awesome-threat-modelling
Threat Modeling Guide
A curated list of threat modeling resources to learn and apply threat modeling skills in software development
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
1k stars
67 watching
258 forks
Language: Dockerfile
last commit: 4 months ago
Linked from 1 awesome list
appsecawesomeawesome-listdevsecopsdevsecops-universitypractical-devsecopssecurity-reviewthreat-modeling
Awesome Threat Modeling / Fundamentals | |||
The Threat Modeling Manifesto | |||
Awesome Threat Modeling / Tools / Paid tools | |||
Irius risk | Iriusrisk is a threat modeling tool with an adaptive questionnaire driven by an expert system which guides the user through straight forward questions about the technical architecture, the planned features and security context of the application | ||
SD elements | Automate Threat Modeling with SD Elements | ||
Foreseeti | SecuriCAD Vanguard is an attack simulation and automated threat modeling SaaS service that enables you to automatically simulate attacks on a virtual model of your AWS environment | ||
Tutamen Threat Model system | This tool allows threat model metadata to be added to any software diagram, turning that diagram into a threat model. It's simple to use, requires no lock-in license, and is driven by the Common Weakness Enumeration, STRIDE and OWASP Top 10 | ||
YAKINDU Security Analyst | YAKINDU Security Analyst is a model-based software tool for threat analysis and risk assessment of technical systems. You can identify your protection needs, analyze possible threats and calculate the resulting risks. The underlying assessment model and calculation logic are highly customizable and can be integrated into existing toolchains |