TechKnowSurge
VideoSecurityFree

Weaponization

The weaponization phase of the cyber kill chain covers how attackers acquire, create, or compromise the tools and infrastructure needed to execute an attack. Known as resource development in the MITRE ATT&CK framework, this phase is a critical step in an adversary's attack preparation.

Complete this video to capture a CTF flag worth 1 point.

About this video

Before any attack is launched, adversaries go through a preparation phase focused on assembling everything they need to succeed. In the cyber kill chain, this is called weaponization. In the MITRE ATT&CK framework, the equivalent is resource development — the systematic process of acquiring, creating, or compromising tools, infrastructure, and access to support malicious operations. The MITRE ATT&CK framework breaks resource development into several key techniques. Attackers may purchase or trade for existing network access, bypassing the need to breach a perimeter from scratch. They may acquire infrastructure such as domains, DNS servers, and web services to support phishing sites or malvertising campaigns. Alternatively, rather than building their own infrastructure, adversaries may compromise legitimate third-party domains and servers to use as cover. Account compromise is also common, with attackers stealing or tricking users into surrendering credentials across email, cloud, and social media platforms. Capability development is another major component of this phase, with malware creation ranking as one of the most significant subtechniques. Whether tools are bought, stolen, or built from scratch, the goal is the same: to assemble a functional arsenal before the active stages of the attack begin. An adversary's overall capability reflects not just their technical knowledge and skill, but the quality and depth of the resources they are able to bring to bear. Recognizing the scope of weaponization helps security professionals better anticipate attacker behavior and identify indicators of preparation before an intrusion occurs.

What you'll learn

What's covered

Weaponization Phase

Key terms

Weaponization
The phase of the cyber kill chain where an attacker creates, obtains, or modifies malware and other tools necessary to carry out an attack.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Threat Actor
An individual or group responsible for a security incident or attack.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Infrastructure
The collection of servers, domains, DNS services, and web resources an attacker acquires or compromises to support an attack operation.
Domain Name System
DNS
A hierarchical naming system that translates human-readable domain names into IP addresses.
Backdoor
A hidden method of bypassing normal authentication or security controls to gain unauthorized access.

Topics

Cyber Kill Chain Mitre Att&ck Weaponization Resource Development Malware Development Attack Infrastructure Cybersecurity

Transcript

If I was a construction worker, I would need tools to carry out my job. Even if I had the skills and knowledge, I'd probably need a whole bunch of tools. For instance, let's say I was a framer and I was building houses. I'd at least need a hammer and a saw, and probably a lot of other tools, to build that house.

It's the same thing when we're carrying out an attack. If we've targeted a company and we're going to carry out an attack on that company, we need to equip ourselves with tools — or in this case weapons, since it's an attack. So let's talk about the weaponization phase.

What weaponization is

The weaponization phase is where we're going to equip ourselves with the tools necessary to carry out this attack. Weaponization means creating, obtaining, and/or modifying malware and other tools to carry out the attack. In the cyber kill chain, we call this weaponization. In MITRE ATT&CK, we call it resource development: you're going to develop resources to carry out this attack.

Resource development in MITRE ATT&CK

I'm on the MITRE ATT&CK website to give us some perspective of what this resource development looks like. We see: adversary is trying to establish resources they can use to support operations. So what are they trying to do? Here are the different techniques, different approaches that they would use for resource development. It gives us an idea of really what this phase is all about.

First of all, the first technique is to acquire access. What we might be doing is we might be bargaining or trading or purchasing some sort of access into a network. Then that skips a lot of maybe social engineering or other methods to gain that access, and we can jump to just having credentials to get in there.

Or maybe we're acquiring infrastructure. Maybe we're going to carry out some sort of social engineering attack. To do that, we need a website. To do a website, we need some sort of domain, so we're going to have to purchase a domain. And then because we have a domain, we'll have to purchase a DNS server or run a DNS server. So we've got servers that we're setting up. Perhaps we need some sort of web services that we're going to launch on that, and then have some sort of malvertising: we're going to advertise, and so we're going to purchase some advertising space that's going to send people to our fake website. So that's equipping ourselves with some infrastructure.

There are also compromised accounts. Up here is to acquire access, so maybe we're purchasing some sort of access there. But in here, we're compromising an account, so maybe we're tricking somebody into giving us their credentials. We've got social media accounts, email accounts, cloud accounts.

Maybe there's some sort of compromised infrastructure. So rather than acquiring our infrastructure like domains, DNS servers, web services, maybe instead we find somebody else's and we're compromising that infrastructure — domains, DNS server, web services — so that we can utilize those.

We may be developing some sort of capabilities. Notice that we've got malware as the number one sub-technique here, and so we're going to look a lot into malware, because that's a huge part of this, putting up malware.

As you can see, it's just a bunch of different capabilities here that we're either purchasing, acquiring, or that we are compromising and stealing, or we're creating. So we'll just create all of these tools here to be able to carry out our attack.

Capabilities

Really, weaponization is a big part of an adversary's capabilities. Capabilities is the potential and ability, so a lot of it does have to do with knowledge and skill, but it also has to do with the tools that they have to exploit an asset. Once we've equipped ourselves with the necessary tools — the servers and the domains and the malware — then we can proceed with our attack.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →