REVIEW 4 major objections 5 minor 9 references
So, I climbed to the top of the pyramid of pain -- now what?
T0 review · 4 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read An eight-stage Human Layer Kill Chain merged with the Cyber Kill Chain into a Sociotechnical Kill Plane gives defenders a shared vocabulary and measurable human indicators for AI-enabled attacks that manipulate people.
desk verdict A useful taxonomy for the human side of attacks, but the load-bearing orthogonality claim is asserted rather than shown, and the evidence base is too thin for the readiness claims. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the Sociotechnical Kill Plane, a two-dimensional grid whose horizontal axis is the Cyber Kill Chain's seven technical phases and whose vertical axis is the paper's eight-stage Human Layer Kill Chain. Its load-bearing assumption is that the two axes are orthogonal; the plane does the work of decomposing a single campaign into simultaneous technical and psychological progressions, with a zero-click zone absorbing technical phases that never touch the human layer. The second mechanism is the indicator taxonomy: atomic HIoCs (directly observable physiological or behavioural signs), computed HIoCs (derived models such as predictive regressions), and latent HIoCs (inferred states such as stress or burnout), which convert psychological impact into evidence that can be collected and tracked.
What would settle it
Analyze a corpus of several hundred real incident reports and check whether every Human Layer Kill Chain stage maps to a distinct Cyber Kill Chain phase without residue, and whether human-required attacks ever progress along the human axis while the technical axis stays still. If all campaigns collapse onto the technical axis or all human stages are captured by existing phases, the plane's second dimension is redundant; if a romance scam's sustained engagement has no technical correlate, the orthogonality claim is supported.
Extended reading notes
Core claim
The paper's central claim is that the human and technical layers of a cyber attack are orthogonal, so an attack can be mapped simultaneously on two axes: the seven technical phases of the Cyber Kill Chain and the eight psychological stages of the Human Layer Kill Chain. On the resulting plane, a 'zero-click zone' holds purely technical phases that need no user action, while attacks that require meaningful human interaction — the paper's examples are romance scams, business email compromise, and ransomware with payment negotiation — progress along the human axis. The paper argues that existing models, which fold human involvement into a single social-engineering stage, cannot represent the sustained psychological progression these attacks need. It then defines Human Indicators of Attack (HIoAs) as digital artefacts revealing psychological tactics, and Human Indicators of Compromise (HIoCs) as observable, self-reported, or latent signs that a person has been psychologically affected, subdividing the latter into atomic, computed, and latent indicators.
Load-bearing premise
The load-bearing premise is that the human and technical layers of an attack are orthogonal, so a psychological stage cannot be reduced to a technical phase; if every human stage can be expressed within the existing Cyber Kill Chain or within a single social-engineering stage of an extended kill chain, the second axis contributes no new information.
Editorial extensions
If this is right
- Threat descriptions can be decomposed on two axes at once, giving finer granularity for analyzing attacker tactics, techniques, and procedures and supporting attribution.
- Disruption points can be located on the human layer as well as the technical one, so defenders can target the stages where an attack is most fragile.
- Non-technical personnel can contribute to threat identification by recognizing psychological tactics, as seen in a phishing-bingo training session where untrained participants engaged with attack emails.
- Attack narratives can carry temporal information and a critical HKC stage, supporting estimates of incident-response timing within accepted risk boundaries.
Reading between the lines
- Testable extension: measure a campaign's 'human interaction depth' as its distance from the zero-click zone on the plane, turning the model into a quantitative exposure metric.
- Testable extension: pair the HIoC classes with physiological sensors in simulated phishing drills to see whether dysregulation can be detected before the user acts.
- An implication the authors leave implicit: if the axes are truly orthogonal, campaigns with long human engagement such as romance scams should show little technical progress during parts of their life cycle, a prediction that can be checked against incident timelines.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper argues that existing kill-chain models, including Lockheed Martin's Cyber Kill Chain (CKC) and the Unified Kill Chain, do not adequately capture the human-psychological dimension of AI-enabled attacks. It introduces an eight-stage Human Layer Kill Chain (HKC) covering target profiling, human vulnerability assessment, personalized attack design, trust establishment, emotional triggering, sustained engagement, action manipulation, and operational cleanup, and proposes merging HKC with CKC into a two-dimensional 'Sociotechnical Kill Plane.' The paper also defines Human Indicators of Attack and Compromise (HIoA/HIoC) with atomic, computed, and latent subtypes, discusses implications for incident response, and presents three illustrative campaigns (romance scam, business email compromise, ransomware) plus a table of attack lifecycle durations. The central claim is that HKC and CKC are orthogonal and complementary, yielding a more granular and accessible attack-analysis framework.
Significance. If the orthogonality and measurability claims are substantiated, the framework has practical value: it gives security teams and non-specialists a shared vocabulary, extends the IoC concept to psychological observables, and explicitly connects AI-enabled manipulation to kill-chain phases. The paper's strengths include clear stage definitions, concrete example campaigns, and an honest acknowledgement that empirical validation is future work. However, the core added value rests on proving that the HKC axis is non-redundant with the CKC, and that point is currently asserted rather than demonstrated; the significance is therefore conditional.
major comments (4)
- [4.1, Figure 2] The statement that CKC and HKC are 'orthogonal and can be complementary' is asserted, not demonstrated. The three example campaigns in Figure 2 progress through HKC stages largely in lockstep with CKC phases (e.g., profiling near reconnaissance, attack design near weaponization, trust establishment near delivery, action manipulation near actions on objectives), which is what one would expect if HKC were merely a relabeling of the social-engineering parts of CKC. In addition, the 'zero-click zone' explicitly exempts technical phases from having HKC coordinates, so the plane is not a full two-dimensional product space. Without a formal definition of orthogonality or concrete examples in which the same CKC phase hosts different HKC stages (or the same HKC stage appears across multiple CKC phases), the claimed two-dimensional plane may add no information over the existing CKC plus a single social-engineering stage. This is load-bearing for the paper's central claim.
- [4.1, Table 2] Table 2 presents 'Avg. duration' and 'Critical HKC stage' for three scam types without any source, sample size, or collection methodology. These figures are used in Section 4.1 to motivate response-time estimates and disruption points, but as printed they give an unsupported quantitative veneer to the framework. The table should either be labeled as purely illustrative or be supported by a citable dataset and a description of how the values were obtained.
- [4.2, 5] The claim that HIoCs 'can be directly measured' through observation, self-report, or measurement technologies is not supported by any measurement study in the manuscript. The PHINGO anecdote in Section 5 reports only that participants 'were able to participate and contribute' and gives no participant count, outcome metric, reliability, or comparison baseline, so it does not substantiate the 'democratising' claim. Furthermore, the 'computed HIoC' example (problematic internet use negatively associated with security behaviour) is a correlational finding from prior work, not a demonstrated indicator of post-attack dysregulation; the mapping from psychological states to observable indicators needs explicit operationalization.
- [4.1, Table 2] The concept of a 'critical HKC stage' is introduced without an operational definition. Table 2 assigns exactly one stage per scam type, but the criteria for selecting that stage (first appearance, longest duration, greatest leverage, or something else) are never stated. Because the paper uses these stages to identify disruption points and response actions, the missing criteria weaken the framework's practical claims and should be clarified.
minor comments (5)
- [Abstract, 3, Figure 2, 4.2] There are several typographical errors: 'Humal' in the abstract, 'sems' in Section 3, 'Lockheed Martins\'' in the Figure 2 caption, and 'such asbehavioural' missing a space in Section 4.2. These should be corrected.
- [3] The claim that 'a substantial amount of phishing emails over the recent year have considerably improved on the psychological manipulation attempt techniques, strongly indicating that LLMs are used' is unsupported by data. Either provide a source or soften the wording to reflect anecdotal observation.
- [5] The PHINGO game observation should be described with enough methodological detail (number of participants, task design, outcome measures, inter-rater agreement if any) to be interpretable; as written, it is too thin to support the 'democratizing' narrative.
- [Table 1] The contrasts in Table 1, such as CKC defense being 'technical controls, policies, processes and awareness' versus HKC defense being 'psychological resilience (mental health focus)', are useful heuristics but should be framed as illustrative tendencies rather than categorical distinctions, since many CKC defenses also have human elements.
- [References] The Recorded Future citation 'Future [2024]' should include the full report title and an access date, and the in-text citation should match the reference formatting used elsewhere.
Circularity Check
No circular derivation: HKC is a definitional taxonomy, the orthogonality premise is asserted rather than derived, and the two self-citations are illustrative, not load-bearing.
full rationale
The paper proposes the Human Layer Kill Chain (HKC) as a definitional taxonomy of eight stages and merges it with Lockheed Martin's Cyber Kill Chain into a two-dimensional Sociotechnical Kill Plane. There is no derivation chain that could be circular: the HKC stages (Sec. 4) are stipulated definitions, Table 2's durations are asserted observations rather than fitted parameters, and Figure 2's campaigns are illustrative examples rather than predictions tested against the framework's own inputs. The load-bearing premise — 'we can consider that CKC and HKC are orthogonal and can be complementary' (Sec. 4.1) — is an unsupported assertion, but an unproven premise is a validity concern, not a circularity; the paper does not present orthogonality as a demonstrated result and then reuse that 'finding' as evidence for itself. The two self-citations are non-load-bearing: Yankouskaya et al. (2025) supports the motivational claim that GenAI induces user reliance (Sec. 3), and Deutrom et al. (2022) is offered as an example of a predictive HIoC (Sec. 4.2); both are published, externally falsifiable empirical works, and removing them would not alter the framework. No fitted value is renamed as a prediction, no uniqueness theorem is imported from the authors' prior work, and no known result is relabeled as new — the paper explicitly acknowledges its relation to the Unified Kill Chain's single 'Social Engineering' stage and to Montañez Rodriguez et al.'s PTechs/PTacs. Accordingly the score is 1: no circular derivation exists, with only minor, non-load-bearing self-citations.
Assumptions & free parameters
free parameters (1)
- Attack duration estimates (Table 2) =
0 to 48 hours (tech support), 2 to 14 days (BEC), 3 to 18 months (romance scam)
assumptions (5)
- domain assumption The Lockheed Martin Cyber Kill Chain is a valid baseline for describing technical attacks.
- ad hoc to paper HKC and CKC are orthogonal dimensions.
- domain assumption Human psychological compromise can be observed and measured via physiological, behavioral, and self-report indicators.
- ad hoc to paper The attack durations and critical stages in Table 2 are representative.
- ad hoc to paper The eight HKC stages are exhaustive and sequentially appropriate for human-targeting attacks.
invented entities (4)
-
Human Layer Kill Chain (HKC)
-
Sociotechnical Kill Plane
-
Human Indicators of Attack and Compromise (HIoAs/HIoCs)
-
Zero-click zone
Cite this review
Pith. "Pith review of So, I climbed to the top of the pyramid of pain -- now what?." pith.science (2026). https://pith.science/paper/6W4ATEUE
@misc{pith2026250524685,
author = {Pith},
title = {Pith review of: So, I climbed to the top of the pyramid of pain -- now what?},
year = {2026},
howpublished = {\url{https://pith.science/paper/6W4ATEUE}},
note = {Machine review of arXiv:2505.24685}
}
read the original abstract
This paper explores the evolving dynamics of cybersecurity in the age of advanced AI, from the perspective of the introduced Human Layer Kill Chain framework. As traditional attack models like Lockheed Martin's Cyber Kill Chain become inadequate in addressing human vulnerabilities exploited by modern adversaries, the Humal Layer Kill Chain offers a nuanced approach that integrates human psychology and behaviour into the analysis of cyber threats. We detail the eight stages of the Human Layer Kill Chain, illustrating how AI-enabled techniques can enhance psychological manipulation in attacks. By merging the Human Layer with the Cyber Kill Chain, we propose a Sociotechnical Kill Plane that allows for a holistic examination of attackers' tactics, techniques, and procedures (TTPs) across the sociotechnical landscape. This framework not only aids cybersecurity professionals in understanding adversarial methods, but also empowers non-technical personnel to engage in threat identification and response. The implications for incident response and organizational resilience are significant, particularly as AI continues to shape the threat landscape.
Figures
Reference graph
Works this paper leans on
-
[1]
Eric M Hutchins, Michael J Cloppert, Rohan M Amin, et al. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues in Information Warfare & Security Research, 1 0 (1): 0 80, 2011
work page 2011
-
[2]
Paul Pols and Jan van den Berg. The unified kill chain. CSA Thesis, Hague, pages 1--104, 2017
work page 2017
-
[3]
The diamond model of intrusion analysis
Sergio Caltagirone, Andrew Pendergast, and Christopher Betz. The diamond model of intrusion analysis. Threat Connect, 298 0 (0704): 0 1--61, 2013
work page 2013
-
[4]
Impact of ai on the cyber kill chain: A systematic review
Mateusz Kazimierczak, Nuzaira Habib, Jonathan H Chan, and Thanyathorn Thanapattheerakul. Impact of ai on the cyber kill chain: A systematic review. Heliyon, 2024
work page 2024
-
[5]
Ala Yankouskaya, Magnus Liebherr, and Raian Ali. Can chatgpt be addictive? a call to examine the shift from support to dependence in ai conversational large language models. Human-Centric Intelligent Systems, pages 1--13, 2025
work page 2025
-
[6]
Navigating the dual-edged sword of generative ai in cybersecurity
Flavio Ambrosio da Silva. Navigating the dual-edged sword of generative ai in cybersecurity. Brazilian Journal of Development, 11 0 (1): 0 e76869--e76869, 2025
work page 2025
-
[7]
Cyber threat analysis: Russia, 2024
Recorded Future. Cyber threat analysis: Russia, 2024. URL https://go.recordedfuture.com/hubfs/reports/cta-2024-0509.pdf
work page 2024
-
[8]
Jensen Deutrom, Vasilis Katos, and Raian Ali. Loneliness, life satisfaction, problematic internet use and security behaviours: re-examining the relationships when working from home during covid-19. Behaviour & Information Technology, 41 0 (14): 0 3161--3175, 2022
work page 2022
Show all 9 references
-
[9]
Quantifying psychological sophistication of malicious emails
Rosana Monta \ n ez Rodriguez, Theodore Longtchi, Kora Gwartney, Ekzhin Ear, David P Azari, Christopher P Kelley, and Shouhuai Xu. Quantifying psychological sophistication of malicious emails. In International Conference on Science of Cyber Security, pages 319--331. Springer, 2023
2023
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.