A wastewater plant tabletop uses the Diamond Model of adversary, capability, infrastructure, and victim. How should the analyst apply those vertices in Enterprise Security?
Select an answer to reveal the explanation.
Short Explanation
Diamond is a thinking square, not a Splunk index. Adversary, capability, infrastructure, and victim tell you what to pivot on — IPs, domains, plant assets — inside the ES you already have. Do not go hunting for a Diamond sourcetype.
Full Explanation
The Diamond Model of Intrusion Analysis gives four vertices: adversary, capability, infrastructure, and victim. Analysts apply it by choosing pivots in Enterprise Security — infrastructure such as IP addresses and domains, victim assets from Asset and Identity — not by treating Diamond as an index, sourcetype, or CIM replacement. Renaming a correlation search does not instantiate the model. Frameworks guide investigation; they are not Splunk objects.