skip to content

Cyber Kill Chain: does filtering Delivery and patching Exploitation break the chain?

level: seniorimportance: should knowfreq 47%

answer

  1. which two links were named
  2. scope of each claim, path by path
  3. a path with no arrival and no flaw
  4. what exactly is being falsified
  5. domain of validity, not discard or defend

basics

~20 s

No. It interdicts paths that need those two links and says nothing about paths that need neither. A bought remote-access credential traverses no delivery and no exploit, so both claims are true and the chain still completes.

solid answer

~50 s

The claim conflates two links with all seven. Filtering what arrives is a statement about **Delivery**; a fully patched estate is a statement about **Exploitation**. Both can be entirely true while an intrusion completes, because the break-one-link argument only bites on links the path actually traverses. Hand it the counter-example: an affiliate buys a working remote-access credential into a managed-service provider's shared tenancy and their first act is Actions on Objectives — nothing arrived and no software flaw was reached, so stages three and four hold nothing to break. Notice what that falsifies: the **interdiction claim as stated**, not the estate's posture, which may be excellent. The right conclusion is neither to discard the model nor to defend it whole, but to state its domain of validity — a delivery-era argument, sound for paths that traverse in order from the front — and then ask which plausible paths those two controls sit on.

go deeper

for a junior

Recognise that filtering what arrives speaks only to Delivery and patching speaks only to Exploitation. Two named stages are not the same as all seven.

for a middle

Be able to produce a concrete path that traverses neither of those links and explain, stage by stage, why each is empty on it. A general objection without an example rarely convinces a reviewer.

for a senior

Show you can name precisely what the counter-example falsifies — the interdiction claim's universality, not the estate's posture — and then redirect the review to which links each plausible path requires. Resist both discarding and relabelling.

for a principal

Own how a stage-coverage claim gets used outside the room: reported as assurance to people who will not read the caveat. Decide what your reporting must state alongside coverage so it cannot be read as a completeness guarantee.

## The claim as made A reviewer says: *"we filter delivery and we are fully patched, so the chain is already broken."* It is a confident, well-formed argument. It cites the model correctly, it cites two real control classes, and it reaches a conclusion the model does appear to license. It is also wrong, and the way it is wrong is the single most useful thing this leaf teaches. ## Unpacking what each half establishes **"We filter delivery."** This is a claim about stage three. It says that things arriving by the carriers you filter do not reach their destination in a usable state. Its scope is exactly the set of paths on which something has to arrive. **"We are fully patched."** This is a claim about stage four. It says that a path requiring a known software flaw will not find one. Its scope is exactly the set of paths on which something must be subverted to run. Both statements can be completely true. Neither is a statement about a path on which nothing arrives and nothing is subverted. ## The counter-example, and what it is a counter-example to An access broker sells a position into a managed-service provider's shared tenancy: a working remote-access credential together with a delegated administration path. An affiliate buys it and connects. The remote-access service accepts the credential — correctly, on the inputs it was given. Standing access is already durable, so nothing needs installing. The service itself carries the operator's instructions. The buyer's first action is the objective. Walk the two claims against that path. The Delivery control never engages, because nothing was delivered. The patch posture never engages, because no flaw was reached. Two links were broken with great care and the intrusion did not touch either of them. Be precise about the target of the refutation, because this is what separates a senior answer from a clever one: the example does not show the estate is badly run, and it does not show that filtering and patching were wasted. **It falsifies the universality of the interdiction claim.** The claim "break any one link and the intrusion fails" is sound wherever the intrusion needs the link, and empty wherever it does not. ## The conclusion that is actually correct Two bad conclusions are on offer and both are common. *Discard the model.* Tempting, and wrong. For an intrusion that really does begin with research, build a carrier, send it, subvert something, persist, open a channel and then act, the seven-stage argument is cheap, communicative and correct, and it attributes controls to stages in a way that non-specialist readers follow. *Defend it whole.* Also wrong, and usually defended by relabelling: calling the credential purchase a "delivery" or the accepted authentication an "exploitation". Relabelling preserves the diagram by making its stages mean nothing, and it produces exactly the false comfort the reviewer started with. The correct move is to **retain the model with a stated domain of validity**. Say it out loud when you use it: this is a delivery-era interdiction argument, and it applies to paths that traverse the links in order from the front. For a path that enters mid-sequence, the argument makes no promise, and the analysis has to begin where the path begins. ## What that changes in the review The reviewer asked the wrong question. "Are these links broken?" invites a yes and stops. The question that produces work is: **for each intrusion path we consider plausible against this estate, which links does that path actually need, and which of our controls sits on one of them?** For a path that begins with bought or already-held access, the answers are all in the second half of the sequence: authentication that a resold secret alone cannot satisfy; limits on what standing third-party access can reach once it is inside; and controls at the objective itself, so that reaching the position is not the same thing as achieving the goal. That reframing also protects you from the mirror-image error. Nothing here argues for spending less on patching or on filtering what arrives. Those controls are load-bearing on a large fraction of real paths. The argument is about **what a stage-completeness claim licenses you to conclude** — and two broken links licenses you to conclude only that paths needing those two links are interdicted. ## Saying it well "Both statements are true and neither is a claim about a path with no delivery and no exploit on it. Here is such a path. So the model's break-one-link argument holds for delivery-era intrusions and makes no promise about entered-mid-chain ones — which means the review question is which links our plausible paths need, not whether these two are broken." That is the whole answer, and it lands because it corrects the reasoning without attacking the estate or the model.

  • The reviewer answers that buying access is 'really just delivery'. How do you respond?
    That relabelling saves the diagram by emptying the stage. Delivery means something arrived at the target by a carrier you can act on; a purchase happens outside your estate, in a market, and no filter of yours is between the two parties. If any origin of access counts as delivery, then 'we filter delivery' stops constraining anything and the comfort it was providing was never real.
  • So do you keep using the seven-stage chain at all?
    Yes, with its domain stated. For intrusions that traverse from Reconnaissance forward it is a cheap, well-understood way to attribute controls to stages and explain interdiction to non-specialists. What you stop doing is quoting stage coverage as though it settled a question about paths that enter mid-sequence, because there the argument makes no promise either way.
  • What question should the review have asked instead?
    For each plausible intrusion path against this estate, which links does that path actually require, and which of our controls sits on one of them? That is answerable, it forces the mid-chain-entry paths into the conversation, and it produces a different investment list from the one you get by ticking stages.

saying these in an interview costs you the question

  • Accepts that two broken links proves the chain cannot complete
  • Relabels a purchased credential as a Delivery stage
  • Calls an accepted credential an Exploitation stage
  • Discards the whole model on one counter-example
  • Concludes the estate is badly run rather than the claim overreaching

context