Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Threat Model Builder

Describe the system, get STRIDE threats per element, then rate, assign and track them.

Security No upload Works offline Free, no sign-up
Saved in this browser

Kept in this browser’s storage on this device only — avoid it on a shared computer.

Nothing saved yet. Use Save in this browser.

    Paste a Threat Dragon model

    Model details

    Trust boundaries

    Where the level of trust changes: the Internet, your network, a third party, an administration zone.

      Components

      External entities are people and systems outside your control; processes are code that handles data; data stores keep it (databases, files, queues, logs).

        Data flows

        Add at least two components to connect them.

        How data moves between the components: what it is, the protocol, and whether it is encrypted and authenticated.

          Data flow diagram

          The diagram draws itself as you add components and data flows.

          • External entity
          • Process
          • Data store
          • Trust boundary
          • Unencrypted across a boundary

            Checks

              Threats

              Threats appear here as you add components and data flows: each element gets the STRIDE categories that apply to it.

                Add your own threat

                Report and files

                Add components first: the report describes them and their threats.

                The suggested threats are a checklist, not an assessment. Review the model with the people who design, build and run the system — they know the threats no library can.

                Next steps

                About the Threat Model Builder

                A threat model asks what can go wrong with a system before an attacker or an outage shows you. This builder follows the approach of the OWASP Threat Modeling Cheat Sheet: describe the system as a data flow diagram — the people and systems outside it, its processes, its data stores, the data flows between them and the trust boundaries where the level of trust changes — then check each element for the STRIDE threats that apply to it: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

                The diagram is drawn for you as you add elements, and each element gets suggested threats with the usual mitigations and links to the OWASP Cheat Sheets that explain them. Rate each threat with the OWASP Risk Rating Methodology, give it an owner and a status, and download the model as a PDF or Markdown report, a CSV threat register or an OWASP Threat Dragon file. Everything stays in your browser.

                How to use it

                1. Add the trust boundaries if you know them (the Internet, your network, a third party), then the components: external entities (users, partner systems), processes (applications, services, jobs) and data stores (databases, files, queues, logs).
                2. Add the data flows between them, with the protocol and whether each one is encrypted and authenticated. The diagram updates as you type, and the checks point out flows that break the usual diagram rules.
                3. Work through the threats: each element gets the STRIDE categories that apply to it. Adjust the wording, rate the likelihood and impact, choose a status and an owner, and mark the ones that do not apply.
                4. Add the threats only your team can know, then download the report (PDF or Markdown), the threat register (CSV) or a Threat Dragon file. Save the model in this browser or as a file to carry on later.

                Examples

                The example online shop
                Input
                Customers and staff on the Internet; a web shop, an admin console, an orders database and application logs in the shop’s cloud account; a payment gateway at a third party.
                Result
                A diagram with three trust boundaries and seven flows, and 58 suggested threats — among them “Requests on “Payment result callback” are not authenticated”, because the callback crosses a boundary without authentication.

                Open it with Example model to see every part of the tool, then change it into your own system.

                A flow that carries personal data unencrypted
                Input
                A data flow from a mobile app (outside every boundary) to an API inside the company network, carrying personal data, not marked as encrypted.
                Result
                Tampering, information disclosure and denial of service threats for the flow, plus “Confidential data crosses a boundary unencrypted”, a red line on the diagram and a warning in the checks.

                Common uses

                • Running a threat modeling session for a new feature, with the diagram and the threat list on screen.
                • Writing the threat model a security review, an audit or a customer questionnaire asks for.
                • Turning a whiteboard sketch into a threat register with owners and statuses.
                • Moving a model between this tool and OWASP Threat Dragon.

                STRIDE per element

                Not every kind of threat applies to every part of a system. The suggestions follow the usual STRIDE-per-element table, the one OWASP Threat Dragon uses as well:

                • External entities (people, partner systems): spoofing and repudiation.
                • Processes: all six — spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
                • Data stores: tampering, repudiation, information disclosure and denial of service.
                • Data flows: tampering, information disclosure and denial of service.

                What you tick about an element adds more: a web application or API gets injection, cross-site scripting, request forgery and session threats; a process with high privileges, a store with credentials or personal data, a log, a store not encrypted at rest, and a flow that crosses a trust boundary without authentication or unencrypted with confidential data each get their own threat.

                Threats that keep up with the model

                While you have not changed a suggested threat, it follows its element: rename “API” to “Orders API” and its threats are renamed too, tick “web application” and the web threats appear. As soon as you rate a threat, give it an owner, a status or notes, or edit its wording, it is yours and stays even if the element changes so that it no longer applies — it is then marked so you can check it. Threats of an element you delete are deleted with it, and an element marked out of scope gets no suggestions.

                The Suggestions setting chooses how much the library adds: every applicable category, only the categories an element has no threat of yet (useful after importing a model that already has threats), or none.

                Rating the risk

                Each threat can be rated with the OWASP Risk Rating Methodology. For a quick rating choose the likelihood and the impact (Low, Medium or High); the methodology’s matrix turns them into Note, Low, Medium, High or Critical. For a defensible rating open the sixteen factors (threat agent, vulnerability, technical and business impact) — the same engine as the OWASP Risk Rating Calculator — and the vector is kept with the threat.

                OWASP Threat Dragon files

                The Threat Dragon download is a version 2 model (2.3.0 format) of OWASP Threat Dragon, the open-source threat modeling tool, with one STRIDE diagram: actors, processes, stores, flows, trust boundary boxes and every threat with its type, status, severity, description and mitigation, laid out like the diagram here. Threat Dragon has no owner, notes or likelihood and impact fields, so they are written as the last lines of each threat description; importing the file here reads them back.

                You can also import a model made in Threat Dragon 2. Elements, flows, boundary boxes and threats are kept and the diagram is drawn again; positions, text blocks and boundary lines are not kept, because only a box says which components are inside it.

                A starting point, not a verdict

                The library suggests the common threats for each kind of element. It cannot know your business logic, your users, your attackers or how the system is really run, so a model built here is a draft for the people who design, build and operate the system to review together. Add the threats only they can see, and update the model when the system changes.

                Limitations

                • The suggestions cover common STRIDE threats per kind of element, not threats specific to your business logic, industry or users.
                • The diagram is laid out automatically; elements cannot be dragged. Models with dozens of components give wide diagrams.
                • Threat Dragon diagrams are redrawn when imported: positions, text blocks and boundary lines are not kept, and Threat Dragon 1 files must be opened and saved in Threat Dragon 2 first.
                • Models saved in this browser disappear if the browser’s site data is cleared. Download a model file for anything you need to keep.

                Privacy

                Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

                Frequently asked questions

                What is STRIDE?

                A way to remember six kinds of threat, each the opposite of a security property, as Microsoft’s Threat Modeling Tool documentation describes them: Spoofing (authentication), Tampering (integrity), Repudiation (non-repudiation), Information disclosure (confidentiality), Denial of service (availability) and Elevation of privilege (authorisation). Checking each element of a data flow diagram for the categories that apply to it is a simple way not to miss whole classes of problems.

                What is a trust boundary?

                A line where the level of trust changes: between the Internet and your network, between your application and a third party’s service, between ordinary users and an administration zone. Data crossing a boundary is where authentication, encryption and input checks matter most, so flows that cross one are highlighted.

                Why does it warn about an external entity connected to a data store?

                In a data flow diagram, data reaches a store through a process — the code that reads or writes it. A direct line usually hides that process (an upload service, a database client, a file share), and the process is where many threats live. Add it, or keep the shortcut if you mean it.

                Can I open the file in OWASP Threat Dragon?

                Yes: the Threat Dragon download is a version 2 model that Threat Dragon 2 opens, with the elements, flows, boundary boxes and threats. Files saved by Threat Dragon 2 can be imported here as well.

                Where is my model stored?

                Only in your browser. Save in this browser keeps it in this browser’s storage on this device; Save model file downloads a file you can keep, share or open again later. Nothing is uploaded.

                Does this replace a threat modeling session?

                No. It gives a session a structure and a checklist, and it writes the results up, but the threats that matter most are often the ones only the people who know the system can see. Use it with them.

                Quick answers and tool search

                Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.