Skip to content

Diamond model

The Diamond Model of Intrusion Analysis structures each intrusion event around four connected vertices: Adversary, Capability, Infrastructure, and Victim. Its strength is pivoting: from one known vertex you discover the others and link events into campaigns.

Adversary
/\
/ \
Infrastructure Capability
\ /
\/
Victim
# Adversary who (actor/group)
# Capability the HOW (malware, exploit, TTP; see cti-attack)
# Infrastructure what it uses (C2, domains, IPs, staging servers; see mal-c2)
# Victim who/what it attacks (organization, person, asset)

Each intrusion connects these four. There are also meta-features (timestamp, phase, result) and axes of socio-political (motivation) and technology.

- from INFRASTRUCTURE (a C2) -> other victims talking to it + other IPs of the actor
- from CAPABILITY (a hash/YARA) -> other samples/campaigns of the same adversary
- from VICTIM -> which capability/infra hit it -> attribute to the adversary
# linking many Diamond events by shared vertices = reconstruct a CAMPAIGN
Event: victim receives phishing (capability: macro+loader) from a domain (infrastructure)
-> pivot the domain (pDNS/WHOIS/TLS) -> more domains -> more victims
-> pivot the loader (YARA) -> other samples -> same capability in another campaign
-> set of events with shared infrastructure/capability = the same adversary
Kill Chain (cti-killchain) gives the temporal SEQUENCE (phases)
Diamond gives the STRUCTURE of each event and pivoting (relationships)
ATT&CK (cti-attack) gives the CAPABILITY detail (TTPs)
-> used together: Kill Chain (when) + Diamond (what/who/how) + ATT&CK (technique)
  • Document each intrusion as Diamond events -> basis to pivot and group into campaigns.
  • Pivot infrastructure and capability (pDNS, WHOIS, CT, YARA) to discover more of the actor.
  • Feed and consume CTI (CTI fundamentals): the vertices are enriched with feeds and with your own IR.
  • Combine with the Kill Chain (sequence) and ATT&CK (TTPs) for a complete analysis.
  • The Diamond Model (Caltagirone, Pendergast, Betz, 2013) is a standard framework for intrusion analysis and attribution.
  • Infrastructure pivoting (pDNS/WHOIS/CT) is routine in CTI to expand APT campaigns.
  • Vendor attribution reports implicitly structure findings by the Diamond’s vertices.
  • Model each intrusion by the 4 vertices (adversary/capability/infra/victim)
  • Record meta-features (phase, timestamp, result)
  • Pivot infrastructure (pDNS/WHOIS/CT) to more indicators
  • Pivot capability (YARA/hashes) to more samples/campaigns
  • Link events by shared vertices → campaign
  • Cross with Kill Chain (sequence) and ATT&CK (TTPs)
  • Feed the CTI and the report (Intelligence reporting)