1.6 KiB
1.6 KiB
Security Killchains
Frameworks of killchains are inherited from the military and separate steps in which an attack occurs.
Lockheed & Martin
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command & Control
- Actions on Objectives
Mitre ATT&CK Matrix
Mitre ATT&CK is a matrix of Tactics, Techniques and Procedures (TTP) of adversaries called Adanced Persistent Threats (APT). The tactics are
- Reconnaissance
- Resource Development
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Exfiltration
- Impact
Crowdstrike as a threat intelligence tool is built on the Mitre ATT&CK framework.
Unified Cyber Kill Chain
The Unified Cyber Kill Chain is the youngest and
most detailed framework and builds upon the other frameworks. It contains combined
stages which are seen as lifecycles with potentially repeatable steps.
- Reconnaissance
- Weaponization
- Delivery
- Socical Engineering
- Exploitation
- Persistance
- Defense Evation
- Command & Control
- Pivoting
- Discovery
- Privilege Escalation
- Execution
- Credential Access
- Lateral Movement
- Collection
- Exfiltration
- Impact
- Objectives
Mentioned lifecycles are Inital Foothold, Network Propagation and
Actions on Objective