the cyber kill chain
termsecurity
The staged model of an intrusion published by Lockheed Martin analysts in 2011 - reconnaissance, weaponisation, delivery, exploitation, installation, command and control, actions on objectives - borrowed from military targeting doctrine.
Its value is defensive framing: an intrusion is a sequence, so breaking any link stops the operation, and defenders can invest where interruption is cheapest rather than trying to stop everything. Its limits are equally real - the model assumes a tidy linear campaign, fits malware delivery better than credential abuse or insider misuse, and stops at the objective rather than covering the months an intruder spends moving laterally. ATT&CK largely superseded it for detailed work; the kill chain survives because it explains the shape of an attack to people who do not need a matrix.
Also known as: lockheed martin kill chain, intrusion kill chain, attack lifecycle