DRAG DROP - Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right. Select and Place: <DragDrop items={["not visible to the victim","virus scanner turning off","malware placed on the targeted system","open port scans and multiple failed logins from the website","large amount of data leaving the network through unusual ports","system phones connecting to countries where no staff are located","USB with infected files inserted into company laptop"]} slots={[{"answer":"open port scans and multiple failed logins from the website","id":"reconnaissance","label":"reconnaissance"},{"answer":"not visible to the victim","id":"weaponization","label":"weaponization"},{"answer":"USB with infected files inserted into company laptop","id":"delivery","label":"delivery"},{"answer":"virus scanner turning off","id":"exploitation","label":"exploitation"},{"answer":"malware placed on the targeted system","id":"installation","label":"installation"},{"answer":"system phones connecting to countries where no staff are located","id":"command_control","label":"command & control"},{"answer":"large amount of data leaving the network through unusual ports","id":"actions_objectives","label":"actions on objectives"}]} explanation={"Reconnaissance often appears as port scans and login attempts. Weaponization prepares evasive malware, delivery introduces it through a vector such as infected removable media, exploitation executes malicious activity such as disabling security controls, and installation places malware on the victim system. Command and control produces suspicious outbound communications, while actions on objectives can include exfiltrating substantial data.\n\n**Learn more:** [Lockheed Martin Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html)"} reuse={false} />