1.3 Cyber Defense Frameworks: NIST SP 800-61, ISO 27035, MITRE ATT&CK, and Cyber Kill Chain
Key Takeaways
NIST SP 800-61 Rev. 3, published in April 2025, supersedes Rev. 2 and integrates incident response across all six NIST CSF 2.0 Functions; Rev. 2's four-phase lifecycle remains useful legacy and exam vocabulary.
The Lockheed Martin Cyber Kill Chain models seven sequential phases and helps defenders identify disruption opportunities, while recognizing that real adversaries may retry, adapt, or skip modeled steps.
MITRE ATT&CK categorizes real-world adversary behavior non-linearly across Tactics, Techniques, Sub-techniques, and Procedures, empowering defenders to map telemetry and identify defensive gaps.
The Diamond Model of Intrusion Analysis links Adversary, Capability, Infrastructure, and Victim across socio-political and technical axes to facilitate adversary pivoting and campaign clustering.
Combining frameworks—using the Cyber Kill Chain for phase progression, MITRE ATT&CK for granular TTP characterization, and the Diamond Model for infrastructure tracking—maximizes incident investigation efficacy.
Cyber Defense Frameworks and Adversary Modeling
Cyber defense frameworks provide the structured methodologies, standardized taxonomies, and analytical models necessary to investigate, contain, and communicate complex security intrusions. Rather than responding to adversaries with ad hoc tactics, mature security operations leverage established international standards and threat modeling frameworks. A comprehensive defense strategy synthesizes process-oriented lifecycle models (such as NIST SP 800-61 and ISO/IEC 27035) with adversary-centric models (including the Lockheed Martin Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model of Intrusion Analysis).
Current NIST SP 800-61 Rev. 3, Legacy Rev. 2, and ISO/IEC 27035
Process frameworks establish the institutional workflow required to manage security incidents from initial readiness through organizational closure. Incident handlers must distinguish the current NIST publication from legacy terminology that may still appear in courseware and older playbooks.
Current NIST SP 800-61 Rev. 3
NIST published SP 800-61 Rev. 3 in April 2025 and explicitly superseded Rev. 2. Rev. 3 is a Cybersecurity Framework (CSF) 2.0 Community Profile rather than a replacement four-step diagram: Govern, Identify, and Protect support preparation; Detect covers discovery and analysis; Respond covers containment, eradication, coordination, and reporting; Recover restores operations; and lessons learned improve every Function. Treat incident response as organization-wide cybersecurity risk management, not an isolated technical team activity.
Legacy NIST SP 800-61 Rev. 2
Rev. 2 remains important for interpreting older ECIH materials, policies, and exam questions. Its "Computer Security Incident Handling Guide" structures incident management into a continuous four-phase lifecycle:
- Preparation: Establishes policies, response plans, communication protocols, and specialized toolkits. Emphasizes preventative actions, including host and network hardening, vulnerability management, and workforce training.
- Detection and Analysis: Focuses on identifying indicators of compromise (IoCs), validating precursor signals, determining the scope and severity of an intrusion, and documenting incident baselines. Prioritizes triage based on business impact and data sensitivity.
- Containment, Eradication, and Recovery: Uniquely groups these three interrelated operational activities into a single iterative phase:
- Containment: Prevents the incident from expanding (deploying short-term isolation and long-term segmentation).
- Eradication: Identifies and purges all malicious artifacts, closes compromised user accounts, and patches underlying vulnerabilities.
- Recovery: Safely restores clean systems back to production environments, validates normal operations, and institutes heightened monitoring to prevent reinfection.
- Post-Incident Activity: Mandates a formal "lessons learned" meeting, comprehensive final incident reporting, and data retention compliance. Critically, findings feed directly back into the Preparation phase in a closed continuous improvement loop.
ISO/IEC 27035
The International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) standard 27035 delineates a five-stage incident management process: (1) Plan and prepare; (2) Detection and reporting; (3) Assessment and decision; (4) Responses; and (5) Lessons learned.
In the legacy Rev. 2 model, NIST combines containment, eradication, and recovery into a unified operational loop. Current Rev. 3 maps these outcomes to CSF 2.0 Respond and Recover. ISO/IEC 27035 emphasizes governance and separates assessment and decision from response in its commonly taught lifecycle. This structure aligns closely with formal enterprise risk registers and ISO 27001 information security management systems.
Lockheed Martin Cyber Kill Chain
Developed as part of the Intelligence Driven Defense philosophy, the Lockheed Martin Cyber Kill Chain models targeted intrusions across seven sequential, linear phases:
- Reconnaissance: The adversary researches and selects targets through active network scanning, credential scraping, and open-source intelligence (OSINT).
- Weaponization: Coupling an exploit payload with a deliverable carrier (such as trojanizing a PDF or weaponizing an Office macro). This occurs on attacker infrastructure without victim interaction.
- Delivery: Transmitting the weaponized payload to the victim environment via spear-phishing emails, drive-by web downloads, or USB drops.
- Exploitation: Executing the malicious payload to exploit a system, application, or operating system vulnerability.
- Installation: Establishing a persistent backdoor, scheduled task, or registry run key on the compromised victim asset.
- Command and Control (C2): Opening an interactive, two-way communication channel between the infected asset and external attacker infrastructure.
- Actions on Objectives: Accomplishing the operational mission, such as exfiltrating proprietary records, deploying ransomware encryption, or pivoting laterally.
Defenders categorize disruption points relative to exploitation: Left of Boom interventions occur prior to exploitation (blocking reconnaissance, email gateway filtering during delivery), neutralizing threats before code executes. Right of Boom interventions occur post-exploitation (EDR process termination during installation, DNS sinkholing to sever C2, and host isolation during actions on objectives). Disrupting a link can stop that attempt or force the adversary to change infrastructure or technique, but responders must verify containment because real campaigns can retry, branch, or skip modeled steps.
MITRE ATT&CK Matrix
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) matrix is a non-linear, comprehensive knowledge base of adversary behaviors observed in real-world attacks. Unlike linear kill chains, ATT&CK models opportunistic, iterative behaviors across a structured hierarchy:
- Tactics: Represent the adversary's operational objective—the "why" (such as Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact).
- Techniques: Detail the specific technical mechanism used to accomplish an objective—the "how" (such as T1059: Command and Scripting Interpreter).
- Sub-techniques: Describe granular variations of a technique (such as T1059.001: PowerShell).
- Procedures: Document the exact, real-world execution implementation used by a specific threat group or malware strain (such as APT28 invoking specific base64-encoded PowerShell parameters).
Incident handlers use MITRE ATT&CK to map observed endpoint telemetry to known threat actors, identify blind spots in logging coverage, and guide proactive threat hunting.
The Diamond Model of Intrusion Analysis
Developed by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz, the Diamond Model establishes a formal mathematical and relational framework for intrusion analysis. Every malicious event is structured around four core vertices:
- Adversary: The threat actor operating the attack (Adversary Operator) and the sponsor directing them (Adversary Customer).
- Capability: The tools, exploits, malware, and technical tradecraft employed by the adversary.
- Infrastructure: The physical or logical communication architecture utilized by the adversary (domain names, IP addresses, proxy servers, compromised relays).
- Victim: The target organization, person, network asset, email address, or service being exploited.
The four vertices are linked by two foundational axes:
- Social-Political Axis: Connects Adversary to Victim, characterizing intent, motivation, espionage objectives, and geopolitical context.
- Technical Axis: Connects Capability to Infrastructure, characterizing the technological architecture and attack delivery mechanisms.
Extended meta-features—including Phase, Result, Direction, Methodology, and Resources—enable analysts to chain individual diamond events into activity threads and campaigns. Handlers leverage the Diamond Model for pivoting: using a known infrastructure indicator (such as a command-and-control IP address) to discover other victim assets or unearth associated adversary capabilities.
In the NIST SP 800-61 Rev 2 incident handling lifecycle, which phase explicitly combines stopping the spread of an attack, removing malicious artifacts and backdoors, and safely restoring system functionality to normal business operations?
Detection and Analysis
Post-Incident Activity
Containment, Eradication, and Recovery
Preparation and Planning
Under the Lockheed Martin Cyber Kill Chain framework, an email gateway detects and quarantines a weaponized spreadsheet before the recipient can open it. At which stage of the attack progression did the defensive control disrupt the adversary?
Exploitation
Weaponization
Command and Control (C2)
Delivery
An incident response analyst uses the Diamond Model of Intrusion Analysis to investigate an intrusion. After identifying a malicious command-and-control IP address used by the attacker, the analyst searches proxy logs to identify other infected hosts that communicated with the same address. Which core analytical technique is the analyst employing?
Pivoting
Eradication
Living-off-the-land analysis
De-weaponization
Sections you finish are checked off in the contents.