Introduction to the Cyber Kill Chain

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

7 hours 6 minutes
Video Transcription
Hey, everyone, welcome back to this course in this video. We're gonna talk briefly about the cyber kill chain from Lockheed Martin. So we're just gonna talk about some of the steps in the Lockheed Martin Cyber kill chain.
So the steps we have our reconnaissance weaponization delivery, and we're gonna talk about each of these individually, we've got exploitation, installation,
the command and control. And then finally, the actions on objectives. So once the Attackers actually get in, maintain a foothold, then it's OK. Now, let's go ahead and complete our actual objective. It might be stealing data. It might be destroying data, corrupting data, lots of different things that might be
so. Let's talk about reconnaissance. Our reconnaissance is as we
no. From a previous lesson when we talked about re Kon as a step in pen testing methodology, Reconnaissance is just gathering that information, right? So what kind of information can the adversary potentially gather? Well, things like I p addresses, email, information, host or network information could be also identifying different vulnerabilities.
The attacker may also be identifying employees over on social media that might be good targets for social engineering attacks.
Also, there might be looking for information around any contracts awarded. So
the adversary might be looking at press releases because a lot of companies, when they get a contract like a major contract,
they'll put out a press release basically just saying Hey, look at us. We landed a contract with Company X, so that might be a way that the attacker could either get in through the third party, that that the other person on that contract, or the order that they may be able to use that as a conversation piece
for social engineering. They might be able to contact someone that works with the company on social media
and say, Hey, congrats on the contract, Great job. And then they could build a report from there and then exploit that relationship
weaponization. So the attacker is basically gonna use a weapon, Isar. And so all that does is that it's a tool that couples malware with on an exploit into basically a delivery herbal payload.
It could be they get it from a public or private channel, right? So buying it on a marketplace or they may just write their own,
and then once they've got that, the Attackers going to select the delivery method. It could be, um, in the sense of like a phishing email. It could be that they create a document that this malware lives in. And then that's gonna be what the employee or the victim opens up and it installs, um, our on the device.
Next we have delivery. So this is where the adversary has actually launched the malware to the target. So it could be
through things like phishing attacks, where they embedded in a document. It could also be three USB drop attacks where they take a USB, put them our on it, maybe put an image file or something, and drop that in a parking lot with some keys on it. So it looks like it's somebody dropped their keys and then do gooders as I call them. We'll go and pick it up in the parking lot, go inside.
You know, ask around. Usually, like who's is this? Everyone says, No, it's not mine.
They'll plug it in. Maybe there's a file on there that could help them identify who it is and poof. Now there's Mauer on theknot phonies. Device could also be through social media, right? Could I could send you a document and say, Hey, are you having trouble? Uh, maybe I target your sales team member, right? And I say, Hey, if you're having trouble with sales, this step by step guide, always help me, right?
So they
Oh, thanks so much for sharing right. They click it, they opened it
unsuspecting. It's a step by, you know, a little step by step guide or some tips on sales or whatever. I just create something. But in there I've embedded malware, right and they don't even know. And it's now downloaded on the company machine
and things like watering hold attacks. So if I know that
people that a certain company always
order their food from a Chinese restaurant at lunchtime, then I can actually just go ahead and create a watering hole attacks. So instead of them going to the actual Chinese website and create a mirror site, I can create a site that looks like it, or I can also just embed malware on that website and
every time they go there to order their food, I'm downloading malware in the background on their machine
exploitation. So to get access, the attacker has to exploit, right, they have to exploit the vulnerability. Um, it could be a zero day exploit. They may use something that's previously unknown. They might also a lot of times just use, uh, they might just exploiting vulnerability, right? A common one that's out there because a lot of organizations still
are not patching their vulnerabilities effectively
installation. So the attacker wants to maintain the access, right? So once you've done all this work to
exploit that vulnerability, all that someone really has to do is put a patch in place and fix their vulnerability, right? And then, poof, you lose access. However, if you install something like a back door, you can potentially maintain persistent access. And that's what the attacker wants to do, right? They want to install that backdoor backdoor. That may also do things like
doing time storm
where they change the time on the file. So it makes it look like the Mauer is actually part of like the operating system installed. So they basically put it at a previous time commanding controls. This is where the Mauer opens the channel communication back to the control. Essentially right. So
think of it. And if you ever watch Star Trek the next generation? Think of it like the Borg ship.
Ah, Borg ship or the border themselves were tied into what was called the collective, and so they would send information back to the collective and the collective would send information to them That's in in that. In that example, that's what the command and control is, right. There's the attacker system and it's sending
information or instructions back to the victims system. And the victim system is sending potentially information or whatever
back to the command control server, then the actions on objectives. So again, this could vary. It could be things like harvesting log in credentials to be used for a privileged escalation attacks. It could be performing internal reconnaissance. It could be a lateral movement throughout the target
environment. Right, So maybe I compromise one system, and then I wanna move laterally through
to compromise as many systems I can could be extra illustrating data, so data theft could be destroying data. Right? Or destroying systems. Maybe I do end up doing a DDOS attack and break your system. Right brick brick. Your Web server could be corrupting the data, right? Overriding the data
or otherwise modifying the data. So a lot of different things they might do once they're in and they've established a foothold.
So just a quick quiz question here in what stages the kill chain would attacker provide a U. S. B to the victim
with the exploitation of weaponization or delivery?
All right, so if he gets delivery, you are correct, right? So, again, thinking through, especially in that example, I deliver the U. S. B. So I go drop into the parking lot. I'm delivering it. Kind of like a FedEx or U S ups, right? I deliver it to the parking lot and then some unsuspecting person takes that plugs it in and poof. Now the organization has malware just like magic.
So in this video, we just went through the steps in the Lockheed Martin killed chain
Up Next