Glossary

Cyber Kill Chain

The kill chain breaks attacks into steps: reconnaissance, weaponization, delivery, exploitation, installation, command & control, and actions on objectives. Stop any step and you stop the attack.

What is Cyber Kill Chain?

A framework describing the stages of a cyberattack, from reconnaissance to data exfiltration.

Why Should You Care?

Understanding the kill chain is critical because it shifts incident response from reactive cleanup to proactive intervention—defenders can block an attacker at any stage, and early detection dramatically reduces damage scope. Organizations that map their detection and response capabilities to kill chain stages can quantify gaps and prioritize defenses. For security teams, the framework transforms abstract attacks into measurable phases, enabling triage decisions: stopping reconnaissance prevents the attack entirely, while missing it still allows you to block delivery or exploitation.

Is your business exposed?

Real-World Example

The 2020 SolarWinds supply chain attack followed the kill chain precisely—adversaries conducted reconnaissance on SolarWinds' development environment, weaponized malicious code into the Orion software update, exploited trust in automatic updates for installation, and established command-and-control persistence. Organizations that detected the malware at installation or early C2 phases contained the breach; those who missed these stages suffered months of undetected lateral movement and data access.

How to Protect Against Cyber Kill Chain

  1. 1.

    Build defenses for each kill chain stage

  2. 2.

    Detect attacks early in the kill chain

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required