Which Cyber Kill Chain links does a buyer of working VPN credentials never traverse?
answer
- count which links are empty
- who did the early stages, and when
- an accepted credential is not an exploit
- the earliest link the buyer touches
- standing access already is the persistence
basics
~10 sReconnaissance, Weaponization, Delivery and Exploitation. The buyer's path begins no earlier than Installation, and where the purchased access is itself standing access, their first act is Actions on Objectives.
solid answer
~50 sAn affiliate who buys a working remote-access credential enters the sequence in the second half. Stages one to four — Reconnaissance, Weaponization, Delivery, Exploitation — did not happen for them: nothing was researched about this estate by them, no payload was built, nothing was delivered, and no software flaw was triggered, because a valid credential being accepted is authentication working as designed. The earliest link they can touch is **Installation**, and in the case that makes this leaf interesting — a purchased remote-access credential into a managed-service provider's shared tenancy, sold together with a delegated administration path — even Installation is redundant, because standing access already gives what Installation exists to obtain. The four early links did occur, but for the broker, earlier, and possibly against many estates. So per-victim controls placed on those links interdict nothing on this path: there is no link there to break.
code
text · 9 linesCyber Kill Chain (Lockheed Martin, 2011) This intrusion
1 Reconnaissance -> not traversed by the buyer (broker's work, months earlier)
2 Weaponization -> not traversed (nothing was built)
3 Delivery -> not traversed (no message, no download, no media)
4 Exploitation -> not traversed (a valid credential was accepted, not a flaw)
5 Installation -> optional here: the purchased access IS the standing access
6 Command and Control -> the remote-access service is the channel
7 Actions on Objectives -> the buyer's FIRST action
...go deeper
Know that an intrusion can begin with access someone already has or has bought, and that no message and no software flaw need appear anywhere on such a path. Be able to say a valid credential being accepted is not an exploit.
Walk the seven stages against the bought-access path out loud and justify each blank link. Expect to be pushed on Exploitation specifically, and on whether Installation is required when the purchased access is already standing.
Show you can separate 'this party did not traverse the link' from 'nobody ever performed it', and draw the operational consequence: which control classes touch a path that has neither a delivery nor an exploit on it.
Be ready to say what a narrative standard should require of an analyst when four of its seven boxes are blank — leaving them blank, marking them out of scope, or reporting two chains for two parties are different organisational choices with different downstream readers.
## The scenario An access broker sells a position: a working remote-access credential into a managed-service provider's shared tenancy, together with a delegated administration path that reaches the provider's customers. An affiliate buys it. Their first action inside the estate is to go after what they came for. Narrate that with the seven-stage chain and something strange happens: most of the diagram is empty. ## Link by link, for the buyer **Reconnaissance — not traversed.** The buyer did not research this estate. They read a listing. Someone did reconnaissance, but it was the broker, at a different time, and quite possibly as an untargeted sweep that happened to include this estate. **Weaponization — not traversed.** Nothing was paired with a carrier. There is no document, no installer, no crafted object at all. There is a username, a secret and a service that accepts them. **Delivery — not traversed.** Nothing was sent to anybody. No message arrived, nothing was downloaded, no media was plugged in. The buyer connected to a service that exists for people to connect to. **Exploitation — not traversed, and this is the one people get wrong.** Presenting a valid credential to a service that then accepts it is not exploitation. No memory is corrupted, no logic is subverted, no unpatched component is reached. The authentication decision was made correctly on the inputs it was given; the inputs were simply someone else's. A path with no exploit on it cannot be interdicted by removing exploitable code. **Installation — optional.** Installation exists so that access does not depend on repeating Delivery and Exploitation. When the thing you bought is standing remote access plus a delegated administration path, that requirement is already satisfied at purchase. The buyer may still add something of their own, and if they do, this link genuinely returns to the narrative — but it was not required to get started. **Command and Control — satisfied by design.** The remote-access service is the channel. It is meant to carry an operator's instructions to the estate; it does not care which operator. **Actions on Objectives — the first act.** In a clean bought-access intrusion this is where the buyer's story begins, which is a genuinely disorienting thing to write on a stage diagram. ## What this does, and does not, prove It is tempting to conclude that the kill chain is broken as a model. That is the overreach. What the example falsifies is the **universality of the interdiction claim**, not the model's usefulness on the paths it was built for. The claim "break one link and the intrusion fails" is sound whenever the intrusion needs the link. Here, four of the seven links are not needed by this party, so interdicting them removes nothing from this path — there is nothing there to remove. Note carefully what the early stages' absence does *not* mean. It does not mean nobody performed them. Reconnaissance and, very often, an exploited internet-facing service or a stuffed credential is exactly how the broker produced the listing. The stages happened; they happened **for a different party, at a different time, and amortised across an inventory of victims**. The buyer inherited the *result* without traversing the *path*. If you narrate the whole affair as one intrusion by one actor, the chain looks complete and you will draw the wrong conclusion; if you narrate the buyer's intrusion, four links are blank. ## The same shape, other origins Bought access is the cleanest example but not the only one. Any position that already exists enters mid-sequence: a person who holds legitimate access and turns it to their own ends traverses none of the first four links either, because their access was granted, not obtained. The shared feature is the one that matters for the model — **entry with no exploit and no delivery anywhere on the path**. ## How to answer this in a loop Name the four links, say why each is empty, and then say the sentence the interviewer is waiting for: the earliest link this party touches is Installation, and where the purchased access is itself persistent, even that is skipped. Finish with the consequence rather than a verdict on the model — a control class attached to Delivery or Exploitation is not a claim about a path that traverses neither.
- Did those first four stages happen at all, or did nobody ever perform them?They happened, but for the broker and earlier — very often as untargeted sweeping or credential stuffing across many estates at once. The buyer inherits the result, not the path. That distinction matters: narrate the whole affair as one actor and the chain looks complete; narrate the buyer's intrusion and four links are blank, which is the version that tells you what an interdiction would have to touch.
- If the buyer deploys their own remote-access software after entering, does Installation come back?Yes, that single link returns to the narrative, and it becomes a real place to interdict this path. The first four do not come back with it. This is the useful test: ask which links the path actually needs, and place your argument only on those, rather than assuming a full sequence because the diagram has seven boxes.
- Why is presenting a stolen credential not classed as Exploitation?Exploitation means subverting a mechanism so something runs that should not — a memory corruption, a logic flaw, an unpatched component. Authentication that accepts a valid secret has not been subverted; it made the correct decision on the inputs it received. Classing it as exploitation leads directly to the wrong conclusion that patch state protects the path.
saying these in an interview costs you the question
- Calls an accepted stolen credential an exploit
- Says the model still applies because the broker did the early stages
- Assumes a path must begin at Reconnaissance
- Claims bought access is just a very fast Delivery stage
- Concludes the model is worthless rather than bounded