Skip to main content
AD Academy
SOC Analyst — Read traffic, logs, and attacks
Intermediate16 minLast updated: Topic 3 of 3

Cyber Kill Chain and SIEM

The seven stages of an attack with what is seen at each stage, and how a central log server connects the picture.

Not read

What you will learn here

  • The seven Kill Chain stages
  • What logs show at each stage
  • How a SIEM ties it together

Worth reading first:Windows Event ID Map for the Analyst

A real attack is not a single moment but a chain. Lockheed Martin formulated it as the Cyber Kill Chain: if one link is stopped — the entire chain is broken. Click on a stage in the diagram to see what happens in it and what is actually seen from it.

Cyber Kill Chain — the seven attack stages

Click a stage to see the traces it leaves

What happens

The user clicks Enable Content, the macro runs and abuses a permission or a software flaw.

What the network analyst sees

The first outbound call right after the document opens, usually HTTPS to an unknown host.

What the system analyst sees

Event 4688 / Sysmon 1: WINWORD.EXE ⇒ powershell.exe -enc — the classic indicator.

Why do we even need SIEM?

On the left are the log sources: a domain controller, workstations running Sysmon, network gear sending syslog and Linux servers. An agent or forwarder collects, parses and ships the logs to a central server, where they are normalised and indexed, correlation rules run (twenty 4625 events in a minute raise an alert) and a dashboard or alert reaches the analyst. That is why admins configure the endpoints while analysts work on a central log server: one timeline, cross-host correlation, and logs that survive a wiped machine.

  • One timeline: Event 4625 on the workstation and a Firewall event from the same second appear together on the same screen.
  • Correlation between computers: the same account failed on ten workstations in a minute — this is one rule in , and without it, no one would notice.
  • Survivability: If the attacker deleted the local log (Event 1102), the copy on the central server has already been sent.
  • History: You can go back months when a new IOC is discovered.
  • Common tools: Wazuh (free, ELK-based), Splunk (enterprise), Elastic Security, Microsoft Sentinel.
Architecture and Theory — Under the Hood

Cyber Kill Chain (Lockheed Martin) has 7 stages: Recon, Weaponization, Delivery, Exploitation, Installation, C2, Actions on Objectives. (Wazuh/Splunk/Elastic/Sentinel) collects logs from all sources and allows detecting the early stages before the attacker reaches Actions.

  • Sources: Windows Security + Sysmon, Firewall, EDR, DNS, , Logs.
  • Parsing → Enrichment (GeoIP, Threat Intel) → Correlation → Alert → Case.
  • MITRE ATT&CK categorizes techniques — each Alert is linked to a tactic (TA0001 Initial Access etc.).
  • Detection Engineering: From Sigma Rules to Query in the tool's language (SPL, KQL, EQL).
Practical Definition (PowerShell / GUI)
# Elastic KQL - PowerShell Encoded Command
process.name:powershell.exe and process.command_line:*-enc*

# Splunk SPL - First Logons from User to Server
index=win EventCode=4624 LogonType=3 | stats count by user,dest | where count=1

# Wazuh - Custom Sigma Rules
<rule id="100010" level="12">
  <if_sid>60106</if_sid>
  <field name="win.eventdata.commandLine">mimikatz</field>
  <description>Mimikatz command line detected</description>
</rule>
bash
Real-world Scenarios in the Organization
  • Recon: Port scanning on DMZ server (Firewall drops + Suricata alerts).
  • Delivery: Email with link to Typosquat website ( log + URL Reputation).
  • Exploitation: 4688 of winword.exe running powershell.exe with -enc.
  • C2: Constant Beaconing to a new (First-Seen + DGA Score).
  • Objectives: — 4662 with GUID of .
Troubleshooting
  • Too many False Positives → Tuning + Baseline for each environment.
  • Logs not entering → Agent health (Winlogbeat/Universal Forwarder), Time Sync, TLS certs.
  • Detection missing layer → Map against MITRE ATT&CK Navigator and identify gaps.
Glossary and Quick Command Line
  • Kill Chain: Recon → Weaponize → Deliver → Exploit → Install → C2 → Actions.
  • MITRE ATT&CK = Technique dictionary with ID (TXXXX).
  • Sigma = Cross-SIEM format for rules.
  • SOAR = Response automation — not just detection.

Check yourself

At which stage in the Kill Chain would you see beaconing every 60 seconds to an external target?

What is the main advantage of a central log server?

Was this page helpful?