Cyber Warfare Reference Guide
AEROSPACE ACADEMY // FIFTH DOMAIN

Cyber Warfare

Military operations conducted in, through, and via cyberspace to achieve objectives that support commander's intent. Cyberspace operations encompass offensive, defensive, and network management activities across the digital battlespace — targeting information systems, critical infrastructure, and command-and-control networks.

<100ms
Attack Propagation Speed
200+
Known Nation-State APT Groups
$10T+
Projected Global Cybercrime Cost (2025)
Offensive Cyber Ops (OCO)

Operations intended to project power by the application of force in or through cyberspace. Includes cyber attack, exploitation, and operations to degrade, disrupt, or destroy adversary capabilities.

Exploitation Disruption Destruction
Defensive Cyber Ops (DCO)

Operations to defend DOD or other friendly cyberspace. Includes passive and active defense measures: monitoring, detection, analysis, and response to cyber threats and vulnerabilities.

Detection Response Hardening
DODIN Operations

Operations to design, build, configure, secure, operate, maintain, and sustain DOD communications systems and networks. Ensures information availability across the joint force.

NIPRNet SIPRNet JWICS
Cyber Kill Chain

Seven-stage model: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives. Breaking any link disrupts the attack.

Domain Comparison: Cyber vs EW vs IO vs Kinetic
AttributeCyberElectronic WarfareInformation OpsKinetic
DomainCyberspaceElectromagnetic SpectrumInformation EnvironmentPhysical
SpeedNear-instantaneousSpeed of lightHours to monthsMinutes to hours
AttributionVery difficultModerateDifficultEasy
ReversibilityOften reversibleUsually reversibleVariableIrreversible
RangeGlobalLine of sight / regionalGlobalTheater-dependent
CostLow to moderateModerate to highLowVery high
CollateralUnpredictable spreadLimitedBroad influenceHigh physical damage
MITRE ATT&CK Framework — 14 Tactics

The MITRE ATT&CK framework catalogs adversary tactics, techniques, and procedures (TTPs) based on real-world observations. The 14 tactics represent the adversary's tactical goals during an operation.

TA0043
Reconnaissance
TA0042
Resource Development
TA0001
Initial Access
TA0002
Execution
TA0003
Persistence
TA0004
Privilege Escalation
TA0005
Defense Evasion
TA0006
Credential Access
TA0007
Discovery
TA0008
Lateral Movement
TA0009
Collection
TA0011
Command & Control
TA0010
Exfiltration
TA0040
Impact

Offensive Cyber Operations

OCO projects power by applying force in and through cyberspace — degrading, disrupting, or destroying adversary capabilities and infrastructure. Operations are governed by the Law of Armed Conflict (LOAC) as interpreted in the Tallinn Manual on international law applicable to cyber operations.

Legal Framework: All offensive cyber operations must comply with LOAC principles: distinction (military vs civilian targets), proportionality, military necessity, and unnecessary suffering. The Tallinn Manual 2.0 provides 154 rules for cyber operations under international law.
Network Attack Visualization

Animated visualization: Attacker traverses network layers — Perimeter → DMZ → Internal Network → Critical Infrastructure. Click to restart animation.

Exploitation Techniques
Disruption Techniques
Destruction Techniques
Deception Techniques
Total time from initial reconnaissance to successful exploitation of target system.
Time an adversary remains undetected in a network. Median: 21 days (2023).
Average time from intrusion to detection across N incidents.
Major Cyber Operations Platforms
OrganizationNationFocusNotable Capability
US Cyber CommandUnited StatesFull-spectrum cyber133 Cyber Mission Force teams
NSA / TAOUnited StatesSIGINT / CNETailored Access Operations
Unit 8200IsraelSIGINT / CyberStuxnet co-development
GRU Unit 74455RussiaDestructive cyberSandworm / NotPetya
PLA SSFChinaEspionage / IP theftAPT41 / APT10 operations
RGB / Bureau 121DPRKFinancial / DestructiveLazarus Group / WannaCry

Defensive Cyber Operations

DCO encompasses all measures to detect, identify, protect against, and respond to unauthorized activity within DOD information systems and networks. Employs defense-in-depth strategy across all seven OSI layers with continuous monitoring and active threat hunting.

SOC Dashboard — Real-Time Monitoring
Defense-in-Depth — OSI Layer Security Mapping
LayerOSIAttack SurfaceDefense Measures
7ApplicationSQL injection, XSS, API abuseWAF, input validation, SAST/DAST
6PresentationSSL/TLS attacks, encoding exploitsCertificate pinning, secure protocols
5SessionSession hijacking, replay attacksToken management, session timeouts
4TransportSYN floods, port scanningRate limiting, TLS 1.3, IPS
3NetworkIP spoofing, routing attacksFirewalls, ACLs, IPSec, segmentation
2Data LinkARP poisoning, MAC flooding802.1X, port security, VLAN isolation
1PhysicalPhysical access, wiretappingPhysical security, TEMPEST, air gaps
Detection Techniques
Response Techniques
Hardening Techniques
Monitoring Techniques
NIST Incident Response Lifecycle
1. Preparation 2. Detection & Analysis 3. Containment 4. Eradication 5. Recovery 6. Lessons Learned

NIST SP 800-61r2 defines the standard incident response lifecycle. Post-incident activity feeds back into preparation, creating a continuous improvement loop. Average containment time for breaches: 73 days.

197d
Avg MTTD (2023)
73d
Avg MTTR (2023)
44%
False Positive Rate (Industry Avg)
$4.45M
Avg Breach Cost (2023)
Defensive Posture Assessment
Perimeter Security 87%
Endpoint Protection 92%
Network Segmentation 68%
Identity & Access Management 81%
Incident Response Readiness 74%
Threat Intelligence Integration 56%

Network & Infrastructure

Military network architecture employs defense-in-depth across classified and unclassified enclaves. From NIPRNet to JWICS, each network tier implements layered security controls including next-generation firewalls, intrusion detection systems, and zero-trust microsegmentation.

Network Topology — Defense in Depth

Military network zones: Internet → Perimeter/DMZ → Internal Enclave → Restricted/Critical. Each boundary enforces security controls.

NIPRNet
ClassificationUNCLASSIFIED
PurposeGeneral DOD comms
Internet AccessYes (filtered)
EncryptionTLS / IPSec
SIPRNet
ClassificationSECRET
PurposeClassified comms
Internet AccessNo (air-gapped)
EncryptionNSA Type 1
JWICS
ClassificationTOP SECRET/SCI
PurposeIntel community
Internet AccessNo (air-gapped)
EncryptionNSA Suite A/B
Firewalls & Perimeter
IDS / IPS Systems
SIEM & Log Management
Endpoint Detection
Zero Trust Architecture
Core Principle: "Never trust, always verify." Zero Trust assumes breach and verifies each request as though it originates from an untrusted network. Every access decision is based on identity, device health, and contextual signals — not network location.
Identity-Centric

Strong authentication (MFA/FIDO2), continuous authorization, least-privilege access per session

Microsegmentation

Granular network segments per workload, lateral movement prevention, software-defined perimeters

Continuous Monitoring

Real-time risk scoring, UEBA analytics, automated policy enforcement, device compliance checks

DNS Security

DNSSEC validation, DNS-over-HTTPS (DoH), DNS sinkholing for malware C2 disruption, DNS firewalling, passive DNS monitoring for threat intel.

PKI / Certificates

DOD PKI hierarchy, CAC/PIV smart cards, certificate transparency logs, OCSP stapling, automated certificate lifecycle management (ACME).

VPN / Tunnel Architecture

IPSec site-to-site tunnels, WireGuard, SSL VPN for remote access, HAIPE encryptors for classified traffic, GRE/MPLS overlay networks.

Threat Actors & TTPs

Nation-state advanced persistent threat (APT) groups represent the most sophisticated cyber adversaries. Understanding their tactics, techniques, and procedures (TTPs) through frameworks like MITRE ATT&CK enables proactive defense and threat-informed security architecture.

Nation-State Threat Actors
APT GroupNationAlso Known AsPrimary TargetsKey TTPsNotable Operations
APT28Russia (GRU)Fancy Bear, Sofacy Government, military, mediaSpearphishing, 0-days, credential theftDNC hack (2016), Bundestag
APT29Russia (SVR)Cozy Bear, The Dukes Government, think tanksSupply chain, stealth, cloud abuseSolarWinds (2020)
APT41China (MSS)Double Dragon, Barium Tech, healthcare, gamingSupply chain, rootkits, dual espionage/crimeCCleaner, ShadowPad
LazarusDPRK (RGB)Hidden Cobra, ZINC Financial, crypto, defenseWatering holes, wiper malware, crypto theftWannaCry, Sony hack, $625M Ronin
APT33Iran (IRGC)Elfin, Refined Kitten Aviation, energy, petrochemicalSpearphishing, Shamoon wiper, VPN exploitsShamoon 1/2/3 attacks
SandwormRussia (GRU 74455)Voodoo Bear, IRIDIUM Critical infrastructure, electionsWiper malware, ICS attacks, supply chainNotPetya, Ukraine grid attacks
Major Cyber Operations Timeline
Notable Cyber Operations
2007
Estonia DDoS Attacks
Massive DDoS campaign against Estonian government, banking, and media following removal of a Soviet-era statue. First large-scale cyber attack against a nation-state. Led to creation of NATO CCDCOE.
2010
Stuxnet
US/Israel joint operation targeting Iranian uranium enrichment centrifuges at Natanz. First known cyber weapon to cause physical destruction. Exploited 4 zero-days, spread via USB, targeted Siemens S7-300 PLCs. Destroyed ~1,000 centrifuges.
2015
Ukraine Power Grid Attack
Sandworm (GRU) used BlackEnergy malware to compromise Ukrainian power distribution companies. First confirmed cyber attack to cause a power outage — 230,000 customers affected. Followed by Industroyer/CrashOverride in 2016.
2017
NotPetya
Russian GRU-attributed wiper disguised as ransomware. Spread via Ukrainian tax software (M.E.Doc) supply chain. Caused $10B+ in global damage. Maersk, Merck, FedEx among major victims. Most destructive cyber attack in history.
2017
WannaCry
North Korean ransomware leveraging EternalBlue (NSA exploit leaked by Shadow Brokers). Infected 200,000+ systems across 150 countries. NHS, Telefonica, Renault among victims. Kill switch discovered by Marcus Hutchins.
2020
SolarWinds (SUNBURST)
Russian SVR (APT29) compromised SolarWinds Orion build process, inserting backdoor into updates distributed to 18,000+ organizations. US Treasury, DHS, DOE among breached agencies. Epitome of supply chain attack sophistication.
2021
Colonial Pipeline
DarkSide ransomware group shut down largest US fuel pipeline (5,500 miles). Caused fuel shortages across US East Coast. $4.4M ransom paid (partially recovered by FBI). Triggered Executive Order 14028 on cybersecurity.
2023
MOVEit Exploitation
Cl0p ransomware group mass-exploited zero-day in Progress MOVEit Transfer (CVE-2023-34362). 2,500+ organizations compromised including Shell, BBC, US DOE. Demonstrated scale of managed file transfer supply chain risk.

Equipment & Tools

Cyber operations rely on specialized software tools, hardware appliances, and military platforms. From penetration testing frameworks to network forensics analyzers, these tools form the arsenal of both offensive and defensive cyber operators.

Cyber Operations Tool Matrix
ToolCategoryFunctionPlatform
Exploitation FrameworkOffenseExploitation framework — 2,000+ exploits, payload generation, post-exploitationCross-platform
Adversary Simulation PlatformOffenseAdversary simulation, beacon C2, lateral movement, malleable profilesWindows/Linux
Credential Extraction ToolOffenseWindows credential extraction — Kerberos tickets, NTLM hashes, plaintext passwordsWindows
Active Directory Path MapperOffenseActive Directory attack path mapping using graph theoryCross-platform
Network Discovery ScannerBothNetwork discovery, port scanning, service/OS detection, NSE scriptingCross-platform
Web Application Security TesterBothWeb application security testing — proxy, scanner, intruder, repeaterCross-platform
Network Protocol AnalyzerDefenseNetwork protocol analyzer — deep packet inspection, pcap analysisCross-platform
Malware Pattern MatcherDefensePattern matching rules for malware identification and classificationCross-platform
Memory Forensics FrameworkDefenseMemory forensics framework — RAM artifact extraction and analysisCross-platform
SIEM PlatformDefenseSIEM platform — log aggregation, correlation, alerting, dashboardsCloud/On-prem
Network Security MonitorDefenseNetwork security monitor — traffic analysis, connection logging, protocol parsingLinux/macOS
Network IDS/IPS EngineDefenseNetwork IDS/IPS — signature-based and anomaly detection enginesLinux
Network TAPs

Passive hardware devices that copy network traffic for monitoring without introducing latency or detection risk. Full-duplex TAPs capture both directions simultaneously. Essential for out-of-band IDS deployment.

HSM (Hardware Security Module)

FIPS 140-2/3 validated cryptographic hardware for key generation, storage, and management. Tamper-resistant modules used for PKI root CAs, code signing, database encryption, and payment processing.

Air-Gap Enforcement

Data diodes and cross-domain solutions (CDS) that enforce one-way data flow between classification levels. Ensures physical isolation of classified networks while enabling controlled information sharing.

Military Cyber Organizations
OrganizationNationEstablishedMission
USCYBERCOMUnited States2009Full-spectrum cyberspace operations — unified combatant command under STRATCOM, elevated 2018
UK NCSCUnited Kingdom2016National cyber defense, incident response, and public guidance (part of GCHQ)
NATO CCDCOENATO (Estonia)2008Cooperative Cyber Defence Centre of Excellence — research, training, Locked Shields exercise
ANSSIFrance2009National cybersecurity agency — defense, certification, and regulatory enforcement
BSIGermany1991Federal Office for Information Security — standards, certification, cyber defense
Persistent Cyber Training Environment (PCTE)

Army-led program providing scalable, on-demand cyber ranges for individual and collective training. Supports realistic adversary emulation, mission rehearsal, and certification of Cyber Mission Force teams. Cloud-based, accessible worldwide.

National Cyber Range (NCR)

DOD test and evaluation facility for cyber tools and tactics. Provides isolated, high-fidelity network environments replicating real-world infrastructure. Supports red/blue/purple team exercises and capability assessment.

Skills & Certifications

Cyber warriors require a broad technical foundation spanning networking, operating systems, programming, cryptography, and adversary tradecraft. This section maps core competencies, industry certifications, and career progression pathways for military and civilian cyber professionals.

Competency Radar — Cyber Warrior Profile

Radar chart showing relative competency levels across 8 core skill dimensions for cyber operations roles.

Core Technical Competencies
Specialized Skills
Certification Pathways
FND
Foundation Security Certification
Baseline security certification. DOD 8570 IAT Level II. Covers threats, vulnerabilities, cryptography, identity management. Required for many military cyber roles.
ETH
Ethical Hacking Certification
Offensive security certification covering penetration testing methodology, tools, and techniques. DOD 8570 CSSP Analyst.
OFF
Offensive Security Certification
Hands-on penetration testing certification. 24-hour practical exam. Industry gold standard for offensive security skills. Proves real-world exploitation ability.
MGT
Security Management Certification
Management-level certification. 8 domains: security management, asset security, architecture, network security, IAM, assessment, operations, software security. DOD 8570 IAM Level III.
ADV
Advanced Technical Certifications
Specialized certifications covering security essentials, penetration testing, incident handling, reverse engineering malware, and forensic analysis. Considered premier technical training in the industry.
Career Progression Path
SOC Analyst (L1) SOC Analyst (L2/L3) Incident Responder Threat Hunter Red Team Lead CISO
ENTRY (0-2 YRS)

SOC Analyst, Security Engineer, IT Auditor. Focus: monitoring, triage, basic incident response. Certs: Foundation cert.

MID-LEVEL (3-7 YRS)

Pen Tester, Incident Responder, Threat Intel Analyst, Malware Analyst. Focus: specialization. Certs: Intermediate certs.

SENIOR (8+ YRS)

Red Team Lead, Security Architect, CISO, Cyber Mission Commander. Focus: strategy & leadership. Certs: Advanced certs.

Reference Matrix

Comprehensive filterable and sortable reference of all cyber operations, techniques, and tools covered in this guide. Use the category and difficulty filters to narrow results.

Master Reference Table
Name Category Type Difficulty Description
Zero-Day ExploitOCOTechniqueAdvancedExploitation of previously unknown vulnerability with no available patch
SQL InjectionOCOTechniqueIntermediateCode injection via malicious SQL statements in application input
Buffer OverflowOCOTechniqueAdvancedMemory corruption to achieve arbitrary code execution
Credential HarvestingOCOTechniqueBeginnerPhishing, keylogging, or dump tools to capture authentication data
Supply Chain CompromiseOCOTechniqueAdvancedCompromising trusted software/hardware vendors to reach end targets
DDoS AttackOCOTechniqueBeginnerVolumetric or application-layer flood to deny service availability
Wiper MalwareOCOToolAdvancedDestructive malware that overwrites or encrypts data irreversibly
ICS/SCADA AttackOCOTechniqueAdvancedTargeting industrial control systems for physical-world effects (Stuxnet-class)
SIEM MonitoringDCOToolBeginnerSecurity information and event management for log correlation and alerting
IDS/IPSDCOToolIntermediateSignature and anomaly-based intrusion detection/prevention systems
EDRDCOToolIntermediateEndpoint detection and response — behavioral analysis, process monitoring
HoneypotDCOTechniqueIntermediateDecoy systems to detect, deflect, and study attacker behavior
Threat HuntingDCOTechniqueAdvancedProactive hypothesis-driven search for undetected threats in network
Patch ManagementDCOProcessBeginnerSystematic application of security updates to reduce attack surface
Zero TrustDCOArchitectureIntermediateIdentity-centric, never-trust-always-verify security model
Network SegmentationDCOArchitectureIntermediateDividing networks into zones to limit lateral movement
Network Discovery ScannerBothToolBeginnerNetwork mapper for discovery, port scanning, and service detection
Network Protocol AnalyzerBothToolIntermediateNetwork protocol analyzer for deep packet inspection and forensics
Exploitation FrameworkBothFrameworkIntermediateExploitation framework for penetration testing and vulnerability validation
Memory Forensics FrameworkBothToolAdvancedMemory forensics framework for RAM analysis and artifact extraction
Malware Pattern MatcherDCOToolAdvancedPattern-matching rules for malware identification and threat classification
Adversary Simulation PlatformOCOFrameworkAdvancedAdversary simulation platform with beacon C2 and malleable profiles
Incident ResponseDCOProcessIntermediateNIST SP 800-61 lifecycle: Preparation, Detection, Containment, Eradication, Recovery
Digital ForensicsBothDisciplineAdvancedEvidence acquisition, chain of custody, disk/memory/network forensic analysis