Implementing Diamond Model Analysis
Overview
The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads linking related events, create activity-attack graphs, and generate pivot-ready intelligence from intrusion data.
When to Use
- When deploying or configuring implementing diamond model analysis capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Common Misconfigurations & Verification
- Empty core features break pivots: events missing one of the four vertices (Adversary/Capability/Infrastructure/Victim) silently drop out of
find_pivots(), which only pivots on non-empty fields. Validate every DiamondEvent populates all four before adding it.
- Unnormalized infrastructure values:
1.2.3.4, 1.2.3.4:443, and hxxp://1.2.3.4 are treated as distinct infrastructure nodes, so shared-infra pivots are missed. Canonicalize values before graphing.
- Timestamp format drift:
build_activity_thread() sorts lexically on the timestamp string - mixed formats (epoch vs ISO-8601) corrupt thread ordering. Enforce UTC ISO-8601.
- Capability not mapped to ATT&CK: leaving
mitre_techniques empty prevents cross-event capability correlation and ATT&CK-based clustering of activity groups.
- Over-merging activity groups: clustering threads on shared infrastructure alone (CDN, shared host) creates false activity groups - require a capability or adversary pivot as well.
- Verification: confirm pivot output groups only events with >1 shared value, render the activity-attack graph and check edges are chronological, and verify each event resolves to valid ATT&CK technique IDs.
Prerequisites
- Python 3.9+ with
networkx, stix2, graphviz libraries
- Understanding of the Diamond Model core and meta-features
- Access to threat intelligence data (MISP/OpenCTI events)
- Familiarity with MITRE ATT&CK for capability mapping
Key Concepts
Diamond Model Core Features
- Adversary: The threat actor or operator conducting the intrusion
- Capability: The tools, techniques, and malware used (maps to ATT&CK)
- Infrastructure: C2 servers, domains, email addresses, hosting providers
- Victim: Target organization, system, person, or data asset
Meta-Features
- Timestamp: When the event occurred
- Phase: Kill chain stage (recon, delivery, exploitation, etc.)
- Result: Success, failure, or unknown
- Direction: Adversary-to-infrastructure, infrastructure-to-victim, etc.
- Methodology: Social engineering, technical exploit, insider threat
- Resources: Financial, human, technical resources required
Activity Threads and Groups
- Activity Thread: Sequence of Diamond events from a single adversary operation
- Activity Group: Cluster of threads attributed to the same adversary
Workflow
Step 1: Define Diamond Event Data Structure
from dataclasses import dataclass, field
from datetime import datetime
from typing import Optional
import json
import uuid
@dataclass
class DiamondEvent:
adversary: str = ""
capability: str = ""
infrastructure: str = ""
victim: str = ""
timestamp: str = ""
phase: str = ""
result: str = ""
direction: str = ""
methodology: str = ""
confidence: int = 0
notes: str = ""
event_id: str = field(default_factory=lambda: str(uuid.uuid4())[:8])
mitre_techniques: list = field(default_factory=list)
iocs: list = field(default_factory=list)
def to_dict(self):
return {
"event_id": self.event_id,
"adversary": self.adversary,
"capability": self.capability,
"infrastructure": self.infrastructure,
"victim": self.victim,
"timestamp": self.timestamp,
"phase": self.phase,
"result": self.result,
"direction": self.direction,
"methodology": self.methodology,
"confidence": self.confidence,
"mitre_techniques": self.mitre_techniques,
"iocs": self.iocs,
"notes": self.notes,
}
Step 2: Build Activity Thread from Events
import networkx as nx
class DiamondAnalysis:
def __init__(self):
self.events = []
self.graph = nx.DiGraph()
def add_event(self, event: DiamondEvent):
self.events.append(event)
self.graph.add_node(event.event_id, **event.to_dict())
def build_activity_thread(self):
"""Link events chronologically into activity threads."""
sorted_events = sorted(self.events, key=lambda e: e.timestamp)
for i in range(len(sorted_events) - 1):
self.graph.add_edge(
sorted_events[i].event_id,
sorted_events[i + 1].event_id,
relationship="followed_by",
)
def find_pivots(self):
"""Find pivot points where events share infrastructure or capabilities."""
pivots = {"infrastructure": {}, "capability": {}, "adversary": {}}
for event in self.events:
if event.infrastructure:
pivots["infrastructure"].setdefault(event.infrastructure, []).append(event.event_id)
if event.capability:
pivots["capability"].setdefault(event.capability, []).append(event.event_id)
if event.adversary:
pivots["adversary"].setdefault(event.adversary, []).append(event.event_id)
return {
k: {pk: pv for pk, pv in v.items() if len(pv) > 1}
for k, v in pivots.items()
}
def generate_report(self):
return {
"total_events": len(self.events),
"unique_adversaries": len(set(e.adversary for e in self.events if e.adversary)),
"unique_victims": len(set(e.victim for e in self.events if e.victim)),
"unique_infrastructure": len(set(e.infrastructure for e in self.events if e.infrastructure)),
"pivots": self.find_pivots(),
"events": [e.to_dict() for e in self.events],
}
Validation Criteria
- Diamond events capture all four core features with meta-features
- Activity threads link related events chronologically
- Pivot analysis identifies shared infrastructure and capabilities across events
- Graph visualization renders the activity-attack graph correctly
- Events map to MITRE ATT&CK techniques for capability classification
References
1---2name: implementing-diamond-model-analysis3description: The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features - Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.4license: Apache-2.05---6# Implementing Diamond Model Analysis
7
8## Overview
9
10The Diamond Model of Intrusion Analysis provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. This skill covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads linking related events, create activity-attack graphs, and generate pivot-ready intelligence from intrusion data.
11
12
13## When to Use
14
15- When deploying or configuring implementing diamond model analysis capabilities in your environment
16- When establishing security controls aligned to compliance requirements
17- When building or improving security architecture for this domain
18- When conducting security assessments that require this implementation
19
20## Common Misconfigurations & Verification
21
22- **Empty core features break pivots:** events missing one of the four vertices (Adversary/Capability/Infrastructure/Victim) silently drop out of `find_pivots()`, which only pivots on non-empty fields. Validate every `DiamondEvent` populates all four before adding it.
23- **Unnormalized infrastructure values:** `1.2.3.4`, `1.2.3.4:443`, and `hxxp://1.2.3.4` are treated as distinct infrastructure nodes, so shared-infra pivots are missed. Canonicalize values before graphing.
24- **Timestamp format drift:** `build_activity_thread()` sorts lexically on the `timestamp` string - mixed formats (epoch vs ISO-8601) corrupt thread ordering. Enforce UTC ISO-8601.
25- **Capability not mapped to ATT&CK:** leaving `mitre_techniques` empty prevents cross-event capability correlation and ATT&CK-based clustering of activity groups.
26- **Over-merging activity groups:** clustering threads on shared infrastructure alone (CDN, shared host) creates false activity groups - require a capability or adversary pivot as well.
27- **Verification:** confirm pivot output groups only events with >1 shared value, render the activity-attack graph and check edges are chronological, and verify each event resolves to valid ATT&CK technique IDs.
28
29## Prerequisites
30
31- Python 3.9+ with `networkx`, `stix2`, `graphviz` libraries
32- Understanding of the Diamond Model core and meta-features
33- Access to threat intelligence data (MISP/OpenCTI events)
34- Familiarity with MITRE ATT&CK for capability mapping
35
36## Key Concepts
37
38### Diamond Model Core Features
39- **Adversary**: The threat actor or operator conducting the intrusion
40- **Capability**: The tools, techniques, and malware used (maps to ATT&CK)
41- **Infrastructure**: C2 servers, domains, email addresses, hosting providers
42- **Victim**: Target organization, system, person, or data asset
43
44### Meta-Features
45- **Timestamp**: When the event occurred
46- **Phase**: Kill chain stage (recon, delivery, exploitation, etc.)
47- **Result**: Success, failure, or unknown
48- **Direction**: Adversary-to-infrastructure, infrastructure-to-victim, etc.
49- **Methodology**: Social engineering, technical exploit, insider threat
50- **Resources**: Financial, human, technical resources required
51
52### Activity Threads and Groups
53- **Activity Thread**: Sequence of Diamond events from a single adversary operation
54- **Activity Group**: Cluster of threads attributed to the same adversary
55
56## Workflow
57
58### Step 1: Define Diamond Event Data Structure
59
60```python
61from dataclasses import dataclass, field
62from datetime import datetime
63from typing import Optional
64import json
65import uuid
66
67@dataclass
68class DiamondEvent:
69 adversary: str = ""
70 capability: str = ""
71 infrastructure: str = ""
72 victim: str = ""
73 timestamp: str = ""
74 phase: str = ""
75 result: str = ""
76 direction: str = ""
77 methodology: str = ""
78 confidence: int = 0
79 notes: str = ""
80 event_id: str = field(default_factory=lambda: str(uuid.uuid4())[:8])
81 mitre_techniques: list = field(default_factory=list)
82 iocs: list = field(default_factory=list)
83
84 def to_dict(self):
85 return {
86 "event_id": self.event_id,
87 "adversary": self.adversary,
88 "capability": self.capability,
89 "infrastructure": self.infrastructure,
90 "victim": self.victim,
91 "timestamp": self.timestamp,
92 "phase": self.phase,
93 "result": self.result,
94 "direction": self.direction,
95 "methodology": self.methodology,
96 "confidence": self.confidence,
97 "mitre_techniques": self.mitre_techniques,
98 "iocs": self.iocs,
99 "notes": self.notes,
100 }
101```
102
103### Step 2: Build Activity Thread from Events
104
105```python
106import networkx as nx
107
108class DiamondAnalysis:
109 def __init__(self):
110 self.events = []
111 self.graph = nx.DiGraph()
112
113 def add_event(self, event: DiamondEvent):
114 self.events.append(event)
115 self.graph.add_node(event.event_id, **event.to_dict())
116
117 def build_activity_thread(self):
118 """Link events chronologically into activity threads."""
119 sorted_events = sorted(self.events, key=lambda e: e.timestamp)
120 for i in range(len(sorted_events) - 1):
121 self.graph.add_edge(
122 sorted_events[i].event_id,
123 sorted_events[i + 1].event_id,
124 relationship="followed_by",
125 )
126
127 def find_pivots(self):
128 """Find pivot points where events share infrastructure or capabilities."""
129 pivots = {"infrastructure": {}, "capability": {}, "adversary": {}}
130
131 for event in self.events:
132 if event.infrastructure:
133 pivots["infrastructure"].setdefault(event.infrastructure, []).append(event.event_id)
134 if event.capability:
135 pivots["capability"].setdefault(event.capability, []).append(event.event_id)
136 if event.adversary:
137 pivots["adversary"].setdefault(event.adversary, []).append(event.event_id)
138
139 return {
140 k: {pk: pv for pk, pv in v.items() if len(pv) > 1}
141 for k, v in pivots.items()
142 }
143
144 def generate_report(self):
145 return {
146 "total_events": len(self.events),
147 "unique_adversaries": len(set(e.adversary for e in self.events if e.adversary)),
148 "unique_victims": len(set(e.victim for e in self.events if e.victim)),
149 "unique_infrastructure": len(set(e.infrastructure for e in self.events if e.infrastructure)),
150 "pivots": self.find_pivots(),
151 "events": [e.to_dict() for e in self.events],
152 }
153```
154
155## Validation Criteria
156
157- Diamond events capture all four core features with meta-features
158- Activity threads link related events chronologically
159- Pivot analysis identifies shared infrastructure and capabilities across events
160- Graph visualization renders the activity-attack graph correctly
161- Events map to MITRE ATT&CK techniques for capability classification
162
163## References
164
165- [Diamond Model Paper](https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf)
166- [MITRE ATT&CK](https://attack.mitre.org/)
167- [STIX 2.1 Campaign Object](https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html)