What is a kill chain?
A kill chain is a staged model that connects detection or access to a later objective and helps analysts identify points where the sequence can be interrupted.
Read the supporting sectionDefinitions before conclusions
A kill chain is a staged model that links observation, preparation, decision, action, and assessment. The phrase is used in several domains, and those meanings should not be silently merged.
Answer-first summary
A kill chain is a staged model that connects detection or access to a later objective and helps analysts identify points where the sequence can be interrupted.
Read the supporting sectionF2T2EA means Find, Fix, Track, Target, Engage, and Assess—the familiar military dynamic-targeting sequence used as one of the site’s three distinct models.
Read the supporting sectionNo. AI may assist sensing, fusion, classification, prioritization, navigation, or assessment while a human retains authority over force.
Read the supporting sectionThree primary meanings
The common logic is a linked sequence with multiple opportunities for interruption. The object being modeled, the authority delegated to software, and the consequences of failure are different in each case.
01 · Military decision and engagement
Find, Fix, Track, Target, Engage, Assess converts observations into an intended operational effect. AI can assist one or more functions without controlling the entire sequence.
Primary questions: identity, uncertainty, legal status, authorization, intervention, and effects assessment.
02 · Cyber intrusion lifecycle
The classic model uses Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.
Primary questions: what the adversary attempted, what defenders could observe, and where a control could disrupt progression.
03 · Attack against an AI-enabled system
A compact application-centered model is Recon, Poison, Hijack, Persist, Impact, with an Iterate/Pivot loop for agentic systems.
Primary questions: trust boundaries, instruction/data confusion, downstream authority, persistent state, egress, and rollback.
The essential distinction
The correct unit of analysis is the function–context pair: which function is automated or learned, in what environment, for what duration, against what target class, under which constraints, with what human information and intervention capability?
| Function | Possible AI contribution | What it does not establish | Control question |
|---|---|---|---|
| Sensing | Anomaly detection, adaptive search, clutter reduction | Identity, legal status, or authorization | Is the source trusted, current, and observing the intended area? |
| Fusion and tracking | Association, confidence estimation, trajectory prediction | That correlated sources are genuinely independent | Are provenance, contradictions, stale data, and uncertainty visible? |
| Classification | Object recognition, segmentation, behavior scoring | Positive identification or contextual understanding | How does performance change under novel, degraded, or deceptive conditions? |
| Decision support | Ranking, prioritization, course-of-action generation | Legal judgment, proportionality, or command responsibility | Is the system recommending, filtering, or effectively determining the choice? |
| Navigation and guidance | Route planning, obstacle avoidance, terminal discrimination | Independent authority to select a target | Who established the mission bounds and who can abort? |
| Assessment | Change detection, damage classification, re-action recommendation | That a follow-on action is justified | Can an uncertain assessment automatically trigger another effect? |
Human-control terminology
Terminology is not globally standardized. Knowledge, time, workload, information quality, the reliability of intervention, and the scope of delegated action matter more than the presence of a person somewhere in the organization chart.
Human in the loop
A human must authorize the application of force to a particular target or engagement. Navigation, cueing, tracking, or aiming may still be automated.
Human on the loop
The system may select and engage within bounded parameters while an operator monitors and can abort, deactivate, or override.
Out of the loop after activation
The operator establishes parameters before activation, after which the system can match sensor observations to a target profile and initiate engagement without approving each selected object.
Does the operator understand capabilities, limits, target profile, and likely effects?
Are identity, provenance, uncertainty, contradictory evidence, and civilian context visible?
Is there capacity for a genuine decision rather than reflexive approval under overload?
Can the system be stopped, and are target type, area, time, scale, and effects constrained?
Chains and webs
A simple chain suggests one sensor, one command path, and one effector. Contemporary architectures often distribute sensing, data fusion, decision support, communications, and effects across satellites, aircraft, ground stations, ships, command applications, and multiple weapons. A node may be replaced or rerouted, creating a more resilient kill web.
Distribution changes the assurance problem. One false or stale track can propagate through several services. Responsibility may be divided among data providers, software vendors, network operators, commanders, and weapon crews. Provenance and authority metadata therefore need to travel with a track from collection through assessment.
A network can be resilient to the loss of a node while becoming more vulnerable to the rapid propagation of a plausible but incorrect state.
See how KillChains.com and KillWebs.com fit together, or open the interactive KillWebs.com explorer.
Common misconceptions
Public product pages and news coverage frequently compress several technical and governance questions into one label. These corrections keep the analysis bounded.
It may refer to navigation, search, mission execution, terminal guidance, target-profile matching, or weapon release. The function and mission constraints must be named.
Some automatic defensive systems use deterministic, rule-based, or model-based logic without a learned classifier. They may still hold significant engagement authority.
Confidence may be poorly calibrated and says nothing by itself about source reliability, identity continuity, civilian status, or proportionality.
An overloaded operator with seconds to review opaque machine recommendations may function as a rubber stamp despite being nominally “in the loop.”
They can establish what a company publicly says a system does, but not necessarily combat performance, deployed configuration, or operator doctrine.
Programs, services, vendors, operators, versions, and mission sets vary. Public disclosure is uneven, and important details remain classified or disputed.
Institutional chains
Machine leadership describes the migration of sensing, interpretation, prioritization, planning, coordination, execution, and evaluation into software. Humans may still set the mandate, approve exceptions, retain override duties, and bear legal or political responsibility.
This is not one binary state. A system may be an analyst, recommender, workflow manager, orchestrator, operational delegate, or proxy executive. Each level delegates different functions and creates different accountability risks.