ATTACK ANATOMY & LIFECYCLE

Interactive Kill-Chain Step-Through

Deconstruct the progression of high-impact cyber intrusions from initial reconnaissance to catastrophic enterprise impact. Examine tactics, techniques, and critical defensive interception opportunities.

Key Facts

  • Interactive step-through breakdown of cyberattack lifecycles mapped to the unified kill chain.
  • Analyze how initial minor entry points cascade into catastrophic enterprise-wide outages.
  • Each phase highlights critical defensive choke points where detections can sever the chain.
  • Examine empirical evidentiary exhibits from landmark federal cyber prosecution records.
STAGE 01

1. Reconnaissance & Weaponization

Adversaries gather intelligence on target personnel, external IP perimeters, exposed SaaS instances, and software vulnerabilities before initiating intrusion.

Standard Adversary Techniques:
  • OSINT research on LinkedIn
  • External network scanning (Shodan/Censys)
  • Acquiring zero-day exploits or credential dumps
Empirical Precedent: Target (2013): Reconnaissance focused on heating/ventilation contractor Fazio Mechanical, discovering vendor billing portal.
STAGE 02

2. Initial Access

Adversaries cross the enterprise boundary into internal networks or cloud environments.

Standard Adversary Techniques:
  • Spear-phishing with malicious attachments
  • Exploitation of edge VPNs/firewalls (Citrix/Ivanti)
  • Helpdesk vishing and MFA token resets
Empirical Precedent: Change Healthcare (2024): Remote Citrix access gained using compromised enterprise credentials without MFA.
STAGE 03

3. Execution & Persistence

Malicious code executes on host machines and secures survivability across system reboots.

Standard Adversary Techniques:
  • PowerShell / WMI command execution
  • Registry run keys and scheduled tasks
  • Installing web shells on DMZ servers
Empirical Precedent: SolarWinds (2020): SUNBURST backdoor executed within Orion memory, maintaining persistence across 18,000 systems.
STAGE 04

4. Privilege Escalation & Lateral Movement

Adversaries harvest credentials to elevate privileges to Domain Admin, traversing across VLANs and subnets.

Standard Adversary Techniques:
  • Mimikatz LSASS memory dumping
  • Pass-the-Hash / Kerberoasting
  • PsExec / RDP session hijacking
Empirical Precedent: Colonial Pipeline (2021): Threat actor moved laterally from legacy VPN segment into active directory domain controllers.
STAGE 05

5. Impact & Objectives (Exfiltration / Encryption)

Adversaries execute final operational objectives: data theft, ransomware extortion, or physical/operational disruption.

Standard Adversary Techniques:
  • Ransomware deployment across VMware ESXi clusters
  • Multi-gigabyte cloud exfiltration via Rclone
  • Raw disk wiping and Master Boot Record overwrite
Empirical Precedent: NotPetya (2017): Automated execution of EternalPetya wiper corrupting MBR and MFT across all reachable domain hosts.

The Defensive Paradox: Severing the Chain Early

An attacker must successfully execute every successive link in the kill-chain to accomplish their ultimate operational objective. Conversely, defensive operations succeed by breaking a single link. Implementing phishing-resistant MFA, network microsegmentation, and automated egress monitoring neutralizes lateral movement before exfiltration or mass encryption occurs.