
A defender-side extension of the Lockheed Martin Cyber Kill Chain for LLM and agentic AI threats. Adds a model supply chain stage and splits actions-on-objectives into exfiltration, model extraction, and agentic pivot.
An update to the Lockheed Martin Cyber Kill Chain for defenders working against LLM and agentic AI attacks. Adds a pre-attack stage for model supply chain compromise. Adds AI-specific sub-techniques to each of the original seven stages. Splits the Actions on Objectives stage into three peer sub-stages: classical data exfiltration, model extraction, and agentic pivot.
Author: Gourav Nagar Version: 1.0 Date: May 19, 2026 Repository: https://github.com/gouravnagar-infosec/ai-kill-chain
Cite as: Nagar, G. (2026). Extended Cyber Kill Chain for AI-Era Threats (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.20349357
The Lockheed Martin Cyber Kill Chain has been the working model for how defenders describe an intrusion campaign since 2011. Seven stages from reconnaissance to actions on objectives. Network and endpoint attack surface. Human attackers operating tools against deterministic targets. Its value to defenders is the disruption logic: block any one stage and the rest of the chain cannot complete.
LLMs and AI agents do not fit that picture. Attackers now target model weights, training data, system prompts, tool descriptions. A document or a web page can carry instructions that an AI agent will execute as if a user had typed them. Agents with tool access can pivot through legitimate trust relationships without ever loading shellcode.
MITRE ATLAS and the OWASP LLM Top 10 both catalog these threats. ATLAS v5.4.0 (February 2026) has 16 tactics, 84 techniques, and 42 case studies, with coverage that reaches into indirect prompt injection and agentic command and control. OWASP's 2025 LLM Top 10 prioritizes ten risk categories for application builders. Both are organized as matrices or risk lists. Neither is a kill chain.
This document is the kill-chain-shaped view of the same content. It is written for SOC analysts and detection engineers who already think in kill chain stages.
It does three things on top of the canonical seven. It adds a new pre-attack stage (Stage 0) for adversary activity against the AI supply chain itself. It adds AI-specific sub-techniques inside each of the original seven stages, with EKC IDs so detection rules and SOC playbooks can reference them. And it splits Stage 7 (Actions on Objectives) into three peer sub-stages: classical data exfiltration, model extraction, and agentic pivot.
This is not a replacement for ATLAS or OWASP. It is the kill-chain-shaped view of the same threat surface.
The original Cyber Kill Chain, from Hutchins, Cloppert, and Amin's 2011 Lockheed Martin paper, breaks an intrusion into seven stages.
| Stage | Name | What the adversary is doing |
|---|---|---|
| 1 | Reconnaissance | Picking targets |
| 2 | Weaponization | Pairing an exploit with a payload |
| 3 | Delivery | Getting the weapon to the target |
| 4 | Exploitation | Triggering it |
| 5 | Installation | Implanting persistence |
| 6 | Command and Control | Establishing a control channel |
| 7 | Actions on Objectives | Achieving the mission |
The model is the basis of more than a decade of detection engineering practice, threat intel reporting structure, and SOC playbook design. A book-length treatment of the framework and its operational use is Nagar and Kumar (2025), Cyber Security Kill Chain: Tactics and Strategies (Packt). This framework extends that book.
The original assumptions break in four places for AI-era attacks.
Attacks now have a pre-network stage. A poisoned dataset or a compromised pre-trained model sitting on a public registry can compromise a target organization before any packet crosses a firewall. The canonical kill chain starts at Reconnaissance and has nowhere to put this.
Prompts mix code and data. LLMs cannot reliably tell instructions apart from content. Hidden text in a web page, an email, or a tool description can become instructions the model follows. What the kill chain treats as separate Delivery and Exploitation stages collapses into a single primitive in the AI case: indirect prompt injection.
Models themselves are targets now. Adversaries want the weights, the fine-tuning data, the system prompts, the capabilities encoded in deployed models. "Data exfiltration" understates this. Model extraction, training-data extraction, capability mining each have different mechanics and need different defenses.
And agents pivot through their own permissions. A compromised AI agent with tool access (MCP, function calling, browser control) does not need to escalate privileges or load shellcode. It invokes the tools it is already allowed to use. The mechanics are not classical lateral movement, but the effect on a target environment is.
ATLAS has been catching up. v4.9.0 (April 2025) added Command and Control as a tactic (AML.TA0014). v5.1.0 (November 2025) added Lateral Movement (AML.TA0015). As of v5.4.0 (February 2026) ATLAS is a 16-tactic matrix with good coverage of agentic threats, including case studies for SesameOp (AML.CS0042) and OpenClaw (AML.CS0050, AML.CS0051). This framework does not exist to fill gaps in ATLAS; ATLAS works as a matrix. It exists because the same content needs to be available to defenders who reason in kill-chain stages, with the original stage disruption logic still doing the work.
flowchart LR
S0["Stage 0<br/><b>Model Supply<br/>Chain Compromise</b><br/><i>NEW</i>"]:::new
S1["Stage 1<br/>Reconnaissance<br/><i>AI-augmented</i>"]:::mod
S2["Stage 2<br/>Weaponization<br/><i>AI-augmented</i>"]:::mod
S3["Stage 3<br/>Delivery<br/><i>AI-augmented</i>"]:::mod
S4["Stage 4<br/>Exploitation<br/><i>AI-augmented</i>"]:::mod
S5["Stage 5<br/>Installation<br/><i>AI-augmented</i>"]:::mod
S6["Stage 6<br/>Command & Control<br/><i>AI-augmented</i>"]:::mod
S7["Stage 7<br/>Actions on Objectives<br/><i>EXPANDED</i>"]:::expanded
S7A["7a. Data Exfiltration<br/><i>classical</i>"]:::expanded
S7B["7b. Model Extraction<br/><i>NEW</i>"]:::new
S7C["7c. Agentic Pivot<br/><i>NEW</i>"]:::new