APT-Lifecycle

APT Lifecycle / Cyber Kill Chain

Lebenszyklus eines gezielten Angriffs

The APT lifecycle describes the typical phases of a targeted attack — from reconnaissance through initial access and establishing a foothold to lateral movement and the actual objective. Such models make visible that an attack is not a single moment but a sequence. Each phase offers a chance for detection and interruption.

History & facts. Well-known phase models — such as the Cyber Kill Chain or the tactics-ordered structure of ATT&CK — break an attack into traceable steps. The value lies in the change of perspective: instead of looking only at the final damage, the entire path to it becomes visible, with numerous points where defenders could intervene. Early phases are often quieter but more rewarding to detect than the loud end. Outlook & recommendation. The practical benefit lies in matching one's own detection against the phases: where along the lifecycle would an attack stand out in our environment — and where not? This gap analysis prioritises investments better than collecting individual tools. It connects directly to ATT&CK and to the idea of thinking about detection across the entire attack path rather than only at the endpoint.
APT-Lifecycle — APT Lifecycle / Cyber Kill Chain