Skip to main content
FrameworksSIEM

What is Diamond Model?

The Diamond Model of Intrusion Analysis represents every intrusion event as a relationship between four core features: Adversary, Capability, Infrastructure, and Victim, connected in a diamond shape to facilitate threat intelligence analysis and attribution.

Definition

Diamond Model
The Diamond Model of Intrusion Analysis represents every intrusion event as a relationship between four core features: Adversary, Capability, Infrastructure, and Victim, connected in a diamond shape to facilitate threat intelligence analysis and attribution.

How Diamond Model Works

Developed by Sergio Caltagirone, Andrew Pendergast, and Christopher Betz and published through the US Department of Defense, the Diamond Model gives analysts a repeatable schema for describing a single intrusion event, and a method for connecting many events into a campaign. The four vertices sit at the corners of a diamond: Adversary (the actor's identity, if known, along with motivation and intent), Capability (the malware, exploits, and tools used), Infrastructure (the IPs, domains, hosting providers, and C2 servers), and Victim (the targeted organization, system, or data). Meta-features around the diamond, timestamp, phase (mapping loosely to kill chain stages), result, and direction, add context to each event.

The model's value is in pivoting. Start with a malware sample (Capability), extract the C2 domains it communicates with (Infrastructure), then search historical data for every other victim that saw traffic to that same infrastructure (Victim), and the pattern across those victims starts to reveal who the Adversary is likely targeting and why. Analysts chain multiple diamonds together, linking one intrusion event's infrastructure to the next event's capability, to build an activity thread showing a campaign's evolution over time.

Where MITRE ATT&CK catalogs what techniques an adversary used, the Diamond Model provides the relational structure for connecting those techniques back to a specific actor and campaign across multiple incidents, which is why the two frameworks are typically used together rather than as alternatives: ATT&CK for the how, Diamond for the who and the connections between events.

The model also formalizes the Adversary vertex into two distinct roles that are easy to conflate: the Adversary-Operator (the individual or team physically running the intrusion, hands on keyboard) and the Adversary-Customer (whoever benefits from the operation, which in a nation-state or ransomware-affiliate context can be a different party than the operator). Separating the two prevents analysts from mistaking an infrastructure-for-hire provider for the actual sponsoring actor, a distinction that matters for attribution and for anticipating what the adversary wants next.

Diamond Model in SOC Operations

You apply Diamond Model thinking every time you pivot outward from a single indicator during investigation. Starting from one flagged IP (Infrastructure), you check what other internal hosts have contacted it (additional Victim data), what malware family has used that infrastructure before (Capability), and whether threat intelligence attributes that combination to a known actor (Adversary). That structured pivoting produces a far richer picture than treating the IOC as an isolated data point, and it's often how an analyst discovers that what looked like an isolated alert is actually the third event in an ongoing campaign against the organization. Documenting investigations along the four vertices also makes it easier to hand off findings to a threat intelligence team, who can slot your event into a larger activity thread and check whether the same adversary has hit other organizations in the sector. Even without full attribution, filling in as many vertices as the evidence supports (Capability and Infrastructure are usually the easiest, Adversary the hardest) turns a one-off ticket into intelligence someone else can build on.

Free

Practice Diamond Model in a Real SOC

SOCSimulator provides hands-on training with realistic SIEM, XDR, and Firewall interfaces. Build real analyst skills investigating diamond model scenarios with zero consequences, free.

More Frameworks Terms

Career Path

SOC Manager Career Guide: Salary & Skills

SOC Managers run the operation. You own staffing, playbook development, tool selection, performance metrics, and executi…

Read more
Career Path

Detection Engineer Career Guide: Salary & Skills

Detection Engineers build the rules, analytics, and automated workflows that determine what the SOC can see. You transla…

Read more
Career Path

Security Engineer Career Guide: Salary & Skills

Security Engineers build and maintain the infrastructure that SOC analysts depend on. You deploy SIEMs, configure firewa…

Read more
Comparison

SOCSimulator vs CyberDefenders: Comparison

SOCSimulator trains the operational workflow: alert triage, correlation, and response under pressure. CyberDefenders tra…

Read more
Comparison

SOCSimulator vs Security Blue Team: Comparison

SOCSimulator provides continuous operational training that keeps your skills sharp between shifts. Security Blue Team pr…

Read more
Tool

SIEM Training Console: SOCSimulator

The SIEM console in SOCSimulator replicates the workflow of enterprise platforms like Splunk Enterprise Security, Micros…

Read more
Technique

MITRE ATT&CK® Techniques: Detection Training Library

Browse all MITRE ATT&CK® techniques with detection strategies and example alerts.

Read more
Career Path

Cybersecurity Career Paths: 2026 Guide

Explore SOC analyst career paths with salary data, required skills, and certification roadmaps.

Read more
Playbook

SOC Investigation Playbooks: Step-by-Step Guides

Practitioner investigation playbooks with decision trees and real SIEM queries.

Read more
Feature

Shift Mode: Real-Time SOC Simulation

Practice alert triage under realistic time pressure with SLA timers and noise injection.

Read more
Feature

Operations: Guided Training Operations

Structured CTF-style investigation operations covering real-world attack scenarios.

Read more
Blog

SOCSimulator Blog: Security Training Insights

Articles on SOC analyst skills, detection engineering, and career development.

Read more