
The 7 Stages of the Cyber Kill Chain in AWS Cloud Security
Cyber attacks follow a series of stages, from reconnaissance to achieving the attacker’s final objective. In this article, I explore the 7 stages of the Cyber Kill Chain and connect them to AWS cloud security. Learn how AWS services such as IAM, WAF, GuardDuty, CloudTrail, Inspector, and KMS can help prevent, detect, and respond to threats. Understanding the attacker’s path helps us build stronger cloud defenses.
The 7 Stages of the Cyber Kill Chain in AWS Cloud Security
As organizations continue moving their applications, data, and infrastructure to the cloud, cybersecurity threats are also evolving. Attackers can use multiple techniques to target cloud environments, from gathering information about an organization to gaining access, moving across resources, and attempting to steal sensitive data.
One useful framework for understanding how attacks happen is the Cyber Kill Chain, developed by Lockheed Martin. It describes an attack through seven stages:
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and Control
- Actions on Objectives
Understanding these stages can help AWS users think about security from an attacker's perspective and build controls that can detect or stop an attack as early as possible.
1. Reconnaissance – Gathering Information
The first stage is Reconnaissance. Attackers collect information about their target before attempting an attack.
In an AWS environment, this could include identifying publicly exposed services, domains, IP addresses, application endpoints, exposed S3 resources, or information accidentally published online.
AWS security services can help reduce this exposure.
For example:
- Amazon GuardDuty can detect suspicious activity and potential threats.
- AWS Security Hub can provide centralized security findings.
- Amazon Inspector can help identify vulnerabilities in workloads.
- AWS Config can monitor resource configurations and compliance.
The goal is to minimize unnecessary exposure and identify weaknesses before attackers can take advantage of them.
2. Weaponization – Preparing the Attack
During Weaponization, an attacker prepares the tools, malware, scripts, or other techniques they intend to use against the target.
For example, an attacker might prepare malware designed to exploit a vulnerable application or create a malicious payload intended to obtain credentials.
Although defenders cannot always see exactly how an attacker prepares their tools, AWS security teams can focus on reducing the opportunities available to those tools.
Strong IAM controls, secure configurations, vulnerability management, and application security can make it much harder for malicious tools to succeed.
3. Delivery – Getting the Attack to the Target
The Delivery stage is when the attacker attempts to deliver the malicious payload.
Common examples include:
- Phishing emails
- Malicious links
- Compromised websites
- Exploit attempts against internet-facing applications
- Malicious files
- Exposed services
For AWS workloads, services such as AWS WAF can help protect web applications against common web-based attacks.
Amazon CloudFront can also be used in front of applications to improve security and resilience, while AWS Shield helps protect against DDoS attacks.
Security isn't only about blocking every attack. It is also about reducing the number of ways an attacker can reach your workloads.
4. Exploitation – Taking Advantage of a Weakness
In the Exploitation stage, the attacker attempts to exploit a vulnerability or weakness.
This could involve exploiting:
- An unpatched operating system
- A vulnerable application
- Weak authentication
- Misconfigured cloud resources
- Excessive permissions
- Stolen credentials
For AWS workloads, vulnerability management is extremely important.
Amazon Inspector can help identify software vulnerabilities and unintended network exposure. Keeping systems patched and following the principle of least privilege can significantly reduce the attack surface.
IAM is especially important here.
A compromised account with limited permissions is much less dangerous than an account with excessive administrative privileges.
5. Installation – Establishing Persistence
If exploitation succeeds, attackers may attempt to establish persistence.
This is the Installation stage.
In a cloud environment, persistence may not always look like traditional malware installation. An attacker who obtains valid credentials could potentially create or modify resources, add access keys, change permissions, or establish another method of access.
AWS security controls can help detect suspicious changes.
For example:
- AWS CloudTrail records API activity.
- AWS Config tracks resource configuration changes.
- Amazon GuardDuty can identify suspicious account and workload activity.
- AWS IAM provides controls for authentication and authorization.
Monitoring changes to cloud resources is critical because attackers can abuse legitimate AWS functionality.
6. Command and Control – Maintaining Communication
The sixth stage is Command and Control (C2).
At this point, an attacker attempts to maintain communication with compromised systems and control them remotely.
In AWS, suspicious outbound connections or unusual API activity may provide indicators of compromise.
Security teams can use services such as Amazon GuardDuty, VPC Flow Logs, CloudTrail, and other monitoring solutions to investigate unusual network or API behavior.
Network segmentation also plays an important role.
Using Amazon VPC, security groups, network ACLs, and controlled routing can limit how compromised resources communicate with other parts of the environment.
The objective is to prevent one compromised workload from becoming a pathway to the entire environment.
7. Actions on Objectives – Achieving the Goal
The final stage is Actions on Objectives.
This is where the attacker attempts to accomplish their actual goal.
Depending on the attack, this could include:
- Stealing sensitive information
- Encrypting data for ransomware
- Destroying resources
- Modifying applications
- Stealing credentials
- Exfiltrating customer information
- Disrupting business operations
This is why protecting data is just as important as protecting infrastructure.
AWS provides multiple security mechanisms for protecting data, including:
- Amazon S3 encryption
- AWS Key Management Service (AWS KMS)
- IAM access controls
- S3 Block Public Access
- CloudTrail logging
- Backup and recovery mechanisms
Organizations should also follow the principle of least privilege and ensure that users and applications only have access to the resources they actually need.
Connecting the Kill Chain to AWS Security
The Cyber Kill Chain is useful because it reminds us that cybersecurity is not about relying on a single security product.
Instead, organizations should build multiple layers of defense.
| Kill Chain Stage | Example AWS Security Focus |
|---|---|
| Reconnaissance | Reduce public exposure, monitor assets |
| Weaponization | Vulnerability management and secure configurations |
| Delivery | AWS WAF, CloudFront, Shield |
| Exploitation | Patch management, Inspector, IAM |
| Installation | CloudTrail, Config, GuardDuty |
| Command & Control | VPC controls, Flow Logs, GuardDuty |
| Actions on Objectives | Encryption, KMS, S3 security, backups |
The important idea is defense in depth.
If an attacker gets past one security control, another control should be available to detect, contain, or stop the attack.
Final Thoughts
The Cyber Kill Chain provides a useful way to understand how an attack can progress from initial reconnaissance to the attacker's final objective.
In AWS, security should not focus only on preventing attacks. Organizations should also be prepared to detect, investigate, respond, and recover when something goes wrong.
By combining services such as IAM, AWS WAF, Amazon Inspector, Amazon GuardDuty, AWS CloudTrail, AWS Config, AWS Security Hub, AWS KMS, and Amazon S3 security controls, organizations can create multiple layers of protection around their cloud workloads.
The key lesson for me is simple:
Don't wait until an attacker reaches the final stage. Detect and stop the attack as early in the Kill Chain as possible.
Understanding the attacker's path helps us build a stronger defensive strategy in the AWS cloud.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article