To detect and combat Cyber Kill Chain attacks in time, it is necessary to know in detail the strategies of cyber thieves. This is the only way to take appropriate action. And this is exactly where Cyber ​​Kill Chain comes in.

The Cyber Kill Chain has become a list of steps that must be taken into account to know how things are being done in terms of security, if companies are truly protected and, in the event of an incident, where the chain could have been broken. This was Invented by the incident team at security firm Lockheed Martin, this model has been followed by many security experts, some of whom have looked to its evolution.

As if it were a chain of attack, the path that an intruder has to take to penetrate systems and carry out his attacks. It also serves to set policies, study available defense technologies, and calculate the costs of failure.

The phases of the Kill Chain

▸Recognition: Learning about the target using various techniques.

▸Creation of the weapon: Adaptation of the malware code to the medium on which the infection will be searched.

▸Delivery: Transmitting the malware code through some means.

▸Exploitation: Exploiting a vulnerability in the software or human error to execute the malicious software.

▸Installation: Malicious software ensures that it can run permanently on the infected computer.

▸Command & Control (C2): The malware communicates with its central, giving attackers remote control.

▸Actions on the objectives: Proceed to theft or the execution of what is proposed to do.

It is possible to assign a viable set of defenses for each of the phases of the Kill Chain which, in its version, ensures that it is a great model for the prevention of advanced attacks. This model has been followed by many security experts, some of whom have sought the evolution of this version and thus be able to guarantee much more security.


Un comentario en «The steps of the Cyber Kill Chain and what is it?»

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *