skip to content

The Break-One-Link Claim

Lockheed Martin's seven stages make one claim: break any single link and the intrusion fails. Interviewers ask because most people recite the stages and then dismiss the model for the wrong reason.

on this pageshow

explore

questions

4

Which Cyber Kill Chain links does a buyer of working VPN credentials never traverse?

level: middleimportance: must knowfreq 52%

basics

~10 s

Reconnaissance, Weaponization, Delivery and Exploitation. The buyer's path begins no earlier than Installation, and where the purchased access is itself standing access, their first act is Actions on Objectives.

open as a page

Cyber Kill Chain: does filtering Delivery and patching Exploitation break the chain?

level: seniorimportance: should knowfreq 47%

basics

~20 s

No. It interdicts paths that need those two links and says nothing about paths that need neither. A bought remote-access credential traverses no delivery and no exploit, so both claims are true and the chain still completes.

open as a page

Initial-access brokers resell entry: what does that do to the cost of breaking early kill-chain links?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

It decouples the two. The broker traverses Reconnaissance through Exploitation once and sells the result many times, so interdicting those links taxes the broker's amortised production cost, while the buyer's entry cost is only a listing price.

open as a page