Is there any open-source threat modeling tool - sort of like SDL Threat Modeling from Microsoft?
Microsoft Threat Modeling ToolIt is an open-source tool that follows the spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege (STRIDE) methodology. Platform: MTMT is a desktop-based tool that runs on Windows OS.
OWASP Threat Dragon provides a free, open-source, threat modeling application for teams implementing the STRIDE approach. It can also be used for categorising threats using LINDDUN and CIA. The key areas of focus for the tool is: Great UX - using Threat Dragon should be simple, engaging and fun.
The Microsoft Threat Modeling Tool is currently released as a free click-to-download application for Windows. This delivery mechanism allows us to push the latest improvements and bug fixes to customers each time they open the tool.
The Open Web Application Security Project (OWASP) is a 501c3 not-for-profit worldwide charitable organization focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.
Threat modeling area, towards the bottom of the page;
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With