The Diamond Model of Intrusion Analysis is a structured framework for investigating network compromises by mapping relationships between adversaries, victims, capabilities, and infrastructure. It enables security teams to trace attacker activity across a network and determine the full scope of a breach.
Diamond Model of Intrusion Analysis
Hopefully all of the defenses that we're putting into place are guarding our network and no intrusions can happen onto our network. But we need to be prepared in case that does happen. We need to understand how to evaluate if there's been an intrusion, where the adversary has gone, and what they have compromised.
This is a glimpse into the diamond model of intrusion analysis, named for its diamond shape. So diamond model is just because of the shape that it forms. Intrusion analysis is so we can analyze the intrusion and then take action against it. The diamond model of intrusion analysis is just a defined approach, a step-by-step approach of how we can analyze intrusions.
The problem is that we could discover that there's been some sort of compromise on our network, but how do we know that other machines aren't compromised? How do we know what data has been stolen? How do we know what has happened on the network? That's where the diamond model of intrusion analysis comes into place. It's a way that we can approach analyzing what's happened on our network. This model helps us discover, develop, track, group and counter any kind of adversaries and their actions.
The diamond model uses the cyber kill chain as a basis for its events. Essentially there are these different events that can happen in each one of these steps that an adversary would take.
The diamond model bases everything off of events. A single event is just some single thing that's happened on the network during this intrusion. Each event has:
An event looks like this: it's a diamond shape, and it has the adversary, capability, the victim and the infrastructure on each of the corners of this diamond.
There is other information that we'll collect about the event as well, like when it happened, what phase it happened in, the result, the direction, the methodology and the resource. We call this the meta features of the event.
Now, an event is just a single thing that's happened, but we're going to actually chain these events together to figure out what the adversary was doing along the way. We're going to record those aspects, those meta features. We're going to record all of the data about each one of those events, which will lead us to other events along the way, so we can really analyze where this adversary has been and what they did.
The reason for the diamond shape is because of these relationships. From any point you can see that there is a link to other aspects of this. For instance, if we have the adversary, the adversary has certain capabilities. If we see the capabilities, that might flag certain adversaries. Same thing, capabilities flag a victim, or the victim discovers a capability, the infrastructure. So we can see these links or relationships between each one of these, and by identifying the victim we might be able to see the capabilities, or vice versa.
Let's take a look at an example here. Let's say somebody reaches out to the help desk and says, my machine found a virus on it, there's some sort of malware on it. So now we have a victim. The victim has reached out to us and reported that there's been an issue, and she notices that there is a virus, that the virus scanner found something on the machine. So now we have a victim, and we can record that information within whatever we're recording information on.
That malware is the capabilities. So the victim has led us to the capabilities. Now we take that malware and we scan it, and we realize that it's communicating to the outside world. A lot of malware communicates to the outside world. For instance, if an adversary wants to control something in the network, whatever they're controlling needs to actually communicate outside of the network. Where are they going to communicate to? Maybe it's an IP address, maybe it's a domain, but it has to have some sort of addressing on where to go and communicate. Same thing with something like data exfiltration: that information has to go somewhere out there, and there's a record of that inside the capability.
So we see that now we've linked it to infrastructure. We've got some sort of IP address, some sort of destination where it's going, or in this case right here it's a domain. We look up that domain, it translates to an IP address, so we do have an IP address. Now we have an idea of who the adversary is, or at least a piece of information about that adversary: we have an IP address.
But during the process of all this, we also realize that there's not just one person communicating with this IP address, but there is somebody else that's communicating. Now we've just discovered another victim, and so we can create a whole new diamond for that victim, and now we're starting to trace it through our network to discover more victims on our network. So what we've done is we've realized that there's this malware that's reaching out to the IP address, and on the firewall we see other victims that are reaching out to the same IP address. So we had one event here, and that spurs on another event, and we just keep tracing this down until we find within our network everywhere that adversary has traversed.
We can also put this into a table. As I mentioned, we've got the cyber kill chain, which is reconnaissance, weaponization, delivery, exploitation, installation, C2, action on objectives, and adversaries are going to step through this process as they go along. But maybe they're doing reconnaissance here and there's a couple of steps there, and then they move to the delivery of this and exploitation. So what we can do is start mapping things out on here, and even develop other threads where we're tracking multiple threads of this adversary.
The end result of doing this analysis is that now we see, as they've moved throughout our network, where they've gone and what they've infected and what they have compromised.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →