Diamond model
The Diamond Model of Intrusion Analysis structures each intrusion event around four connected vertices: Adversary, Capability, Infrastructure, and Victim. Its strength is pivoting: from one known vertex you discover the others and link events into campaigns.
The four vertices
Section titled “The four vertices” Adversary /\ / \Infrastructure Capability \ / \/ Victim# Adversary who (actor/group)# Capability the HOW (malware, exploit, TTP; see cti-attack)# Infrastructure what it uses (C2, domains, IPs, staging servers; see mal-c2)# Victim who/what it attacks (organization, person, asset)Each intrusion connects these four. There are also meta-features (timestamp, phase, result) and axes of socio-political (motivation) and technology.
The power of pivoting
Section titled “The power of pivoting”- from INFRASTRUCTURE (a C2) -> other victims talking to it + other IPs of the actor- from CAPABILITY (a hash/YARA) -> other samples/campaigns of the same adversary- from VICTIM -> which capability/infra hit it -> attribute to the adversary# linking many Diamond events by shared vertices = reconstruct a CAMPAIGNAnalysis example
Section titled “Analysis example”Event: victim receives phishing (capability: macro+loader) from a domain (infrastructure)-> pivot the domain (pDNS/WHOIS/TLS) -> more domains -> more victims-> pivot the loader (YARA) -> other samples -> same capability in another campaign-> set of events with shared infrastructure/capability = the same adversaryRelation to other models
Section titled “Relation to other models”Kill Chain (cti-killchain) gives the temporal SEQUENCE (phases)Diamond gives the STRUCTURE of each event and pivoting (relationships)ATT&CK (cti-attack) gives the CAPABILITY detail (TTPs)-> used together: Kill Chain (when) + Diamond (what/who/how) + ATT&CK (technique)Blue Team / operation
Section titled “Blue Team / operation”- Document each intrusion as Diamond events -> basis to pivot and group into campaigns.
- Pivot infrastructure and capability (pDNS, WHOIS, CT, YARA) to discover more of the actor.
- Feed and consume CTI (CTI fundamentals): the vertices are enriched with feeds and with your own IR.
- Combine with the Kill Chain (sequence) and ATT&CK (TTPs) for a complete analysis.
Real-world cases
Section titled “Real-world cases”- The Diamond Model (Caltagirone, Pendergast, Betz, 2013) is a standard framework for intrusion analysis and attribution.
- Infrastructure pivoting (pDNS/WHOIS/CT) is routine in CTI to expand APT campaigns.
- Vendor attribution reports implicitly structure findings by the Diamond’s vertices.
Testing checklist
Section titled “Testing checklist”- Model each intrusion by the 4 vertices (adversary/capability/infra/victim)
- Record meta-features (phase, timestamp, result)
- Pivot infrastructure (pDNS/WHOIS/CT) to more indicators
- Pivot capability (YARA/hashes) to more samples/campaigns
- Link events by shared vertices → campaign
- Cross with Kill Chain (sequence) and ATT&CK (TTPs)
- Feed the CTI and the report (Intelligence reporting)