Security Concepts / 4 min

What is the Cyber Kill Chain?

A model for understanding attacker activity from reconnaissance through actions on objectives.

Definition

The Cyber Kill Chain is a framework that breaks attacker behavior into stages such as reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives.

Why it helps

The model helps defenders think about where detection and prevention controls can interrupt an attack path.

Portfolio takeaway

When I write lab reports, I use frameworks like this to connect technical observations to defender thinking.