Kill Chain extends the staging, while MITRE ATT&CK catalogs observable behaviors without prescribing a linear order.

### Key points

- **Model structure:** Seven stages describe progression from initial reconnaissance to actions on objectives; the model emphasizes that earlier interruption is cheaper and safer than late-stage response.
- **Defensive use:** Map telemetry, detections, and controls to each stage to find coverage gaps, and use the stages to organize intelligence and post-incident analysis.
- **Analysis:** Record which stage each piece of evidence represents and where the chain was actually broken — an intrusion discovered at command and control was not stopped at delivery.
- **Important limitation:** The model assumes a sequence real adversaries need not follow. Credential theft, living-off-the-land, insider activity, and cloud control-plane abuse fit the staging poorly, and the model says nothing about attacker intent or skill.

### Related terms

[MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)](<https://yellowcube.eu/glossary/mitre-att-and-ck-adversarial-tactics-techniques-and-common-knowledge/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Advanced persistent threat (APT)](<https://yellowcube.eu/glossary/advanced-persistent-threat/>) · [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>)

### Sources

[Lockheed Martin, The Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) · [MITRE ATT&CK](https://attack.mitre.org/) · [NIST SP 800-150, Guide to Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

