Diamond Model of Intrusion Analysis
Four-feature framework for intrusion events: adversary, capability, infrastructure, victim.
The Diamond Model of Intrusion Analysis was articulated by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz in their 2013 paper 'The Diamond Model of Intrusion Analysis' (originally a 2011 Department of Defense technical report). The framework structures intrusion events around four core features arranged at the corners of a diamond: (1) Adversary — the actor or organization conducting the intrusion; (2) Capability — the tools, techniques, malware, or methods used; (3) Infrastructure — the physical or logical structures used by the adversary (servers, IP addresses, domains, email accounts); (4) Victim — the target of the intrusion. The four features are connected by edges representing relationships, with two diagonal axes — the social-political axis (Adversary-Victim, capturing motivation and intent) and the technology axis (Capability-Infrastructure, capturing the technical means). The model also includes meta-features (timestamp, phase, result, direction, methodology, resources) that contextualize specific intrusion events, and analytic pivoting — the practice of moving from one feature to others to discover related malicious activity. Diamond Model is principally a threat intelligence and intrusion analysis framework, complementing rather than replacing Cyber Kill Chain (which addresses temporal phases) and MITRE ATT&CK (which addresses tactical-technical patterns). The three frameworks are often used together: Diamond for analytical pivoting and feature relationships, Kill Chain for temporal phase analysis, ATT&CK for technique-level cataloging. The framework has substantial adoption in mature threat intelligence programs particularly in defense, government, and large enterprise contexts.
Core components
- Four core features: Adversary, Capability, Infrastructure, Victim
- Two axes: social-political (Adversary-Victim) and technology (Capability-Infrastructure)
- Edges representing relationships between features
- Meta-features: timestamp, phase, result, direction, methodology, resources
- Analytic pivoting between features
- Complementary use with Cyber Kill Chain and MITRE ATT&CK
- Application to threat intelligence and intrusion analysis
- Distinction from temporal frameworks (Diamond is non-temporal feature analysis)
Primary use case
Threat intelligence and intrusion analysis particularly in mature security operations; foundation for analytic pivoting in cyber threat intelligence; basis for tracking adversary campaigns over time; reference framework in incident response and forensic analysis; integration with Kill Chain and ATT&CK in unified threat-intelligence approaches; pedagogical reference in cyber threat intelligence education; foundation for some threat-intelligence platform features.
Common criticisms
- Less widely adopted than Cyber Kill Chain or MITRE ATT&CK — substantial adoption is concentrated in mature threat intelligence programs rather than mainstream security operations
- specifying features unambiguously can be difficult, particularly distinguishing 'capability' from 'infrastructure' for some attack tools
- the framework's analytical structure requires substantial threat intelligence expertise to apply effectively, limiting accessibility
- meta-features are conceptually rich but operationally varied across implementations
- commercial threat-intelligence platforms claim Diamond Model alignment with varying fidelity
- integration with technical detection tools (SIEMs, EDR) is less direct than ATT&CK alignment
- like other intrusion-analysis frameworks, doesn't address governance, risk management, or compliance dimensions
- cross-walking with other intelligence frameworks (STIX/TAXII, MISP) requires substantial effort
- tendency to use Diamond Model alongside other frameworks can produce framework proliferation that some security teams find counterproductive.
Lineage
- Siblings
- MITRE ATT&CK, Cyber Kill Chain