Skip to content

Diamond Model

Definition

An analytic framework that structures a cyber intrusion event around four linked elements: adversary, capability, infrastructure, and victim. The model makes explicit the relationships between these elements and supports pivot analysis during an investigation.

Core elements
Adversary, capability, infrastructure, victim
Domain
Cyber threat intelligence
Key use
Pivot analysis across intrusion events

Common questions

How does pivot analysis work within the Diamond Model?+

An analyst starts from one known element of an intrusion, such as a piece of malware infrastructure, and pivots to related elements sharing that same infrastructure or capability, uncovering links to other events, victims, or adversary activity that would not be visible from a single incident viewed in isolation.

How does the Diamond Model differ from the cyber kill chain?+

The kill chain describes the sequential stages of an attack over time, while the Diamond Model describes the structural relationships between the actors and resources involved in a single event. Analysts commonly use both together, mapping kill chain stages while also tracking Diamond Model links across multiple events.

Related terms

Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
STIX
Structured Threat Information eXpression. A standardised, machine-readable language for encoding and sharing threat intelligence objects such as indicators, threat actors, campaigns, and...
Tactics, Techniques, and Procedures (TTPs)
A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
TAXII
Trusted Automated eXchange of Intelligence Information. The transport protocol used to share STIX content between organisations. TAXII defines server and client roles,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.