Threat Modeling
The structured practice of finding threats before the attacker does: modeling a system with data-flow diagrams and trust boundaries, enumerating threats with STRIDE or PASTA, and rating the risk. Senior security and DevSecOps interviews often run this live — you are handed an architecture and asked to threat-model it on a whiteboard.
on this pageshowhide
explore
- Fundamentals and Scoping29 questions
- Practice and Discipline13 questions
- Stakes and Adversaries10 questions
- Bounding the Exercise6 questions
- Data-Flow Diagrams and Trust Boundaries29 questions
- Notation and Decomposition12 questions
- Boundary Placement10 questions
- Surface and Blind Spots7 questions
- STRIDE Analysis35 questions
- Six Threat Categories20 questions
- Threat Elicitation Passes9 questions
- From Threat to Mitigation6 questions
- Attack Trees and Abuse Cases24 questions
- Decomposing an Attack Goal9 questions
- Path Annotation and Costing9 questions
- Misuse Case Narratives6 questions
- Methodologies Beyond STRIDE28 questions
- Risk and Attacker-Centric Methods9 questions
- Privacy and Asset-Centric Methods10 questions
- Method Selection and Scale9 questions
- Risk Rating and Prioritization30 questions
- Qualitative Judgment10 questions
- Numeric Scoring Systems11 questions
- Decision and Ownership9 questions
- SDLC Integration and Tooling34 questions
- Modeling in Delivery9 questions
- Keeping the Model Alive13 questions
- Tool Landscape12 questions
- Modeling Real Architectures23 questions
- Application and API Surfaces6 questions
- Infrastructure and Delivery10 questions
- Clients and Third Parties7 questions
questions
232 · 8 sectionsIn a threat model, how do integrity, authenticity and non-repudiation differ as goals?
basics
~20 sIntegrity means data has not been altered outside authorised change. Authenticity means the claimed origin of a message or request is genuine. Non-repudiation means the originator cannot later credibly deny it, with evidence that convinces a third party.
What are the four questions in Shostack's four-question threat modeling frame?
basics
~20 sWhat are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job? They run in that order and repeat as a loop, not a one-off checklist.
In threat modeling, what is an actor assumption and how does it bound the threats you keep?
basics
~20 sAn actor assumption is a written statement of the adversary you defend against: their capability, resources and access. It bounds the model, because a threat stays in scope only if that assumed actor could reach and carry it out.
For a stadium ticketing on-sale, which assets must the threat model protect?
basics
~20 sThe assets are the ability to complete a purchase during the on-sale window, fair allocation of the inventory, the revenue, and fan trust. Seat-map confidentiality carries almost no loss — here availability and functionality are the assets, not stored data.
In a threat model, what does a recorded assumption need to contain to be useful?
basics
~20 sA usable assumption states the claim in a form that could be proved false, names the team that owns it, says which threats come back if it is wrong, and gives an event or date that forces a recheck.
What does a level-0 context diagram show in a data-flow-diagram threat model?
basics
~20 sA level-0 context diagram draws the whole system as one process, every external entity that talks to it, and the flows between them. It fixes scope and shows what crosses the outer trust boundary, with no internal structure.
On a threat-modeling data-flow diagram, what do process, data store, external entity and flow each represent?
basics
~20 sA process is running code that transforms data, a data store is passive data at rest, an external entity is a person or system you do not control, and a flow is data in motion between them.
When you enumerate entry points on a data-flow diagram, what counts as one?
basics
~20 sAn entry point is anywhere data or a request crosses into the system from outside its trust boundary. Not just HTTP endpoints: queue consumers, file drops, inbound email, webhooks, scheduled jobs that fetch remote data, and admin or support consoles all count.
On a data-flow diagram, what does a trust boundary mark, and what decides where it is drawn?
basics
~20 sA trust boundary marks a data flow where the two sides do not trust each other equally. Draw it wherever the principal, privilege, tenant, code owner or execution context changes - not wherever the network or a firewall changes.
What does a data-flow diagram deliberately omit, and which threats hide in those omissions?
basics
~20 sA data-flow diagram shows what data moves where, not when or in what order. It omits control flow, sequencing, retries and error paths, so replay, race, double-processing and failure-path leak threats stay invisible on it.
In STRIDE, which property does Denial of Service violate, and how does it appear on a process, a store and a flow?
basics
~20 sDenial of Service violates availability - legitimate users stop being served. On a process it exhausts CPU, memory or threads; on a store it fills or locks storage; on a flow it saturates or cuts the channel.
In STRIDE, what does the Elevation of Privilege category cover and which property does it violate?
basics
~20 sElevation of Privilege is STRIDE's category for an actor gaining rights it was never granted - doing something it is not permitted to do. It violates authorization, and the answering controls are authorization decisions plus least privilege.
A production API returns unhandled stack traces and still routes /debug/env — why is this an information-disclosure threat?
basics
~20 sBoth hand an unauthenticated stranger internal detail for free: stack traces expose paths, versions and sometimes a connection string; a debug route dumps environment variables including keys. Return generic errors, keep the route out of production builds, and rotate anything exposed.
What is the Repudiation threat in STRIDE, and which security property does it violate?
basics
~20 sRepudiation is an actor plausibly denying an action they took, or falsely claiming one they did not, because the system kept no trustworthy evidence. It violates non-repudiation, and the answering control family is identity plus auditing.
In STRIDE, which security property does Tampering violate, and which diagram elements can carry it?
basics
~20 sTampering violates integrity: someone modifies data or code they are not authorized to change. On a data-flow diagram it applies to processes, data flows and data stores, but not to external entities, which get spoofed instead.
In an attack tree, how do node costs propagate through AND versus OR nodes to the root?
basics
~20 sIn an attack tree, an AND node costs the sum of its children, because the attacker must complete all of them. An OR node costs the minimum, because the attacker picks one. The root holds the cheapest complete attack.
On an attack tree, what attributes besides cost annotate a node, and why keep them separate?
basics
~20 sAnnotate each leaf with independent attributes: money, skill level, elapsed time, required access, equipment and detectability. Collapsing them into one number hides that a step can be cheap in cash yet demand rare skill or insider access nobody can buy.
How do you turn a user story into an evil user story a developer can act on?
basics
~20 sKeep the three story clauses and make each hostile: the role becomes a named attacker persona, the capability becomes what they want the system to allow, and the benefit becomes their payoff. The asset stays in the final clause.
In an attack tree, what separates a usable concrete-action leaf from a category leaf?
basics
~20 sA concrete-action leaf names one specific thing an attacker does on this system, specific enough to cost and to defend. A category leaf such as 'obtain a credential' only restates the sub-goal above it, hides the real work, and maps to no control.
How do you turn an abuse case into an acceptance criterion and then an automated negative test?
basics
~10 sRestate the attacker's goal as a must-not statement with an observable outcome, then write a test that runs from the adversary's position and asserts the refusal, the unchanged state, and the recorded evidence.
What are the seven LINDDUN threat types, and which privacy property does each one break?
basics
~10 sLINDDUN covers Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness and Non-compliance. Each names the failure of a privacy property: unlinkability, anonymity, plausible deniability, undetectability, confidentiality, user awareness, and policy compliance.
Why does a privacy threat model name the operator as an adversary, unlike a security model?
basics
~20 sA security model protects the system from unauthorised parties. A privacy model protects the person the data describes, including from the operator's own authorised staff and vendors. So the fix is collecting and keeping less, not stronger access control.
How do you run a one-hour rapid threat model on a feature that ships Friday?
basics
~20 sFix the scope to the change itself, sketch its flows and trust boundaries, walk one fixed question set over every boundary crossing, and leave with ranked threats that each have an owner. You buy the obvious high-impact threats and spend completeness.
Which criteria actually decide which threat modeling method a team should use?
basics
~20 sFit decides it, not fashion: team maturity, the system's type and risk profile, any regulatory or contractual driver, the time budget per model, and who consumes the output. A lighter method run every release beats a heavier one nobody finishes.
Why does a CAPEC-driven sweep of an airline loyalty-points API miss arbitrage between member accounts?
basics
~20 sPoints arbitrage is a chain of legitimate operations permitted by that system's own rules, and no catalog holds rules it never saw. A library sets a floor of known patterns; novel abuse comes from an asset-driven pass.
What do the five letters in DREAD stand for, and how is a DREAD score produced?
basics
~20 sDREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.
Your threat model readout goes to a risk committee: why is a CVSS score a poor headline, and what replaces it?
basics
~20 sA CVSS score describes technical severity, not what the business loses. Lead each threat with a scenario: who does what, to whose money or data, and what it costs. Use the score only to rank items against each other.
What is a bug bar in an SDL, and what does it decide about a security finding?
basics
~20 sA bug bar is a written table, agreed before any finding exists, that defines each severity band by the concrete kinds of flaw that belong in it, the deadline to fix each band, and which bands block shipping.
What does the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N tell you about a flaw?
basics
~20 sA CVSS v3.1 base vector: network-reachable with low complexity, needing no privileges and no user interaction, escaping its own security scope to fully compromise confidentiality and integrity in the component it reaches, with no availability impact.
In a threat model, how do you rate the likelihood that a warehouse picker's handheld can post fraudulent stock write-offs?
basics
~20 sRate likelihood from what the abuse requires, not from how clever it is: who already holds the access, how much effort and skill it takes, and whether anyone would notice. Every picker already has the scanner, so likelihood is high.
Who should be in the room for a threat modeling session, and why each?
basics
~20 sA threat modeling session needs whoever knows the design and whoever knows reality: the architect or tech lead, the developers building it, an ops or SRE voice, and a product owner who knows which flows carry value.
What can an automated threat-model generator's output be trusted to deliver, and where does it stop?
basics
~20 sGenerated output is a floor, not a finished model. A tool reliably applies the same per-element rules everywhere and catches structural gaps, such as a data store drawn with no trust boundary. It cannot judge business impact or whether the diagram is true.
Why keep a threat model as code in pytm or threagile instead of a drawn diagram?
basics
~20 sBecause the model becomes a version-controlled source file that diffs in a pull request. pytm's Python and threagile's YAML sit beside the code and regenerate the data-flow diagram and threat report on every run, so the picture never goes stale.
How do you check that a threat model still matches the system that is actually deployed?
basics
~20 sReconcile the model against independent evidence of the running system - deployment descriptors, service and datastore inventories, routing and access config, traffic telemetry - and record every element, flow or trust boundary that reality has and the model does not.
Which changes to a system should trigger a new or updated threat model?
basics
~20 sTrigger on architectural change, not code volume: a new component or service, a new trust boundary such as a new caller or tenant, a new class of data, and any incident that disproves a design assumption.
When threat-modeling a web app, why is the browser drawn as an external entity outside your trust boundary?
basics
~20 sThe browser runs on the user's machine, so every field, header and request sequence it sends is attacker-authorable. Draw it outside your trust boundary: it is an input source, never a place where a rule is enforced.
When threat-modeling a multi-tenant API, where does the trust boundary sit and which STRIDE categories dominate?
basics
~10 sIn a multi-tenant API the deciding boundary is not the network edge but every endpoint, where an authenticated caller's tenant claim meets shared tenant-owned data. Information disclosure and elevation of privilege dominate the result.
A field-service app ships an integration API key inside its package — which threats does that create on a lost handset?
basics
~20 sAnything shipped inside an app package is readable by whoever holds a copy, so treat that key as public. Two assets are exposed: a fleet-wide credential an attacker can replay against your API, and the customer data cached on a device you do not own.
A payroll vendor holds a standing tunnel into your HR database for a nightly sync — where does the trust boundary go?
basics
~20 sAt your side of the tunnel. Everything arriving through it is untrusted input from a system you do not run, so the vendor stays outside your boundary even though the connection is private and encrypted.
How do you draw a data-flow diagram for a serverless architecture with no host to put on it?
basics
~20 sUse the same four DFD elements: functions and managed-service calls are processes; buckets, tables and queues are data stores; event sources are external entities. Draw trust boundaries where the calling identity changes, not where a machine or network ends.