skip to content

Threat Modeling

The structured practice of finding threats before the attacker does: modeling a system with data-flow diagrams and trust boundaries, enumerating threats with STRIDE or PASTA, and rating the risk. Senior security and DevSecOps interviews often run this live — you are handed an architecture and asked to threat-model it on a whiteboard.

on this pageshow

explore

questions

232 · 8 sections

In a threat model, how do integrity, authenticity and non-repudiation differ as goals?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Integrity means data has not been altered outside authorised change. Authenticity means the claimed origin of a message or request is genuine. Non-repudiation means the originator cannot later credibly deny it, with evidence that convinces a third party.

open as a page

What are the four questions in Shostack's four-question threat modeling frame?

level: juniorimportance: must knowfreq 80%
basics
~20 s

What are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job? They run in that order and repeat as a loop, not a one-off checklist.

open as a page

In threat modeling, what is an actor assumption and how does it bound the threats you keep?

level: middleimportance: must knowfreq 62%
basics
~20 s

An actor assumption is a written statement of the adversary you defend against: their capability, resources and access. It bounds the model, because a threat stays in scope only if that assumed actor could reach and carry it out.

open as a page

For a stadium ticketing on-sale, which assets must the threat model protect?

level: middleimportance: must knowfreq 58%
basics
~20 s

The assets are the ability to complete a purchase during the on-sale window, fair allocation of the inventory, the revenue, and fan trust. Seat-map confidentiality carries almost no loss — here availability and functionality are the assets, not stored data.

open as a page

In a threat model, what does a recorded assumption need to contain to be useful?

level: middleimportance: must knowfreq 55%
basics
~20 s

A usable assumption states the claim in a form that could be proved false, names the team that owns it, says which threats come back if it is wrong, and gives an event or date that forces a recheck.

open as a page

What does a level-0 context diagram show in a data-flow-diagram threat model?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A level-0 context diagram draws the whole system as one process, every external entity that talks to it, and the flows between them. It fixes scope and shows what crosses the outer trust boundary, with no internal structure.

open as a page

On a threat-modeling data-flow diagram, what do process, data store, external entity and flow each represent?

level: juniorimportance: must knowfreq 76%
basics
~20 s

A process is running code that transforms data, a data store is passive data at rest, an external entity is a person or system you do not control, and a flow is data in motion between them.

open as a page

When you enumerate entry points on a data-flow diagram, what counts as one?

level: juniorimportance: must knowfreq 68%
basics
~20 s

An entry point is anywhere data or a request crosses into the system from outside its trust boundary. Not just HTTP endpoints: queue consumers, file drops, inbound email, webhooks, scheduled jobs that fetch remote data, and admin or support consoles all count.

open as a page

On a data-flow diagram, what does a trust boundary mark, and what decides where it is drawn?

level: juniorimportance: must knowfreq 78%
basics
~20 s

A trust boundary marks a data flow where the two sides do not trust each other equally. Draw it wherever the principal, privilege, tenant, code owner or execution context changes - not wherever the network or a firewall changes.

open as a page

What does a data-flow diagram deliberately omit, and which threats hide in those omissions?

level: middleimportance: must knowfreq 62%
basics
~20 s

A data-flow diagram shows what data moves where, not when or in what order. It omits control flow, sequencing, retries and error paths, so replay, race, double-processing and failure-path leak threats stay invisible on it.

open as a page

In STRIDE, which property does Denial of Service violate, and how does it appear on a process, a store and a flow?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Denial of Service violates availability - legitimate users stop being served. On a process it exhausts CPU, memory or threads; on a store it fills or locks storage; on a flow it saturates or cuts the channel.

open as a page

In STRIDE, what does the Elevation of Privilege category cover and which property does it violate?

level: juniorimportance: must knowfreq 76%
basics
~20 s

Elevation of Privilege is STRIDE's category for an actor gaining rights it was never granted - doing something it is not permitted to do. It violates authorization, and the answering controls are authorization decisions plus least privilege.

open as a page

A production API returns unhandled stack traces and still routes /debug/env — why is this an information-disclosure threat?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Both hand an unauthenticated stranger internal detail for free: stack traces expose paths, versions and sometimes a connection string; a debug route dumps environment variables including keys. Return generic errors, keep the route out of production builds, and rotate anything exposed.

open as a page

What is the Repudiation threat in STRIDE, and which security property does it violate?

level: juniorimportance: must knowfreq 75%
basics
~20 s

Repudiation is an actor plausibly denying an action they took, or falsely claiming one they did not, because the system kept no trustworthy evidence. It violates non-repudiation, and the answering control family is identity plus auditing.

open as a page

In STRIDE, which security property does Tampering violate, and which diagram elements can carry it?

level: juniorimportance: must knowfreq 82%
basics
~20 s

Tampering violates integrity: someone modifies data or code they are not authorized to change. On a data-flow diagram it applies to processes, data flows and data stores, but not to external entities, which get spoofed instead.

open as a page

In an attack tree, how do node costs propagate through AND versus OR nodes to the root?

level: middleimportance: must knowfreq 62%
basics
~20 s

In an attack tree, an AND node costs the sum of its children, because the attacker must complete all of them. An OR node costs the minimum, because the attacker picks one. The root holds the cheapest complete attack.

open as a page

On an attack tree, what attributes besides cost annotate a node, and why keep them separate?

level: middleimportance: must knowfreq 46%
basics
~20 s

Annotate each leaf with independent attributes: money, skill level, elapsed time, required access, equipment and detectability. Collapsing them into one number hides that a step can be cheap in cash yet demand rare skill or insider access nobody can buy.

open as a page

How do you turn a user story into an evil user story a developer can act on?

level: middleimportance: must knowfreq 60%
basics
~20 s

Keep the three story clauses and make each hostile: the role becomes a named attacker persona, the capability becomes what they want the system to allow, and the benefit becomes their payoff. The asset stays in the final clause.

open as a page

In an attack tree, what separates a usable concrete-action leaf from a category leaf?

level: middleimportance: must knowfreq 62%
basics
~20 s

A concrete-action leaf names one specific thing an attacker does on this system, specific enough to cost and to defend. A category leaf such as 'obtain a credential' only restates the sub-goal above it, hides the real work, and maps to no control.

open as a page

How do you turn an abuse case into an acceptance criterion and then an automated negative test?

level: middleimportance: must knowfreq 62%
basics
~10 s

Restate the attacker's goal as a must-not statement with an observable outcome, then write a test that runs from the adversary's position and asserts the refusal, the unchanged state, and the recorded evidence.

open as a page

What are the seven LINDDUN threat types, and which privacy property does each one break?

level: middleimportance: must knowfreq 72%
basics
~10 s

LINDDUN covers Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness and Non-compliance. Each names the failure of a privacy property: unlinkability, anonymity, plausible deniability, undetectability, confidentiality, user awareness, and policy compliance.

open as a page

Why does a privacy threat model name the operator as an adversary, unlike a security model?

level: middleimportance: must knowfreq 62%
basics
~20 s

A security model protects the system from unauthorised parties. A privacy model protects the person the data describes, including from the operator's own authorised staff and vendors. So the fix is collecting and keeping less, not stronger access control.

open as a page

How do you run a one-hour rapid threat model on a feature that ships Friday?

level: middleimportance: must knowfreq 58%
basics
~20 s

Fix the scope to the change itself, sketch its flows and trust boundaries, walk one fixed question set over every boundary crossing, and leave with ranked threats that each have an owner. You buy the obvious high-impact threats and spend completeness.

open as a page

Which criteria actually decide which threat modeling method a team should use?

level: middleimportance: must knowfreq 62%
basics
~20 s

Fit decides it, not fashion: team maturity, the system's type and risk profile, any regulatory or contractual driver, the time budget per model, and who consumes the output. A lighter method run every release beats a heavier one nobody finishes.

open as a page

Why does a CAPEC-driven sweep of an airline loyalty-points API miss arbitrage between member accounts?

level: seniorimportance: must knowfreq 55%
basics
~20 s

Points arbitrage is a chain of legitimate operations permitted by that system's own rules, and no catalog holds rules it never saw. A library sets a floor of known patterns; novel abuse comes from an asset-driven pass.

open as a page

What do the five letters in DREAD stand for, and how is a DREAD score produced?

level: juniorimportance: must knowfreq 48%
basics
~20 s

DREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.

open as a page

Your threat model readout goes to a risk committee: why is a CVSS score a poor headline, and what replaces it?

level: middleimportance: must knowfreq 62%
basics
~20 s

A CVSS score describes technical severity, not what the business loses. Lead each threat with a scenario: who does what, to whose money or data, and what it costs. Use the score only to rank items against each other.

open as a page

What is a bug bar in an SDL, and what does it decide about a security finding?

level: middleimportance: must knowfreq 60%
basics
~20 s

A bug bar is a written table, agreed before any finding exists, that defines each severity band by the concrete kinds of flaw that belong in it, the deadline to fix each band, and which bands block shipping.

open as a page

What does the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N tell you about a flaw?

level: middleimportance: must knowfreq 68%
basics
~20 s

A CVSS v3.1 base vector: network-reachable with low complexity, needing no privileges and no user interaction, escaping its own security scope to fully compromise confidentiality and integrity in the component it reaches, with no availability impact.

open as a page

In a threat model, how do you rate the likelihood that a warehouse picker's handheld can post fraudulent stock write-offs?

level: middleimportance: must knowfreq 70%
basics
~20 s

Rate likelihood from what the abuse requires, not from how clever it is: who already holds the access, how much effort and skill it takes, and whether anyone would notice. Every picker already has the scanner, so likelihood is high.

open as a page

Who should be in the room for a threat modeling session, and why each?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A threat modeling session needs whoever knows the design and whoever knows reality: the architect or tech lead, the developers building it, an ops or SRE voice, and a product owner who knows which flows carry value.

open as a page

What can an automated threat-model generator's output be trusted to deliver, and where does it stop?

level: middleimportance: must knowfreq 62%
basics
~20 s

Generated output is a floor, not a finished model. A tool reliably applies the same per-element rules everywhere and catches structural gaps, such as a data store drawn with no trust boundary. It cannot judge business impact or whether the diagram is true.

open as a page

Why keep a threat model as code in pytm or threagile instead of a drawn diagram?

level: middleimportance: must knowfreq 58%
basics
~20 s

Because the model becomes a version-controlled source file that diffs in a pull request. pytm's Python and threagile's YAML sit beside the code and regenerate the data-flow diagram and threat report on every run, so the picture never goes stale.

open as a page

How do you check that a threat model still matches the system that is actually deployed?

level: middleimportance: must knowfreq 55%
basics
~20 s

Reconcile the model against independent evidence of the running system - deployment descriptors, service and datastore inventories, routing and access config, traffic telemetry - and record every element, flow or trust boundary that reality has and the model does not.

open as a page

Which changes to a system should trigger a new or updated threat model?

level: middleimportance: must knowfreq 62%
basics
~20 s

Trigger on architectural change, not code volume: a new component or service, a new trust boundary such as a new caller or tenant, a new class of data, and any incident that disproves a design assumption.

open as a page

When threat-modeling a web app, why is the browser drawn as an external entity outside your trust boundary?

level: juniorimportance: must knowfreq 78%
basics
~20 s

The browser runs on the user's machine, so every field, header and request sequence it sends is attacker-authorable. Draw it outside your trust boundary: it is an input source, never a place where a rule is enforced.

open as a page

When threat-modeling a multi-tenant API, where does the trust boundary sit and which STRIDE categories dominate?

level: middleimportance: must knowfreq 70%
basics
~10 s

In a multi-tenant API the deciding boundary is not the network edge but every endpoint, where an authenticated caller's tenant claim meets shared tenant-owned data. Information disclosure and elevation of privilege dominate the result.

open as a page

A field-service app ships an integration API key inside its package — which threats does that create on a lost handset?

level: middleimportance: must knowfreq 74%
basics
~20 s

Anything shipped inside an app package is readable by whoever holds a copy, so treat that key as public. Two assets are exposed: a fleet-wide credential an attacker can replay against your API, and the customer data cached on a device you do not own.

open as a page

A payroll vendor holds a standing tunnel into your HR database for a nightly sync — where does the trust boundary go?

level: middleimportance: must knowfreq 62%
basics
~20 s

At your side of the tunnel. Everything arriving through it is untrusted input from a system you do not run, so the vendor stays outside your boundary even though the connection is private and encrypted.

open as a page

How do you draw a data-flow diagram for a serverless architecture with no host to put on it?

level: middleimportance: must knowfreq 64%
basics
~20 s

Use the same four DFD elements: functions and managed-service calls are processes; buckets, tables and queues are data stores; event sources are external entities. Draw trust boundaries where the calling identity changes, not where a machine or network ends.

open as a page