
The advancement of technology has made cybersecurity an essential part of our various activities. The increase in ransomware and other cyberattacks has made organizations more cyber aware and security conscious in the past few years. One of the most expensive mistakes an organization will make is not incorporating cybersecurity into the organization's infrastructure.
For organizations to protect themselves from these cyberattacks, they need to have multiple layers of security and defense strategies. These may not eliminate the risks but will go a long way to minimize the risks.
One of the defense strategies an organization can adopt is, understanding the Cyber Kill Chain.
In cybersecurity, a Cyber Kill Chain is a set of procedures a cybercrime actor goes through to carry out a successful attack. It is a series of activities an attacker does when launching an attack.
The Cyber Kill Chain is a cybersecurity model that helps cybersecurity personnel to understand their adversaries and know how far they have gone in their attack.
The Cyber Kill Chain consists of seven stages;

RECONNAISSANCE
Reconnaissance is the first stage of the Cyber Kill Chain, and to a great extent, the success of the attack depends on it.
In this stage, the attacker selects a target and researches the target. The malicious actor gathers information about the target’s weaknesses and vulnerabilities. They obtain this information through technical means like network mapping, Open Source Intelligence (OSINT) gathering, port scanning, traffic analysis, and non-technical means like eavesdropping, shoulder surfing, and dumpster diving. Examples of information obtained in this stage are login credentials, email addresses, open ports, operating systems, etc.
WEAPONIZATION
In this stage, the attacker designs an attack vector. An attack vector is a means an attacker uses to exploit a vulnerability. The attack vector exploits the vulnerabilities discovered in the reconnaissance stage. This attack vector could be a virus, worm, or remote access malware packaged in a deliverable payload such as a PDF or Microsoft document.
DELIVERY
The malicious actor delivers the attack vector to the target through a phishing email or other social engineering techniques, websites, or USB drive. These are the most common delivery means.
EXPLOITATION
The malicious code is triggered after the weapon has been delivered, exploiting vulnerable applications or systems.
INSTALLATION
At this stage, the weapon installs other malware, such as a backdoor or remote access Trojan on the target's system, therefore giving the attacker continued access to the target's systems.
COMMAND AND CONTROL
The attacker gains administrative control over the victim's system. Privilege escalation techniques such as password attacks, for example, brute force and password spraying, are used to gain administrative access. The attacker also changes security configurations to remain in control.
ACTIONS ON OBJECTIVES
At this stage, the attacker accomplishes the attack's objectives, which could be exfiltration or destruction of data, encrypting of information, or intrusion of another target.
The Cyber Kill Chain is not only used by cybercrime actors. It is also used by robbers when carrying out a heist. For instance, the Cyber Kill Chain played out in the film Ocean's Eleven. Ocean's Eleven is an American heist movie. In the film, a team of eleven robbers robbed three casinos in Las Vegas simultaneously. The three casinos shared one vault.
The Cyber Kill Chain played out in the movie in the following way;
Reconnaissance: First, they got a sketch of the vault. The drawing helped the robbers know how the vault works, the kind of people they needed on the team, and how they could penetrate the vault. It also enabled them to build a replica of the vault.
Secondly, they formed a group. Then they carried out surveillance on certain persons of interest like the owner of the casinos and the security personnel. The robbers got information about their daily activities.
Weaponization: They needed some minutes of a power outage to enter the vault. At this stage, they decided how to cause a power outage and created a gem-like explosive they used in the heist.
Delivery: They delivered the gem-like explosive into the vault as a treasure that needed security. Also, one of the teammates got sneaked into the vault. He hid in one of the vault carts, that was how he got into the vault.
Exploitation: The robbers used a bomb-like device to cause an electromagnetic pinch, leading to a power outage. Two team members intercepted the security during the blackout and got to the vault entrance. The teammate who sneaked into the vault used the gem-like explosive to blow open the vault. They also intercepted their computer system and made it display video of the replica of the vault so what the surveillance team could see was a peaceful vault, whereas, in the real sense, the vault was in a state of chaos.
Installation: After the door was blown open, the team members at the vault entrance got into the vault.
Command and control: When the casino owner got notified about the robbery, he called 911 and requested a S.W.A.T team. The robbers intercepted the call and disguised as the S.W.A.T team.
Actions on objectives: When the fake S.W.A.T team arrived at the vault, they loaded the money in their gear bags, and that was how the robbers exited the casino with the cash without being caught.
Understanding the Cyber Kill Chain is essential in protecting an organization from attacks. It helps the incidence response team and other cybersecurity experts know the stage and extent to which the attacker has gone in his intrusion into their network.
For instance, if the security team detects suspicious activities like ports scanned sequentially, or an unfamiliar IP address trying to establish a TCP connection, this is a sign that the attack is still in the reconnaissance stage. The security team can add more layers of security to their network. They can also block the IP address from where the attack is coming.
Though the Cyber Kill Chain is an attack methodology, it is also a cyber defense strategy.



