­
Basics Of Cyber Kill Chain Model - All Articles - CISO Platform

Basics Of Cyber Kill Chain Model

Cyber Kill Chain Model 

In military strategy, a 'Kill Chain' is a phase model to describe the stages of an attack, which also helps inform ways to prevent attacks

  • Situational Awareness - Ability to identify what is happening in the networks and system landscape
  • Reconnaissance - Identification and selection of the target/s host or network by active scanning
  • Weaponization & delivery - Transmission / Inject of the malicious payload in to the target/s
  • Lateral Movement - Detect, exploit and compromise other vulnerable hosts
  • Data Exfiltration - Steal and exhilarate data
  • Persistency - Establish a foothold in the corporate network

Situational Awareness

  • Outbound protocols
  • Outbound protocols by size
  • Top destination Countries
  • Top destination Countries by size

Reconnaissance

  • Port scan activity
  • ICMP query

Weaponization & delivery

  • Injection
  • Cross Site Scripting
  • Cross Site Request Forgery
  • Failure to Restrict URL
  • Downloaded binaries
  • Top email subjects
  • Domains mismatching
  • Malicious or anomalous Office/Java/Adobe files
  • Suspicious Web pages (iframe + [pdf|html|js])

Lateral Movement

  • Remove or add account
  • Remote WMI communications
  • Remote Group Policy Editor
  • Remote Session Communications (during outside working hours?)
  • Antivirus terminated

Data Exfiltration

  • Upload on cloud storage domains
  • Suspicious HTTP Methods (Delete, Put)
  • Uploaded images
  • FTP over non standard port
  • IRC communication
  • SSH | ICMP Tunneling

Persistency

  • Unusual User Agents
  • Outbound SSL VPN
  • Outbound unknown

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

City Round Table Meetup - Mumbai, Bangalore, Delhi, Chennai, Pune, Kolkata

  • Description:
    CISO Playbook Round Table Overview : 
    Our round tables are designed to bring together top CISOs and IT leaders in intimate, focused sessions. These closed-door discussions will provide a platform to explore key security challenges and solutions. These sessions aim to create a focused, closed-door environment where 08-10 CISOs will dive deeply into the practicalities of implementing specific technologies.
    • Technology Implementation: From…
  • Created by: Biswajit Banerjee
  • Tags: ciso, playbook, round table

Round Table Dubai 2025 | GISEC

  • Description:
    CISO Playbook Round Table Overview : 

    Our round tables are designed to bring together top CISOs and IT leaders in intimate, focused sessions. These closed-door discussions will provide a platform to explore key security challenges and solutions. These sessions aim to create a focused, closed-door environment where 08-10 CISOs will dive deeply into the practicalities of implementing specific technologies.
    • Technology…
  • Created by: Biswajit Banerjee

Fireside Chat With Dan Bowden (Global Business CISO, Marsh McLennan (Marsh, Guy Carpenter, Mercer, Oliver Wyman))

  • Description:

    We’re excited to bring you an insightful fireside chat on "Navigating the Cyber Insurance Landscape: Key Considerations for CISOs" with Dan Bowden (Global Business CISO, Marsh McLennan) and Erik Laird (Vice President - North America, FireCompass). In this fireside chat, we'll decode the complexities of cyber insurance from a CISO’s lens and uncover how to make smarter, security-aligned decisions when it comes to policy design, claims, and ROI.

    As cyberattacks grow in…

  • Created by: Biswajit Banerjee
  • Tags: ciso, cyber insurance, dan bowden

CISO Platform: CISO 100 Awards & Future CISO Awards @ Atlanta

  • Description:

    Nominate for the CISOPlatform CISO 100 Awards & Future CISO Awards - Recognizing Cybersecurity Leaders. Recommend someone you know deserving of this prestigious accolade....Nominate your colleague, mentor, someone you admire or yourself !

    CISO Platform is collaborating as a community partner with EC-Council’s Global CISO Forum, supporting initiatives such as the CISO Platform…

  • Created by: Biswajit Banerjee