Experimental

Kill Chain Mapper

Map incidents to cyber kill chain stages.

Last reviewed by the Radiatus Cloud team

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Place an incident on the kill chain

After an incident, understanding how far the attacker got is central to the response, and the kill chain gives a framework for it. This tool maps the events of an incident to cyber kill-chain stages, so you can see how far along the chain the attack progressed and what that implies for containment and recovery.

Why staging an incident helps

Knowing an attacker reached the lateral-movement stage tells you something very different from knowing they were caught at initial access: the former means assuming wider compromise, the latter means a contained event. Mapping the observed events to stages structures the messy reality of an incident into a picture you can act on, and it reveals which stages were not detected, which is exactly where your monitoring needs to improve.

A framework for response

Everything runs in your browser, so nothing you enter is uploaded and the tool works offline once the page has loaded. There is no account, no tracking of your choices, and no server involved in the result.

Related tools

Frequently Asked Questions

What does mapping an incident to the kill chain do?

It places the observed events into attack stages, showing how far the attacker progressed, which guides containment and recovery decisions.

Why does the stage reached matter?

Because reaching lateral movement implies wider compromise to assume, while being caught at initial access means a more contained event. The response differs sharply.

What does it reveal about detection?

Which stages went undetected, since events you only discovered later mark gaps in monitoring that need improving.

Is this for use during or after an incident?

Both: it structures the response as events emerge and supports the review afterward by laying out how the attack progressed.

Is my incident data uploaded?

No. The mapping runs entirely in your browser.

Privacy & Security

Mapping done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.