The framework is the Diamond Model of Intrusion Analysis . The Diamond Model represents malicious activity using four core interconnected features: adversary, infrastructure, capability, and victim . This structure allows incident responders and threat-intelligence analysts to examine relationships between who conducted an intrusion, the technical resources used, the capabilities or tools involved, and the targeted organization or asset.
The original Diamond Model paper explicitly defines an intrusion event around these four core features and connects them in a diamond-shaped analytical structure. This relational approach is particularly useful for correlating separate intrusion events, identifying common infrastructure, associating capabilities with adversaries, and developing broader campaign intelligence.
STRIDE is a threat-modeling categorization method covering spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. MITRE ATT & CK organizes real-world adversary behavior according to tactics and techniques. The Cyber Kill Chain organizes intrusion activity into sequential attack stages. The NIST Cybersecurity Framework is a broader cybersecurity risk-management framework rather than an intrusion-event relationship model.
Therefore, a diagram or report organized around adversary–capability–infrastructure–victim relationships specifically identifies the Diamond Model.
Study Guide Reference: Incident Response and Management → Attack Methodology Frameworks → Diamond Model of Intrusion Analysis → Adversary → Infrastructure → Capability → Victim.