What is Diamond Model?
The Diamond Model of Intrusion Analysis represents every intrusion event as a relationship between four core features: Adversary, Capability, Infrastructure, and Victim, connected in a diamond shape to facilitate threat intelligence analysis and attribution.
Definition
- Diamond Model
- The Diamond Model of Intrusion Analysis represents every intrusion event as a relationship between four core features: Adversary, Capability, Infrastructure, and Victim, connected in a diamond shape to facilitate threat intelligence analysis and attribution.
How Diamond Model Works
Developed by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz and published through the US Department of Defense, the Diamond Model gives analysts a repeatable schema for describing a single intrusion event, and a method for connecting many events into a campaign. The four vertices sit at the corners of a diamond: Adversary (the actor's identity, if known, along with motivation and intent), Capability (the malware, exploits, and tools used), Infrastructure (the IPs, domains, hosting providers, and C2 servers), and Victim (the targeted organization, system, or data). Meta-features around the diamond, timestamp, phase (mapping loosely to kill chain stages), result, and direction, add context to each event.
The model's value is in pivoting. Start with a malware sample (Capability), extract the C2 domains it communicates with (Infrastructure), then search historical data for every other victim that saw traffic to that same infrastructure (Victim), and the pattern across those victims starts to reveal who the Adversary is likely targeting and why. Analysts chain multiple diamonds together, linking one intrusion event's infrastructure to the next event's capability, to build an activity thread showing a campaign's evolution over time.
Where MITRE ATT&CK catalogs what techniques an adversary used, the Diamond Model provides the relational structure for connecting those techniques back to a specific actor and campaign across multiple incidents, which is why the two frameworks are typically used together rather than as alternatives: ATT&CK for the how, Diamond for the who and the connections between events.
The model also formalizes the Adversary vertex into two distinct roles that are easy to conflate: the Adversary-Operator (the individual or team physically running the intrusion, hands on keyboard) and the Adversary-Customer (whoever benefits from the operation, which in a nation-state or ransomware-affiliate context can be a different party than the operator). Separating the two prevents analysts from mistaking an infrastructure-for-hire provider for the actual sponsoring actor, a distinction that matters for attribution and for anticipating what the adversary wants next.
Diamond Model in SOC Operations
You apply Diamond Model thinking every time you pivot outward from a single indicator during investigation. Starting from one flagged IP (Infrastructure), you check what other internal hosts have contacted it (additional Victim data), what malware family has used that infrastructure before (Capability), and whether threat intelligence attributes that combination to a known actor (Adversary). That structured pivoting produces a far richer picture than treating the IOC as an isolated data point, and it's often how an analyst discovers that what looked like an isolated alert is actually the third event in an ongoing campaign against the organization. Documenting investigations along the four vertices also makes it easier to hand off findings to a threat intelligence team, who can slot your event into a larger activity thread and check whether the same adversary has hit other organizations in the sector. Even without full attribution, filling in as many vertices as the evidence supports (Capability and Infrastructure are usually the easiest, Adversary the hardest) turns a one-off ticket into intelligence someone else can build on.
Practice Diamond Model in a Real SOC
SOCSimulator provides hands-on training with realistic SIEM, XDR, and Firewall interfaces. Build real analyst skills investigating diamond model scenarios with zero consequences, free.
Related Terms
MITRE ATT&CK® is a globally accessible knowledge base of adversary tactics and techniques observed i...
Threat intelligence is analyzed, contextualized information about current and emerging cyber threats...
An Indicator of Compromise (IOC) is an observable artifact, such as a file hash, IP address, domain ...
An Advanced Persistent Threat (APT) is a sophisticated, often nation-state-sponsored threat actor co...
Threat hunting is the proactive, human-led process of searching through security telemetry to find h...
More Frameworks Terms
Related SOC Training Resources
SOC Manager Career Guide: Salary & Skills
SOC Managers run the operation. You own staffing, playbook development, tool selection, performance metrics, and executi…
Read more Career PathDetection Engineer Career Guide: Salary & Skills
Detection Engineers build the rules, analytics, and automated workflows that determine what the SOC can see. You transla…
Read more Career PathSecurity Engineer Career Guide: Salary & Skills
Security Engineers build and maintain the infrastructure that SOC analysts depend on. You deploy SIEMs, configure firewa…
Read more ComparisonSOCSimulator vs CyberDefenders: Comparison
SOCSimulator trains the operational workflow: alert triage, correlation, and response under pressure. CyberDefenders tra…
Read more ComparisonSOCSimulator vs Security Blue Team: Comparison
SOCSimulator provides continuous operational training that keeps your skills sharp between shifts. Security Blue Team pr…
Read more ToolSIEM Training Console: SOCSimulator
The SIEM console in SOCSimulator replicates the workflow of enterprise platforms like Splunk Enterprise Security, Micros…
Read more TechniqueMITRE ATT&CK® Techniques: Detection Training Library
Browse all MITRE ATT&CK® techniques with detection strategies and example alerts.
Read more Career PathCybersecurity Career Paths: 2026 Guide
Explore SOC analyst career paths with salary data, required skills, and certification roadmaps.
Read more PlaybookSOC Investigation Playbooks: Step-by-Step Guides
Practitioner investigation playbooks with decision trees and real SIEM queries.
Read more FeatureShift Mode: Real-Time SOC Simulation
Practice alert triage under realistic time pressure with SLA timers and noise injection.
Read more FeatureOperations: Guided Training Operations
Structured CTF-style investigation operations covering real-world attack scenarios.
Read more BlogSOCSimulator Blog: Security Training Insights
Articles on SOC analyst skills, detection engineering, and career development.
Read more