Cyber-Attackers
Cyber-Attacks
Lockheed Martin Kill Chain
Elements of a Cybersecurity Program
Breach Targets and Attacks
100

This threat includes the random malware, viruses, Trojans, worms, and other threats that are out on the Internet all the time.

Commodity Threat

100

This is a leg of the CIA triangle that represents the letter C, where the attacker seeks to steal data.

Confidentiality

100

This is the phase when the attacker selects their target and gathers information about the entity that it can use to gain access.

Reconnaissance

100

This is the foundation of a cybersecurity program that directs what is to be protected, to what degree, and the consequences if the protection is violated.

Policy

100

This is the cybersecurity system head and the credentials of this account allow hackers access to the whole system.

System Administrator

200

This is a term used for activists that hack a system to make a public or political statement.

Hacktivists

200

This is a leg of the CIA triangle that represents the letter I, where the attacker seeks to modify data.

Integrity

200

This is the phase after the weapon is delivered where the intruder’s code is triggered. It might target an application or operating system vulnerability.

Exploitation

200

You must create one of these to allocate funds properly to pay for deploying, operating, and maintaining the cybersecurity technologies and processes in the IT program.

Budget

200

This is a copy of the database that is vulnerable to an attack due to the fact that it sometimes has lower security or unencrypted data.

Backup

300

This is a term for a targeted cyber-attack with the intentions of receiving a large payday.

Organized Crime

300

This is a leg of the CIA triangle that represents the letter A, where the attacker seeks to deny access to data.

Availability

300

This is the stage in the Kill Chain where a regular document or file is turned into a deliverable payload.

Weaponization

300

This element consists of the hardware and software that is employed to protect the company in the event of an attack.

Technology

300

This is an attack that overloads the system and can take a victim’s Internet capabilities offline.

Distributed Denial of Service

400

This form of hacking is focused on stealing trade secrets for commercial advantage or national secrets for political or military advantage.

Espionage

400

This is a type of malware that is transferred through e-mail or malicious web sites. It can affect large numbers in an undirected fashion.

Trojan Horse

400

This is the process where a remote access Trojan or back door is added into the victim system.

Installation

400

This is a critical component of an enterprise security program. You can put the policy and technologies in place, but without cooperation from this piece, the system will not operate effectively

People

400

This attack defaces web sites or other public materials with the intent of embarrassing the victim.

Vandalism

500

This form of hacking is focused on damaging the ability of enterprises or governments to operate in cyberspace.

Cyberwar

500

This type of malware/malware feature allows the attacker to remotely control its operation within the target enterprise.

Command and Control

500

The is the last step in the Kill Chain where the objective is data exfiltration involving collecting, encrypting and extracting information from the victim environment.

Actions on Objectives

500

This element is the last piece of an effective cybersecurity program and it consists of evaluating the effectiveness of the risk mitigations, system capabilities, and operational processes.

Assessment

500

This attack involves altering infrastructure data about Internet Properties such as domain names, social media identities, or registered network locations.

Hijacking