The weaponization phase of the cyber kill chain covers how attackers acquire, create, or compromise the tools and infrastructure needed to execute an attack. Known as resource development in the MITRE ATT&CK framework, this phase is a critical step in an adversary's attack preparation.
Weaponization Phase
If I was a construction worker, I would need tools to carry out my job. Even if I had the skills and knowledge, I'd probably need a whole bunch of tools. For instance, let's say I was a framer and I was building houses. I'd at least need a hammer and a saw, and probably a lot of other tools, to build that house.
It's the same thing when we're carrying out an attack. If we've targeted a company and we're going to carry out an attack on that company, we need to equip ourselves with tools — or in this case weapons, since it's an attack. So let's talk about the weaponization phase.
The weaponization phase is where we're going to equip ourselves with the tools necessary to carry out this attack. Weaponization means creating, obtaining, and/or modifying malware and other tools to carry out the attack. In the cyber kill chain, we call this weaponization. In MITRE ATT&CK, we call it resource development: you're going to develop resources to carry out this attack.
I'm on the MITRE ATT&CK website to give us some perspective of what this resource development looks like. We see: adversary is trying to establish resources they can use to support operations. So what are they trying to do? Here are the different techniques, different approaches that they would use for resource development. It gives us an idea of really what this phase is all about.
First of all, the first technique is to acquire access. What we might be doing is we might be bargaining or trading or purchasing some sort of access into a network. Then that skips a lot of maybe social engineering or other methods to gain that access, and we can jump to just having credentials to get in there.
Or maybe we're acquiring infrastructure. Maybe we're going to carry out some sort of social engineering attack. To do that, we need a website. To do a website, we need some sort of domain, so we're going to have to purchase a domain. And then because we have a domain, we'll have to purchase a DNS server or run a DNS server. So we've got servers that we're setting up. Perhaps we need some sort of web services that we're going to launch on that, and then have some sort of malvertising: we're going to advertise, and so we're going to purchase some advertising space that's going to send people to our fake website. So that's equipping ourselves with some infrastructure.
There are also compromised accounts. Up here is to acquire access, so maybe we're purchasing some sort of access there. But in here, we're compromising an account, so maybe we're tricking somebody into giving us their credentials. We've got social media accounts, email accounts, cloud accounts.
Maybe there's some sort of compromised infrastructure. So rather than acquiring our infrastructure like domains, DNS servers, web services, maybe instead we find somebody else's and we're compromising that infrastructure — domains, DNS server, web services — so that we can utilize those.
We may be developing some sort of capabilities. Notice that we've got malware as the number one sub-technique here, and so we're going to look a lot into malware, because that's a huge part of this, putting up malware.
As you can see, it's just a bunch of different capabilities here that we're either purchasing, acquiring, or that we are compromising and stealing, or we're creating. So we'll just create all of these tools here to be able to carry out our attack.
Really, weaponization is a big part of an adversary's capabilities. Capabilities is the potential and ability, so a lot of it does have to do with knowledge and skill, but it also has to do with the tools that they have to exploit an asset. Once we've equipped ourselves with the necessary tools — the servers and the domains and the malware — then we can proceed with our attack.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →