Modernizing the Kill Chain
One consideration before implementing this framework is whether defenders should use the original Intrusion Kill Chain framework or use an updated version of it. There are several ways this framework can be modernized. The ATT&CK framework is an example of a modernized Intrusion Kill Chain. At the time of writing, the current version (ATT&CK version 12.0) provides 14 tactics instead of the 7 stages provided by the original Intrusion Kill Chain framework.
Although tactics and stages are slightly different, the concept is the same – understanding how attackers initially compromise and penetrate enterprise IT environments enables defenders to better protect, detect, and respond to those attacks.
I’ll give you some ideas how the original Intrusion Kill Chain can be modernized in this section. However, don’t be afraid to embrace the notion of iterative improvement based on your organizations’ experiences with this...