Breaking Cyber Kill Chains®
by Marcus J. Ranum on October 29, 2014
The “cyber kill chain®”1 is a model for framing an incident response/analysis capability that was developed by Lockheed Martin’s Computer Incident Response Team. It is a useful framework for talking about and reasoning about why and how we do things in security. The term “kill chain” is admittedly violent when you consider that we're talking about an environment in which, ideally, nothing of the sort is happening.