skip to content

ATT&CK, Kill Chain and TTPs

You will learn what the kill chain, the ATT&CK catalogue, the Diamond Model and the Pyramid of Pain each claim about an adversary. Interviewers use them to hear whether you think in campaigns.

on this pageshow

explore

questions

page 2 of 2

Cyber Kill Chain: does filtering Delivery and patching Exploitation break the chain?

level: seniorimportance: should knowfreq 47%

basics

~20 s

No. It interdicts paths that need those two links and says nothing about paths that need neither. A bought remote-access credential traverses no delivery and no exploit, so both claims are true and the chain still completes.

open as a page

ATT&CK lists mitigations for a technique and your estate implements all of them. Is it handled?

level: seniorimportance: should knowfreq 42%

basics

~20 s

No. The mitigations section is an unordered list of general control classes, not a specification and not a completeness claim. Some techniques carry an explicit note that preventive controls cannot mitigate them, because they abuse legitimate functionality.

open as a page

Why is Defense Evasion an ATT&CK tactic column rather than a label for any quiet action?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

Defense Evasion names a goal an operator spends effort on: steps taken specifically to avoid or degrade controls. Being inconspicuous by accident is not Defense Evasion. Used as an adjective, the column tags everything and stops naming a choice.

open as a page

Initial-access brokers resell entry: what does that do to the cost of breaking early kill-chain links?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

It decouples the two. The broker traverses Reconnaissance through Exploitation once and sells the result many times, so interdicting those links taxes the broker's amortised production cost, while the buyer's entry cost is only a listing price.

open as a page

Two accounts of the same intrusion map to 6 and 19 ATT&CK techniques — what does the gap measure?

level: seniorimportance: nice to knowfreq 29%

basics

~20 s

It measures the accounts, not the intrusion: how much each author could see, how much they chose to write, how far each mapper inferred, and how much of each text was behaviour at all. It says nothing about adversary sophistication.

open as a page

Your Active Directory has one host with unconstrained delegation. How does that reorder ATT&CK techniques?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

It promotes a thinly evidenced technique over a heavily evidenced one. A host trusted for unconstrained delegation caches the Kerberos ticket of whatever authenticates to it, so coercing a privileged account there reaches the directory in one step.

open as a page

Where does the Pyramid of Pain mislead you about a crew that signs every build with one stolen key?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

The pyramid assumes bottom-rung values are by-products a crew regenerates for free. A stolen code-signing key is a scarce asset carrying vendor trust - burning it costs more than every domain they own. The ordering inverts at the bottom.

open as a page

ATT&CK ships two releases a year - do you re-map five years of technique mappings or pin a version?

level: principalimportance: nice to knowfreq 26%

basics

~10 s

Do both, selectively. Migrate mechanically resolvable identifiers on a schedule and keep the originals, never back-fill granularity nobody recorded, and stamp every mapping with its release. Pinning forever fails because everyone else moves.

open as a page

Which ATT&CK matrix scopes an estate whose flat segment mixes office hosts with building-automation controllers?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Both, scoped per asset group rather than per estate: Enterprise for the office hosts, ICS for the controllers. The decision matters because naming a matrix names which adversary goals are in scope, and therefore whose budget owns the gap between them.

open as a page

Your remediation list blocks command lines one by one — how do you state ATT&CK technique risk to the owner?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

State the claim in the adversary's currency: say which procedures are closed, what respelling costs the operator, and that the technique class remains open. Never let a procedure-shaped item close a technique-shaped one, even under schedule pressure.

open as a page

Is 'reached Kill Chain stage N of seven' a sound way to score every intrusion for leadership?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

No, as a universal score. An ordinal assumes every episode traverses the same stages once, in order, so it is undefined for one that repeats a goal and skips several. Offer instead: objective reached or not, which goals were observed, and time to that point.

open as a page

A Diamond Model pivot names an uncontracted peer company as the victim vertex — do you warn them, and on whose authority?

level: principalimportance: nice to knowfreq 21%

basics

~20 s

Usually yes, but not as an engineer acting alone and not as a conclusion. The call needs an owner inside your organisation, and what you hand over is the dated artefact and the narrow edge, never a verdict about the other company's estate.

open as a page

A people-risk owner demands an ATT&CK technique ID for a permitted insider export. What do you tell them?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

No honest identifier exists: the catalogue records behaviour and goals, never permission. Negotiate the form rather than the fact - offer a plain description, map only a genuinely technical step, and ask that the field accept a written reason.

open as a page

showing 31–43 of 43