惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
罗磊的独立博客
小众软件
小众软件
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
博客园_首页
N
Netflix TechBlog - Medium
B
Blog
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
Last Week in AI
Last Week in AI
Jina AI
Jina AI
V
V2EX
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
博客园 - 【当耐特】

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly
Prompt engineering: Conduct a Diamond Model of Intrusion ...
Andrew Castro · 2025-03-14 · via New in Feedly

The Diamond Model of Intrusion Analysis is a widely used framework in cybersecurity to analyze adversary behaviors, infrastructure, and victimology during successful and attempted attacks. However, manually extracting and structuring information from threat reports can be time-consuming.

With Feedly Ask AI, analysts can now generate a diamond model analysis with a simple AI Prompt—helping teams quickly visualize threats and identify key attack patterns based on select reporting.

This article will show you how to run the prompt on a single article or multiple articles about the same attack.

Ask AI Prompt

<Role> 
Lead Threat Intelligence Analyst
<Role> 

<Task> 
Conduct a Diamond Model of Intrusion Analysis that contains all pertinent information from this report. Additionally, provide the information so that an analyst can create an image of the diamond model to depict key findings.
<Task> 

<Guidelines> 
- Extract detailed technical information from the report  
- Structure findings based on the diamond model framework  
- Ensure all elements (Adversary, Infrastructure, Capabilities, Victimology) are included  
- Provide accurate and actionable intelligence  
- Include citations and references where applicable
<Guidelines> 

Ask AI Response - On a single article

We ran this prompt on an AI Feed monitoring threat reports related to North Korean state-sponsored actors. The output generated a structured diamond model analysis, detailing the adversary, infrastructure, capabilities, and victimology in a clear and actionable format. The AI response also incorporated attack timelines, socio-political context, and a visualization guide, making it easier for analysts to assess the full scope of the incident. This prompt can be saved in the prompt library and reused to analyze other cyber threats consistently.

Ask AI Response - On multiple articles

Running the same prompt on an AI Feed, rather than individual articles, provides a more extensive dataset from which to extract intelligence. This bigger dataset enables you to explore diverse perspectives and significantly expand the volume and quality of insights. Ultimately, it gives you a broader scope of information.

For this example, we applied the same prompt to an AI Feed focused on the specific attack. We selected 10 articles and reports to run the Ask AI prompt. As you can see in the visual below, in-line citations link your output to the original reports for transparent verification and traceability.

Running Ask AI on multiple vs single articles

Tailor your analysis based on your needs—focus on a single article for in-depth insights from a trusted source or analyze multiple articles to uncover broader patterns, validate details, and track emerging trends across sources.

By running Ask AI on an AI Feed, analysts can move beyond fragmented reports and generate a comprehensive diamond model analysis with greater depth, accuracy, and traceability.

Try Ask AI

Quickly synthesize content and create trusted, verifiable reports.

Start Free Trial