Kill Chain
Updated July 21, 2026
Originally military/cyber; in CI, the sequence from strategic decision to market impact (hire -> build -> launch -> promote).
Also known as: Cyber Kill Chain, Intrusion Kill Chain, F2T2EA, Find-Fix-Track-Target-Engage-Assess
A kill chain is a sequenced model that decomposes an attack into discrete stages from initial target identification through final objective, designed so a defender can break the sequence at any link. The attraction is structural: each stage is a checkpoint an analyst can observe, defend against, or disrupt, so a single broken link invalidates the rest of the chain. The same logic transfers to any domain where an attacker must pass through a predictable sequence to reach an outcome.
The term originated in military doctrine, where the kill chain describes the end-to-end structure of an attack from finding a target to assessing its destruction. The U.S. Air Force F2T2EA model captures this as Find, Fix, Track, Target, Engage, Assess. In 2011 Eric Hutchins, Michael Cloppert, and Rhett Amin of Lockheed Martin adapted the concept to information security in "Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains", defining a seven-stage intrusion kill chain from reconnaissance through actions on objective that became the standard reference for the cyber usage.
Competitive intelligence borrowed the kill chain as a metaphor, not a doctrine. The CI variant describes the sequence a competitor traverses from an internal strategic decision to observable market impact: executive hire, engineering ramp, patent or beta activity, pricing or page reset, launch keynote, PR and analyst push, campaign air cover. It treats each stage as a detection opportunity. Earlier stages offer more lead time. The application is honest about being a borrowing: the stages are not canonical and competitors vary in which ones they pass through.
From F2T2EA to the Lockheed Martin kill chain
The military kill chain describes an attack as an end-to-end sequence rather than a single event, so defenders can reason about where to break it. The U.S. Air Force F2T2EA model breaks the sequence into Find, Fix, Track, Target, Engage, and Assess, where each step depends on the last and failure of any step invalidates the rest. Defense, by inversion, means denying the opponent any one link.
In 2011 the Lockheed Martin Computer Incident Response Team published "Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains", authored by Eric Hutchins, Michael Cloppert, and Rhett Amin. That paper reframed the military kill chain as an intrusion kill chain and proposed a seven-stage model that became the most cited reference in cybersecurity. The contribution was not the metaphor alone but the pairing of each stage with a defensive action: detect, deny, disrupt, degrade, deceive, contain. That turned reconnaissance into a concrete intervention point rather than a vague early warning.
The seven stages and where defenders intervene
The Lockheed Martin chain runs reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objective. Reconnaissance happens outside the defended network, which is also the model's biggest detection gap: much of what an attacker does to choose a target leaves little trace inside the perimeter. Weaponization is similarly invisible. Visibility improves from delivery onward, where mail gateways, endpoint telemetry, and network logs start to record evidence.
Each stage pairs with a defensive course of action. Detect means establishing that an intrusion is underway. Deny means blocking information disclosure or access. Disrupt and degrade intervene against command and control channels, while deceive feeds false information back through them. Contain uses network segmentation to limit blast radius. The operational value is that a defender can map existing controls to stages and measure coverage as a fraction of the chain denied.
How CI teams borrow the kill chain
The CI variant is a metaphorical borrowing, not a formal model. Practitioners describe the chain a competitor walks from an internal decision to observable market impact: a strategic decision to enter a segment, an executive hire to lead it, engineering hires and patent or beta activity that reveal investment, a pricing or product page reset, a launch keynote, analyst and PR pushes, and finally sustained campaign air cover. Each stage emits public signals an analyst can capture: job postings, trademark and patent filings, page diffs, keynote registrations, press releases.
The analytical payoff is lead time, not the topology. Stages earlier in the chain suggest the eventual move without confirming it; later stages confirm it with little time to respond. A CI team that monitors competitor websites, pricing pages, job postings, and news in a continuous pipeline can stage detections along the chain rather than discovering the move at the launch keynote, when the response window has collapsed.
Kill chain versus threat-actor profiling and adjacent siblings
The kill chain answers the how: the sequence of stages an attacker or competitor traverses to produce an outcome. Threat-actor profiling answers the who: the identity, motives, playbook, and signatures of the actor moving down the chain. A kill chain without profiling tells you what to watch for but not which competitor is most likely to run it; profiling without a chain tells you who is dangerous but not which signal to monitor.
Adjacent CI concepts specialize parts of the chain. An indicator of change is the per-stage detection unit: the atomic signal that something in the chain has advanced. An attack surface describes the set of observable surfaces a defender can monitor across the chain. Four-corners analysis reads a competitor's intent and capability along adversary axes, complementary to a stage timeline. The threat landscape is the wider environment that decides which chains are likely at any moment.
Limitations of the metaphor
The cyber kill chain has known critiques that transfer in altered form. Early stages happen outside the defender's view, so most detection occurs late. The linear model fits outer-perimeter intrusions poorly against insider threats and modern elastic infrastructure. The Unified Kill Chain, proposed by Paul Pols in 2017, expanded Lockheed Martin's seven stages to eighteen to cover both external and internal phases.
The CI borrowing inherits additional limits. Competitors do not walk a canonical chain: some skip the executive hire, some never reset pricing, some launch quietly. Treating the chain as doctrine over-frames noisy events as inevitable progress toward a move. The honest use is as a checklist of stages to instrument, not a forecast of what comes next.
Stop looking terms up. Start tracking them.
meertrack watches your competitors' websites, pricing, and hiring, then alerts you when something meaningful changes.
Frequently Asked Questions
What is the kill chain?
It is the sequenced decomposition of an attack into find, fix, track, target, engage, and assess in the original military F2T2EA model, built so a defender can break the sequence at any link rather than only at the final blow. Each step depends on the last, which is why halting one stage halts the chain. Lockheed Martin adapted the same logic for cyber intrusions, and CI practitioners borrow the metaphor for the path a rival walks from internal decision to observable market move.
What are the seven stages of the Lockheed Martin cyber kill chain?
Reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objective. Lockheed Martin pairs each stage with a defensive action: detect, deny, disrupt, degrade, deceive, or contain. Defenders can then map controls to specific phases of an intrusion and measure coverage as a fraction of the chain denied.
How is the kill chain used in competitive intelligence?
CI teams use the kill chain as a metaphor for the sequence a competitor walks from an internal strategic decision to observable market impact: an executive hire, an engineering ramp, patent or beta activity, a pricing or page reset, a launch keynote, and a PR push. Each stage emits public signals that can be monitored continuously for lead time. The borrowing is explicit, not a formal framework.
Kill chain vs threat-actor profiling, what is the difference?
Kill chain describes the how: the sequence of stages an attack or competitive move traverses. Threat-actor profiling describes the who: the identity, motives, and signature playbook of the actor moving through it. A complete picture needs both: a chain to know what to monitor and a profile to know which competitor is likely to run it.
What are the limitations of the kill chain model?
Early stages occur outside the defender's view, so most detection happens late. The linear chain models insider threats and modern elastic infrastructure poorly, and competitors in a CI setting do not always pass through every stage. The Unified Kill Chain (Paul Pols, 2017) expanded the model to eighteen phases; CI practitioners should treat the chain as a checklist of stages to instrument, not a forecast.
Related terms
Building a behavioral model of a specific competitor (their patterns, decision cadence, resource allocation) to predict future moves.
Indicator of ChangeBorrowed from cybersecurity's "indicator of compromise": a discrete, observable signal that something has shifted in a competitor's behavior.
Attack SurfaceIn CI context, the market segments, customer bases, or product areas where a competitor could threaten your business.
Four Corners AnalysisExamines a rival through four lenses (drivers/motivations, assumptions, current strategy, and capabilities) to predict future moves.
Threat LandscapeThe full picture of external risks and competitive forces acting on a business.
Data Lineage / Source ProvenanceTracking where a competitive insight originated and how it was processed, so stakeholders can assess reliability and recency.
Switching Cost AnalysisEvaluating how difficult it is for customers to move between competitors, considering data portability, integrations, training, and contracts.
Time-Series AnalysisTracking a metric (pricing, headcount, rankings) over time to identify trends, seasonality, and inflection points.