A SOC analyst receives a threat report describing an attacker building a malicious loader, embedding it in a macro-enabled document, and signing the file before emailing it to users. Which Cyber Kill Chain phase occurs immediately before the delivery phase?
Select an answer to reveal the explanation.
Short Explanation
Think of weaponization like the factory before shipping: you're building and packaging the weapon, not sending it yet. Delivery is the mail truck; exploitation is opening the box and popping the latch. So if the report says the attacker crafted, embedded, and signed the payload before emailing it, you're still in weaponization.
Full Explanation
The Cyber Kill Chain models an attack as ordered phases, and weaponization is the stage where an adversary builds, customizes, and packages the attack artifact before it reaches a target. This can include creating a payload, embedding it in a document, compiling code, signing binaries, or preparing a malicious archive. The phase matters because defenders can distinguish preparation activity from inbound communication or execution activity. Exploitation is the phase that follows delivery, when the malicious code attempts to take advantage of a vulnerability or execute after a user interacts with the delivered artifact. Installation occurs after successful exploitation, when the attacker establishes a foothold by placing persistence mechanisms, tools, or agents on the victim system. Command and control is later still, used after the implant is installed to receive instructions, beacon out, or exfiltrate data. Exam caveat: Cyber Kill Chain questions usually test sequence, so match the described activity to the phase that immediately precedes or follows it rather than selecting the first phase that sounds malicious. Operational check: When reviewing an incident timeline, label each observed action with its kill-chain phase before drawing conclusions about attacker capability or impact.