← Back to list

Cyber Kill Chain

Task 1: Introduction

Brian Grier · 2026-06-01 20:57 · 0 claps · 1.3 min read
#tryhackme-walkthrough #thm-writeup #thm #cybersecurity
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Cyber Kill Chain

Task 1: Introduction

Q: How many phases comprise the Cyber Kill Chain?

A: 7

Task 2: Reconnaissance

Q: What is the term for using search engines to reveal sensitive information and confidential files?

A: Google Dorking

Q: What type of reconnaissance is it where the attacker checks the social media pages?

A: Passive Reconnaissance

Task 3: Weaponisation

Q: What technique is mentioned to evade detection by making it challenging to analyse the malicious code?

A: Obfuscation

Q: What built-in feature makes creating a malicious MS Office document possible?

A: Macro

Task 4: Delivery

Q: What method involves showing advertisements on legitimate websites to redirect users to malicious pages?

A: Malvertising

Q: What phishing attack sends text messages with malicious links or instructions to download malware?

A: Smishing

Task 5: Exploitation

Q: What type of exploit is used before the vendor becomes aware of a vulnerability?

A: Zero-day Exploit

Q: What technology is mentioned to prevent an attacker from gaining access even with valid login credentials?

A: MFA

Task 6: Installation

Q: What tactic allows attackers to execute operating system commands on a target via a web browser interface?

A: Web Shell

Q: What technique is mentioned to prevent the execution of unauthorised or malicious software by only allowing approved applications to run?

A: allowlisting

Task 7: Command and Control (C2)

Q: What is the name of the tactic where data is hidden within DNS queries?

A: DNS Tunnelling

Q: What protocol would the attacker use to smuggle his data as encrypted web traffic?

A: HTTPS

Task 8: Actions on Objectives

Q: What is the term for stealing sensitive files from a target network?

A: Data Exfiltration

Q: What principle limits who can access sensitive systems and data to minimise damage caused by an attacker?

A: Principle Of Least Privilege

Q: What type of attack involves encrypting files and demanding payment in exchange for the decryption key?

A: Ransomware

Task 9: Conclusion

Q: What is the flag after you complete the static site?

A: THM{CKC_NJHERDX327} (Lab is broken sometimes)


메타데이터
post_id
7b665c4613a2
slug
cyber-kill-chain-7b665c4613a2
url
https://medium.com/@brian.grier2000/cyber-kill-chain-7b665c4613a2
canonical_url
https://medium.com/@brian.grier2000/cyber-kill-chain-7b665c4613a2
author_url
https://medium.com/@brian.grier2000
status
ok
fetched_at
2026-06-16 19:09:56