January 2020
Intermediate to advanced
448 pages
11h 42m
English
The diamond model of intrusion analysis is a methodology used to describe the process of differentiating APT threats from their specific attributes. The diamond is comprised of four components: Adversary, Infrastructure, Capability, and Victim.
The model attempts to determine the interplay between each of these four groups:

For example, take a simple malware attack. The Adversary is going to use a custom piece of malware. Their ability to develop custom malware indicates their Capability. The Adversary then utilizes their capability to deploy the malware via a compromised web server or infrastructure. This connects to the Victim ...
Read now
Unlock full access