The Diamond Model Explained: Intrusion Analysis for the CySA+ Exam
The Diamond Model analyses a single intrusion event through four connected features. Its value is that establishing any one of them gives you a route to discovering the others — which is what makes it an investigative tool rather than a taxonomy. The four vertices Adversary — who is conducting the intrusion. The operator actually at the keyboard, and behind them the customer who benefits. Capability — what they use. Malware, exploits, stolen credentials, techniques. Infrastructure — what they use it from and through. Command and control servers, domains, IP addresses, email accounts, compromised third-party hosts. Victim — who is targeted. The organisation, and also the specific assets and people. The core axiom is worth stating as the model does: for every intrusion, an adversary uses a capability over some infrastructure against a victim. Every event has all four, even when you only know one. Pivoting — why the model is useful The diamond shape is not decoration. The vert...