IronSights

Penetration testing

Kill chain

A model describing the sequential phases of a cyber attack — from initial reconnaissance through to the attacker achieving their objective — used to understand attack progression and identify defensive intervention points.

Also known ascyber kill chainattack chainattack lifecycle

In plain English

The kill chain maps how an attack unfolds step by step: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. Understanding this model helps defenders identify which phase a detected attack is in and which controls would have broken the chain earlier.

Keep learning

More terms in the IronSights Glossary.