What Is the Diamond Model of Intrusion Analysis?
The Diamond Model breaks down intrusions into Adversary, Capability, Infrastructure, and Victim.
The Diamond Model of Intrusion Analysis, published in 2013 by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz, provides a structured approach to understanding cyber intrusions. The core concept is that every intrusion involves an adversary leveraging a capability through specific infrastructure against a victim. Visualizing these four elements as the corners of a diamond offers a comprehensive view of the event. This model is particularly valued in threat intelligence for its ability to facilitate clear thinking and enable analysts to “pivot” from one piece of information to uncover related, unknown aspects of an attack.
The efficacy of the Diamond Model lies in its ability to organize complex attack data and identify relationships between different components. By forcing analysts to consider the adversarial nature of threats, it moves beyond mere technical event analysis to a more holistic understanding of attacker motivation and methodology.
How It Works
The model’s structure comprises four key vertices: Adversary, Capability, Infrastructure, and Victim. The Adversary refers to the individual or group orchestrating the attack, often including both the operator and the beneficiary. The Capability encompasses the tools, techniques, and skills employed, such as malware, exploits, or specific attack methods. Infrastructure includes the technical resources used to deliver and control the attack, like C2 servers, domains, and IP addresses. Finally, the Victim is the target of the intrusion, which can be an individual, organization, system, or specific data.
Beyond the vertices, the edges of the diamond represent the relationships between these components: an adversary develops a capability, utilizes infrastructure, and directs both against a victim. The model also incorporates “meta-features” like timestamps and attack phases. Crucially, the “pivoting” mechanism allows analysts to infer unknown vertices from a known one. For instance, discovering a malicious IP address (Infrastructure) can lead to identifying multiple connected victims, or analyzing a piece of malware (Capability) can reveal its associated infrastructure and other compromised systems.
Real-World Example
Consider a scenario where malware is discovered on a finance employee’s laptop. The Diamond Model is applied by filling in the vertices: Victim (the employee and their company), Capability (the malware identified as a known banking trojan), and Infrastructure (extracting the C2 domain, ‘update-server-cdn[.]net,’ and its IP address from the malware analysis). The Adversary is initially unknown.
The true power of the model is demonstrated through pivoting. By querying logs for other systems that communicated with ‘update-server-cdn[.]net,’ three additional compromised laptops are identified, revealing new Victims. Further threat intelligence analysis connects this domain and malware family to a financially motivated crime group, beginning to define the Adversary. This process transforms a single indicator into a comprehensive understanding of an entire cyber campaign.
Diamond Model vs. Kill Chain
The Diamond Model and the Cyber Kill Chain are complementary frameworks, not competing ones. While the Kill Chain focuses on identifying the different stages of an attack, the Diamond Model aims to answer “who, what, where, and against whom.” Analysts frequently use them in conjunction; multiple Diamond Model instances can be chained together along a Kill Chain to map out an entire campaign’s “activity thread.” This integrated approach is common in operational threat intelligence and platforms that link indicators to threat actors.
Why Analysts Like It
The Diamond Model promotes analytical discipline by emphasizing that behind every technical alert is a human adversary with intent. It provides a structured method for organizing complex data, ensuring no crucial details are overlooked. The model’s pivoting logic is particularly valuable, enabling analysts to expand from a single indicator to a broader understanding of an entire operation. This capability is akin to a detective using a case board and string to connect disparate clues, where following the connections from any point can lead to solving the entire case.
People Also Ask
Who created the Diamond Model? Sergio Caltagirone, Andrew Pendergast, and Christopher Betz published it in 2013.
What are the four parts of the Diamond Model? Adversary, Capability, Infrastructure, and Victim.
What does pivoting mean in the Diamond Model? It means using one known element to discover the others, such as using a malicious server to find every victim that connected to it.
Sources and Further Reading
The Diamond Model of Intrusion Analysis (original paper, PDF)
ThreatConnect / Vectra AI: Diamond Model components and axioms
EC-Council: What is the Diamond Model of Intrusion Analysis?
- The Diamond Model analyzes intrusions using four interconnected components: Adversary, Capability, Infrastructure, and Victim.
- Analysts use the model to organize information and pivot from known clues to discover unknown aspects of an attack.
- The model's vertices represent the attacker, their tools/methods, their technical resources, and the target.
- Pivoting involves using one known element (e.g., an IP address) to identify related components (e.g., victims, other infrastructure).
- It complements frameworks like the Cyber Kill Chain by providing a "who, what, where, and against whom" perspective.
