performing-threat-modeling-with-owasp-threat-dragon

Featured

Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies, and generate threat model reports for secure design review.

AI & Automation 16,326 stars 1981 forks Updated 2 weeks ago Apache-2.0

Install

View on GitHub

Quality Score: 97/100

Stars 20%
100
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing Threat Modeling with OWASP Threat Dragon ## Overview OWASP Threat Dragon is an open-source threat modeling tool that enables security teams and developers to create threat model diagrams, identify threats using established methodologies (STRIDE, LINDDUN, CIA, DIE, PLOT4ai), and generate comprehensive reports. Threat Dragon runs as both a web application and desktop application (Windows, macOS, Linux), supporting distributed teams working collaboratively on threat models. Version 2.x provides drag-and-drop diagram creation, an auto-generation rule engine for threats and mitigations, and PDF report output for documentation and GRC compliance. ## When to Use - When conducting security assessments that involve performing threat modeling with owasp threat dragon - When following incident response procedures for related security events - When performing scheduled security testing or auditing activities - When validating security controls through hands-on testing ## Prerequisites - OWASP Threat Dragon desktop application or web instance - Understanding of data flow diagram (DFD) notation - Familiarity with STRIDE or LINDDUN threat classification - Application architecture documentation and network diagrams - Stakeholder access for design review sessions ## Threat Modeling Methodologies ### STRIDE | Category | Threat Type | Description | Example | |----------|-------------|-------------|---------| | S | Spoofing | Impersonating a user or system | Stolen session...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
2 weeks ago
Language
Python
License
Apache-2.0

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category