Анализ вторжений по Cyber Kill Chain
★ 8.4 · security
analyzing-cyber-kill-chain is a Claude Code skill that maps intrusion activity against the Lockheed Martin Cyber Kill Chain framework to determine which of the seven phases an adversary completed, where defenses succeeded or failed, and which controls would have interrupted the attack earlier. The workflow covers artifact-to-phase mapping (Reconnaissance through Actions on Objectives), a phase completion matrix with detection gaps, integration with MITRE ATT&CK Enterprise for technique-level detail (TA0001–TA0040), and six courses of action per phase: Detect, Deny, Disrupt, Degrade, Deceive, and Destroy. Output is a structured kill chain analysis report with an attack narrative, evidence-backed phase findings, and a cost-effectiveness-ranked control roadmap. Intended for SOC analysts and incident responders conducting post-incident reviews, building layered defenses, or communicating attack progression to non-technical stakeholders. Aligns with NIST CSF functions ID.RA-01, ID.RA-05, DE.CM-01, and DE.AE-02.
- #kill-chain
- #threat-intelligence
- #mitre-attack
- #incident-response
- #defense