Cyber Kill Chain

Also known as: Lockheed Martin Kill Chain

framework · cybersecurity · organizing-schema

Seven-phase model of intrusion: reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, actions on objectives.

The Cyber Kill Chain was articulated by Eric M. Hutchins, Michael J. Cloppert, and Rohan M. Amin of Lockheed Martin's Computer Incident Response Team in their 2011 paper 'Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains.' Adapted from US military doctrine on targeting (find, fix, track, target, engage, assess), the framework articulates seven phases of a cyber intrusion: (1) Reconnaissance — gathering target information; (2) Weaponization — coupling exploit with deliverable payload; (3) Delivery — transmitting weapon to target (email, web, USB); (4) Exploitation — triggering vulnerability to execute on victim system; (5) Installation — installing backdoor or malware; (6) Command and Control (C2) — establishing communication channel to attacker; (7) Actions on Objectives — achieving the attacker's goals (data exfiltration, lateral movement, destruction). The framework's central commitment is that defense should aim to break the chain at any point — disrupting any one phase prevents the intrusion from succeeding, with detection and response opportunities at each phase. The framework substantially shaped intrusion analysis and threat intelligence practice from 2011 onward and remains widely cited in incident response and security operations. However, the framework has drawn substantial critique for: (1) perimeter-centric thinking that doesn't fit cloud and zero-trust architectures; (2) linear sequential framing that doesn't capture sophisticated attacks involving lateral movement, persistence across phases, and multi-vector approaches; (3) less granularity than MITRE ATT&CK provides. ATT&CK has substantially superseded Cyber Kill Chain in many security operations contexts while Cyber Kill Chain retains pedagogical and conceptual value.

Originators

Eric M. Hutchins, Michael J. Cloppert, Rohan M. Amin (Lockheed Martin Computer Incident Response Team) high

Year / Decade

2011 (Hutchins-Cloppert-Amin paper) high

Primary sources

Hutchins, E.M., Cloppert, M.J. & Amin, R.M. (2011). 'Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains' (Lockheed Martin), Pols, P. (2017). 'The Unified Kill Chain' (extension) high

Band notes

Lockheed Martin's framework biases toward perimeter-centric thinking; less aligned with cloud and zero-trust architectures.

Core components

Primary use case

Intrusion analysis and threat intelligence frameworks; incident response and forensic analysis structuring; security operations playbook development (particularly pre-2020); threat-intelligence reporting structure; pedagogical reference in cybersecurity education for understanding attack progression; basis for some commercial security products marketed around 'kill chain' framing; reference framework in security awareness training.

Common criticisms

Lineage

Siblings
MITRE ATT&CK, Diamond Model of Intrusion Analysis