Diamond Model of Intrusion Analysis

framework · cybersecurity · organizing-schema

Four-feature framework for intrusion events: adversary, capability, infrastructure, victim.

The Diamond Model of Intrusion Analysis was articulated by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz in their 2013 paper 'The Diamond Model of Intrusion Analysis' (originally a 2011 Department of Defense technical report). The framework structures intrusion events around four core features arranged at the corners of a diamond: (1) Adversary — the actor or organization conducting the intrusion; (2) Capability — the tools, techniques, malware, or methods used; (3) Infrastructure — the physical or logical structures used by the adversary (servers, IP addresses, domains, email accounts); (4) Victim — the target of the intrusion. The four features are connected by edges representing relationships, with two diagonal axes — the social-political axis (Adversary-Victim, capturing motivation and intent) and the technology axis (Capability-Infrastructure, capturing the technical means). The model also includes meta-features (timestamp, phase, result, direction, methodology, resources) that contextualize specific intrusion events, and analytic pivoting — the practice of moving from one feature to others to discover related malicious activity. Diamond Model is principally a threat intelligence and intrusion analysis framework, complementing rather than replacing Cyber Kill Chain (which addresses temporal phases) and MITRE ATT&CK (which addresses tactical-technical patterns). The three frameworks are often used together: Diamond for analytical pivoting and feature relationships, Kill Chain for temporal phase analysis, ATT&CK for technique-level cataloging. The framework has substantial adoption in mature threat intelligence programs particularly in defense, government, and large enterprise contexts.

Originators

Sergio Caltagirone; Andrew Pendergast; Christopher Betz (originally at the US Department of Defense) high

Year / Decade

2011 (DoD technical report); 2013 (publicly released paper) high

Primary sources

Caltagirone, S., Pendergast, A. & Betz, C. (2013). 'The Diamond Model of Intrusion Analysis', original 2011 Department of Defense technical report high

Core components

Primary use case

Threat intelligence and intrusion analysis particularly in mature security operations; foundation for analytic pivoting in cyber threat intelligence; basis for tracking adversary campaigns over time; reference framework in incident response and forensic analysis; integration with Kill Chain and ATT&CK in unified threat-intelligence approaches; pedagogical reference in cyber threat intelligence education; foundation for some threat-intelligence platform features.

Common criticisms

Lineage

Siblings
MITRE ATT&CK, Cyber Kill Chain