H3AD-REF / REFERENCES / ATTACK LIFECYCLE & ADVERSARY MODELS

How the Intrusion Unfolds.
And Who's Behind It.

The attacker's side of the ledger. Kill Chain and Courses of Action Matrix map the stages of an intrusion against what stops each one; Pyramid of Pain and Diamond Model describe what you pivot on and who's on the other end. ATT&CK catalogs the techniques — D3FEND is its direct defensive answer.

PART OF A 4-FILE SERIES ON SECURITY FRAMEWORKS & MODELS Attack Lifecycle & Adversary Models · Incident Response & Analysis Models · Defensive & Hunting Maturity Models · Threat Intel Cycles

Cyber Kill Chain

Lockheed Martin, 2011. Seven stages an intrusion has to pass through in order. Break any link and the chain stops.

01
RECON
Harvest emails, org info, exposed tech stack
›
02
WEAPONIZE
Pair an exploit with a deliverable payload
›
03
DELIVER
Transmit it: phishing, USB, watering hole
›
04
EXPLOIT
Trigger the vulnerability, execute code
›
05
INSTALL
Drop malware, establish persistence
›
06
C2
Open a channel for remote control
›
07
ACT ON OBJECTIVES
Exfil, destroy, encrypt — the actual goal
DEFENDER TAKEAWAY

Break Any Link, Stop the Chain

Detection is cheapest at the earliest links. Catching phishing at Delivery costs a mail rule; catching the same intrusion at Actions on Objectives costs an incident. Map each detection you own to a stage — gaps cluster late, where they're most expensive.

Courses of Action Matrix

Lockheed Martin's own defender-side pairing for the Kill Chain. Six DoD IO actions crossed with all seven stages — the cell is where you decide what tooling goes to work.

Action Recon Weaponize Deliver Exploit Install C2 Actions on Obj.
Detect ●●●●●●●
Deny ●—●●●●—
Disrupt ——●●—●—
Degrade —————●—
Deceive ●————●●
Destroy ——————●
WORKED EXAMPLE

Exploitation × Deny/Detect/Disrupt

Patching denies the exploit outright; HIDS detects it passively as it runs; DEP/ASLR disrupts it mid-execution. One kill-chain stage, three independent layers — the matrix is how you check you're not relying on just one.

Pyramid of Pain

David Bianco. Six indicator types stacked by how much pain it causes the attacker when you detect on them. Bottom is trivial to change; top forces them to change how they operate.

TTPs TOOLS NETWORK/HOST ARTIFACTS DOMAIN NAMES IP ADDRESSES HASH VALUES ↑ HARDEST TO CHANGE ↓ TRIVIAL TO CHANGE
TTPsTOUGH!Detecting behavior forces a change in tradecraft, not just tools
ToolsCHALLENGINGForces them to rebuild or replace the attack tool itself
Network / Host ArtifactsANNOYINGRegistry keys, file paths, user-agent strings — forces retooling
Domain NamesSIMPLECosts a few dollars and minutes to register a new one
IP AddressesEASYRotated via proxy, VPN, or cloud host in minutes
Hash ValuesTRIVIALChanges completely with a single byte of the file
APEX = HIGHEST PAIN FOR THE ATTACKER — BASE = TRIVIAL TO CHANGE

Diamond Model

Caltagirone, Pendergast & Betz, 2013. Every intrusion event reduces to four core features and how they connect.

who ADVERSARY how CAPABILITY over INFRA against whom VICTIM
↕ Social-Political Axis — Adversary ↔ Victim↔ Technical Axis — Capability ↔ Infrastructure
Every event = an Adversary using a Capability over Infrastructure against a Victim. Pivot along any edge to find the next node in the intrusion.
META-FEATURES LOGGED PER EVENT
TIMESTAMP PHASE RESULT DIRECTION METHODOLOGY RESOURCES

MITRE ATT&CK (Brief)

A knowledge base of adversary tactics and techniques, not a lifecycle. Structure only here — for technique-by-technique hunting content, see TTPHUNT.

THE WHY

Tactics

14 categories, Reconnaissance through Impact
The adversary's tactical goal for a given step — Initial Access, Persistence, Lateral Movement, and so on. Columns of the ATT&CK matrix.
THE HOW

Techniques

Specific methods under each tactic
How a tactic gets achieved — e.g. T1059 Command and Scripting Interpreter under Execution. Each carries a unique ID for mapping and reporting.
THE VARIANT

Sub-Techniques

More specific implementations of a technique
E.g. T1059.001 PowerShell as a sub-technique of Command and Scripting Interpreter. Narrows detection logic to the exact mechanism used.
THE USE

Matrix Use

What analysts actually do with it
Map existing detections against the matrix to find coverage gaps, tag incidents by technique for trend analysis, and scope purple-team emulation plans.

MITRE D3FEND

ATT&CK's defensive counterpart. 241 techniques (v1.6.0) across 7 tactics — knowledge graph, not a lifecycle, but reads as one: harden, then detect, then contain and recover.

01
HARDEN
Make exploitation harder and costlier up front
›
02
DETECT
Identify adversary access or activity
›
03
ISOLATE
Logical or physical barriers restrict access
›
04
DECEIVE
Honeypots, decoy accounts, fabricated data
›
05
EVICT
Remove the adversary from the network
PLUS TWO NON-LINEAR CATEGORIES: MODEL (ONTOLOGY) AND RESTORE (RECOVERY)