Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ai-kill-chain — A defender-side extension of the Lockheed Martin Cyber Kill Chain for LLM and agentic AI threats. Adds a model supply chain stage and splits actions-on-objectives into exfiltration, model extraction, and agentic pivot. | Kitploit
Tools/GitHubGitHub/gouravnagar-infosec/ai-kill-chain
Threat IntelligencePapers & ResearchLearning & EducationIncident ResponseCurated ResourcesAI Security
GitHubgouravnagar-infosec/ai-kill-chain

ai-kill-chain

A defender-side extension of the Lockheed Martin Cyber Kill Chain for LLM and agentic AI threats. Adds a model supply chain stage and splits actions-on-objectives into exfiltration, model extraction, and agentic pivot.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
2417404 months agoReviewed by Kitploit

Extended Cyber Kill Chain for AI-Era Threats

An update to the Lockheed Martin Cyber Kill Chain for defenders working against LLM and agentic AI attacks. Adds a pre-attack stage for model supply chain compromise. Adds AI-specific sub-techniques to each of the original seven stages. Splits the Actions on Objectives stage into three peer sub-stages: classical data exfiltration, model extraction, and agentic pivot.

Version License: CC BY 4.0 Last Updated DOI

Author: Gourav Nagar Version: 1.0 Date: May 19, 2026 Repository: https://github.com/gouravnagar-infosec/ai-kill-chain

Cite as: Nagar, G. (2026). Extended Cyber Kill Chain for AI-Era Threats (Version 1.0). Zenodo. https://doi.org/10.5281/zenodo.20349357

Table of contents

  1. Abstract
  2. Background
  3. Why the seven-stage model is not enough
  4. The framework at a glance
  5. Stage-by-stage specification
    • Stage 0. Model Supply Chain Compromise (new)
    • Stage 1. Reconnaissance (AI-augmented)
    • Stage 2. Weaponization (AI-augmented)
    • Stage 3. Delivery (AI-augmented)
    • Stage 4. Exploitation (AI-augmented)
    • Stage 5. Installation (AI-augmented)
    • Stage 6. Command and Control (AI-augmented)
    • Stage 7. Actions on Objectives (expanded)
  6. Relationship to MITRE ATLAS, OWASP LLM Top 10, NIST AI RMF
  7. Worked case studies
  8. Detection and mitigation guidance
  9. Originality statement
  10. How to cite
  11. References
  12. License

Abstract

The Lockheed Martin Cyber Kill Chain has been the working model for how defenders describe an intrusion campaign since 2011. Seven stages from reconnaissance to actions on objectives. Network and endpoint attack surface. Human attackers operating tools against deterministic targets. Its value to defenders is the disruption logic: block any one stage and the rest of the chain cannot complete.

LLMs and AI agents do not fit that picture. Attackers now target model weights, training data, system prompts, tool descriptions. A document or a web page can carry instructions that an AI agent will execute as if a user had typed them. Agents with tool access can pivot through legitimate trust relationships without ever loading shellcode.

MITRE ATLAS and the OWASP LLM Top 10 both catalog these threats. ATLAS v5.4.0 (February 2026) has 16 tactics, 84 techniques, and 42 case studies, with coverage that reaches into indirect prompt injection and agentic command and control. OWASP's 2025 LLM Top 10 prioritizes ten risk categories for application builders. Both are organized as matrices or risk lists. Neither is a kill chain.

This document is the kill-chain-shaped view of the same content. It is written for SOC analysts and detection engineers who already think in kill chain stages.

It does three things on top of the canonical seven. It adds a new pre-attack stage (Stage 0) for adversary activity against the AI supply chain itself. It adds AI-specific sub-techniques inside each of the original seven stages, with EKC IDs so detection rules and SOC playbooks can reference them. And it splits Stage 7 (Actions on Objectives) into three peer sub-stages: classical data exfiltration, model extraction, and agentic pivot.

This is not a replacement for ATLAS or OWASP. It is the kill-chain-shaped view of the same threat surface.

Background

The original Cyber Kill Chain, from Hutchins, Cloppert, and Amin's 2011 Lockheed Martin paper, breaks an intrusion into seven stages.

StageNameWhat the adversary is doing
1ReconnaissancePicking targets
2WeaponizationPairing an exploit with a payload
3DeliveryGetting the weapon to the target
4ExploitationTriggering it
5InstallationImplanting persistence
6Command and ControlEstablishing a control channel
7Actions on ObjectivesAchieving the mission

The model is the basis of more than a decade of detection engineering practice, threat intel reporting structure, and SOC playbook design. A book-length treatment of the framework and its operational use is Nagar and Kumar (2025), Cyber Security Kill Chain: Tactics and Strategies (Packt). This framework extends that book.

Why the seven-stage model is not enough

The original assumptions break in four places for AI-era attacks.

Attacks now have a pre-network stage. A poisoned dataset or a compromised pre-trained model sitting on a public registry can compromise a target organization before any packet crosses a firewall. The canonical kill chain starts at Reconnaissance and has nowhere to put this.

Prompts mix code and data. LLMs cannot reliably tell instructions apart from content. Hidden text in a web page, an email, or a tool description can become instructions the model follows. What the kill chain treats as separate Delivery and Exploitation stages collapses into a single primitive in the AI case: indirect prompt injection.

Models themselves are targets now. Adversaries want the weights, the fine-tuning data, the system prompts, the capabilities encoded in deployed models. "Data exfiltration" understates this. Model extraction, training-data extraction, capability mining each have different mechanics and need different defenses.

And agents pivot through their own permissions. A compromised AI agent with tool access (MCP, function calling, browser control) does not need to escalate privileges or load shellcode. It invokes the tools it is already allowed to use. The mechanics are not classical lateral movement, but the effect on a target environment is.

ATLAS has been catching up. v4.9.0 (April 2025) added Command and Control as a tactic (AML.TA0014). v5.1.0 (November 2025) added Lateral Movement (AML.TA0015). As of v5.4.0 (February 2026) ATLAS is a 16-tactic matrix with good coverage of agentic threats, including case studies for SesameOp (AML.CS0042) and OpenClaw (AML.CS0050, AML.CS0051). This framework does not exist to fill gaps in ATLAS; ATLAS works as a matrix. It exists because the same content needs to be available to defenders who reason in kill-chain stages, with the original stage disruption logic still doing the work.

The framework at a glance

flowchart LR
    S0["Stage 0<br/><b>Model Supply<br/>Chain Compromise</b><br/><i>NEW</i>"]:::new
    S1["Stage 1<br/>Reconnaissance<br/><i>AI-augmented</i>"]:::mod
    S2["Stage 2<br/>Weaponization<br/><i>AI-augmented</i>"]:::mod
    S3["Stage 3<br/>Delivery<br/><i>AI-augmented</i>"]:::mod
    S4["Stage 4<br/>Exploitation<br/><i>AI-augmented</i>"]:::mod
    S5["Stage 5<br/>Installation<br/><i>AI-augmented</i>"]:::mod
    S6["Stage 6<br/>Command & Control<br/><i>AI-augmented</i>"]:::mod
    S7["Stage 7<br/>Actions on Objectives<br/><i>EXPANDED</i>"]:::expanded
    S7A["7a. Data Exfiltration<br/><i>classical</i>"]:::expanded
    S7B["7b. Model Extraction<br/><i>NEW</i>"]:::new
    S7C["7c. Agentic Pivot<br/><i>NEW</i>"]:::new
Download Tool