In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?
Trap 1: Installation
Installation covers establishing persistence on the victim host, such as installing a backdoor or remote-access trojan. The FTP transfer is outbound exfiltration, which is Actions on Objectives. It is tempting because installation follows exploitation, but no persistence mechanism is evidenced in the PCAP.
Trap 2: Weaponization
Weaponization covers coupling an exploit with a deliverable payload before delivery; the FTP transfer is exfiltration of data already collected, which is the Actions on Objectives phase. It is tempting because weaponization precedes delivery, but no exploit or payload creation appears in this traffic.
Trap 3: Exploitation
Exploitation is the phase where a vulnerability is triggered to gain access; the outbound FTP transfer shows data already being removed, which is Actions on Objectives. It is tempting because exploitation often precedes exfiltration, but the capture shows no exploit delivery or code execution.
- A
Installation
Why it fails: Installation covers establishing persistence on the victim host, such as installing a backdoor or remote-access trojan. The FTP transfer is outbound exfiltration, which is Actions on Objectives. It is tempting because installation follows exploitation, but no persistence mechanism is evidenced in the PCAP.
- B
Actions on Objectives
Exfiltration of database records to an external FTP endpoint fulfils the attacker's ultimate goal, so it maps to Actions on Objectives. Earlier phases cover reconnaissance, weaponisation, delivery, exploitation, installation and command-and-control; the actual theft of sensitive data is the final stage.
- C
Weaponization
Why it fails: Weaponization covers coupling an exploit with a deliverable payload before delivery; the FTP transfer is exfiltration of data already collected, which is the Actions on Objectives phase. It is tempting because weaponization precedes delivery, but no exploit or payload creation appears in this traffic.
- D
Exploitation
Why it fails: Exploitation is the phase where a vulnerability is triggered to gain access; the outbound FTP transfer shows data already being removed, which is Actions on Objectives. It is tempting because exploitation often precedes exfiltration, but the capture shows no exploit delivery or code execution.