0 / 7
Cyber Kill Chain
An attack does not happen all at once; it passes through several stages in order. The Cyber Kill Chain is an analysis model that splits this process into seven stages, from reconnaissance to actions on objectives. The American defense company Lockheed Martin described it in 2011. The attacker has to get through all seven stages to reach the goal. The defender can stop the attack by breaking just one of them.
Example: an attacker emails an employee a file disguised as a quote, then tries to reach the customer database through that PC.
1 / 7
Reconnaissance
The attacker searches the company website, staff social media, and job postings. They learn employee email addresses and which version of the document program the company uses. They only look at public places, so the company is unlikely to notice.
2 / 7
Weaponization
The attacker puts attack code aimed at that program's weakness and a backdoor together into one document file. The file is named to look like a quote. All of this happens on the attacker's own computer, so the company cannot see it.
3 / 7
Delivery
The attacker writes an email pretending to be a business partner and sends it to an employee with the file attached. USB drives or websites hacked in advance are also used. This company has no equipment that checks attachments, so the email arrives as is.
4 / 7
Exploitation
The employee opens the quote. This triggers the weakness in the document program, and the attack code hidden in the file runs. Had the program been updated, the weakness would be gone and the code would not run.
5 / 7
Installation
The attack code installs the backdoor from the file on the PC. It also registers the backdoor as a startup program so it runs again after a restart. The attacker now has a door to come back through at any time.
6 / 7
Command and Control (C2)
The backdoor connects first, from inside the company to the attacker's server outside. A firewall blocks connections coming in, but usually lets connections going out pass. So the link gets through, and the attacker uses it to send commands to the backdoor.
7 / 7
Actions on Objectives
Through the backdoor, the attacker looks around the internal network and finds the customer database. Its data leaves through the backdoor for the attacker's server. As in a ransomware attack, the attacker may instead encrypt the data to demand money, or simply delete it.
1 / 7
Reconnaissance
The attacker searches the company website, staff social media, and job postings. They learn employee email addresses and which version of the document program the company uses.
2 / 7
Weaponization
The attacker puts attack code aimed at the document program's weakness and a backdoor together into one quote file.
3 / 7
Delivery: blocked here
The attacker writes an email pretending to be a business partner and attaches the quote file. The company's mail security gateway opens the attachment in an isolated place first and finds the hidden attack code. The email is blocked, and nothing reaches the employee's inbox.
4 / 7
Exploitation: does not happen
The quote never reached the employee's inbox. With no file to open, nothing can trigger the weakness in the document program. The program is still not updated, but the attack never got as far as that weakness.
5 / 7
Installation: does not happen
The attack code never ran, so the backdoor cannot be installed.
6 / 7
Command and Control (C2): does not happen
With no backdoor on the PC, nothing connects to the attacker's server. The attacker's server never hears anything.
7 / 7
Actions on Objectives: does not happen
With no way into the company, the customer database stays as it is. Blocking stage 3 alone stopped all four stages after it.