Skip to main content
CYBER KILL CHAIN
Ankita Ganguly(8130)
WHAT IS CYBER KILL CHAIN?
 The Cyber Kill Chain was socialized by Lockheed Martin
 It was developed as a method for describing an intrusion from an attacker’s point of view
 It is used to prevent APT – Advanced Persistent Threat, represents well – resourced and trained
adversaries that conduct multi-year intrusion campaigns targeting highly sensitive economic,
proprietary, or national security information
CYBER KILL CHAIN STAGES
COURSES OF ACTION
Phase Detect Deny Disrupt Degrade Deceive
Reconnaissance Firewall,NIDS,Web
Logs
Firewall,
NIPS
*** *** ***
Weaponization DNS Monitoring
Website Monitoring
*** *** *** ***
Delivery Antivirus, NIDS,
Vigilant User
NIPS, Proxy In-line AV *** ***
Exploitation NIDS
Anti Virus
Antivirus
System
Patching
Antivirus
System
Patching
Restricted
User Account
***
Installation Anti Virus,
Application Logs
Anti virus *** ***
Command & Control CIC, Malware
Sandbox, NIDS
Firewall NIPS *** ***
Actions on Objectives Application Logs Firewall,
VLANs
VLANs *** ***
WHAT CAN THE CYBER KILL CHAIN DO?
 Each phase of the kill chain can be mapped to corresponding defensive tool and action
 An analyst who knows the stages of the kill chain has a basic understanding of what is being
attempted and what response is called for
Cyber kill chain