An analyst reviews an incident where a phishing email delivered an attachment, then PowerShell ran on the endpoint. The CISO wants a model that clearly separates the email delivery phase from the endpoint execution phase, with pre-compromise versus post-compromise activity. Which framework should the analyst use?
Select an answer to reveal the explanation.
Short Explanation
Think of the kill chain like a delivery route: the email is the package on the doorstep, and the PowerShell run is the burglar inside. It maps pre-compromise delivery to post-compromise actions so you can see where the chain broke. ATT&CK tells you what the burglar did, but the chain tells you when the break happened.
Full Explanation
Cyber Kill Chain is designed around linear campaign stages, making it useful for separating activity before initial compromise from activity after initial compromise. In a phishing case, the email and attachment represent delivery and possibly weaponization, while the PowerShell run, persistence, or C2 belong to post-compromise stages such as exploitation, installation, and command and control. This separation helps analysts and managers discuss whether detection failed at the email perimeter, user action, or endpoint execution. MITRE ATT&CK describes adversary behavior through tactics and techniques, such as execution or persistence, but it is not organized around pre-compromise versus post-compromise phases. The Diamond Model focuses on the relationship among adversary, capability, infrastructure, and victim for event-centric analysis, not a chronological chain. The Pyramid of Pain ranks detection indicators by how hard they are to change, such as hashes or TTPs, and does not model campaign stages. Exam caveat: choose the framework whose structure answers the question, not the most popular framework. Operational check: map the phishing email to delivery and the PowerShell event to execution or installation in a kill-chain table, then annotate the corresponding ATT&CK technique IDs.