📖 What is Diamond Model of Intrusion Analysis?
The Diamond Model of Intrusion Analysis is a framework used to map cyber attacks by connecting four core features: adversary, capability, infrastructure, and victim. This allows analysts to identify patterns and pivot between these elements to uncover more about a threat.
"The key to the Diamond Model is 'pivoting.' If you have the infrastructure, you can pivot to find the adversary or the capability."
📚 Certification: CompTIA Cybersecurity Analyst+ (CS0-003)
🔑 What are the Key Concepts of Diamond Model of Intrusion Analysis?
- ▸ Adversary represents the threat actor or group responsible for the attack, focusing on identifying the 'who' behind the malicious activity.
- ▸ Capability refers to the tools, techniques, and malware employed by the adversary to execute the attack, answering 'how' the breach occurred.
- ▸ Infrastructure comprises the physical or virtual assets, such as C2 servers or IP addresses, used to deliver the attack to the victim.
- ▸ Victim identifies the target person or organization, including the specific assets or vulnerabilities exploited during the intrusion event.
- ▸ Pivoting is the process of using a known element (vertex) to discover related elements, enabling analysts to map the full scope of an attack.
🎯 How does Diamond Model of Intrusion Analysis appear on the CS0-003 Exam?
You may be asked to identify which vertex of the Diamond Model is being analyzed when a security researcher discovers a new C2 server IP address and uses it to find other related malicious domains.
A scenario might describe an analyst who has identified a specific piece of custom malware and is now searching for other victims targeted by the same tool to identify a common pattern.
Expect questions where you must choose the Diamond Model over the Cyber Kill Chain when the primary goal is to analyze the relational links between an adversary, their infrastructure, and the victim.
❓ Frequently Asked Questions
How does the Diamond Model differ from the Cyber Kill Chain?
The Cyber Kill Chain focuses on the linear stages of an attack from reconnaissance to actions on objectives. In contrast, the Diamond Model focuses on the relationships between the four vertices, allowing for non-linear analysis and pivoting.
What is a 'pivot' in the context of the Diamond Model?
Pivoting occurs when an analyst takes a known piece of information, such as a malicious IP (infrastructure), and uses it to uncover the malware used (capability) or the actor responsible (adversary), expanding the intelligence map.