All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

methodologyoctave.md

≈869 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCTAVE / OCTAVE Allegro

OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is an organization-wide, asset-driven risk assessment methodology from CERT/SEI. Use when threat modeling at the enterprise portfolio level, not a single application.

Two main variants:

  • OCTAVE Allegro — the streamlined form, most common today. Focuses on information assets and their containers.
  • OCTAVE-S — for small organizations (< 100 people).
  • Original OCTAVE — heavyweight, largely superseded by Allegro.

OCTAVE Allegro — Eight Steps

Step 1: Establish Risk Measurement Criteria

Define the impact areas the organization cares about:

  • Reputation & customer confidence
  • Financial
  • Productivity
  • Safety & health
  • Fines & legal penalties
  • User-defined (e.g. research IP, mission)

For each, define low/medium/high impact thresholds in plain language.

Step 2: Develop an Information Asset Profile

Pick critical information assets (not systems — the information). For each:

  • Name, description, owner
  • Confidentiality, integrity, availability requirements
  • Rationale for choosing it

Step 3: Identify Information Asset Containers

A container is anywhere the asset lives or moves:

  • Technical: servers, databases, SaaS, endpoints, networks
  • Physical: paper files, archives, facilities
  • People: staff roles with access

Step 4: Identify Areas of Concern

Brainstorm real-world scenarios that worry stakeholders. Do not yet evaluate — just collect.

Step 5: Identify Threat Scenarios

Formalize areas of concern into threat scenarios:

  • Actor (internal / external, accidental / deliberate)
  • Means (technical / physical / social)
  • Motive (financial / political / personal)
  • Outcome (disclosure / modification / destruction / interruption)

Optionally use a threat tree (AND/OR; see methodology/attack_trees.md) for exhaustiveness.

Step 6: Identify Risks

For each threat scenario, articulate the consequence in business terms: what happens to the asset? To the organization?

Step 7: Analyze Risks

Score each risk against the Step-1 criteria. Produce a relative risk score as a weighted sum across impact areas.

Step 8: Select Mitigation Approach

For each risk, one of:

  • Mitigate: apply controls to reduce probability/impact
  • Accept: document and monitor
  • Defer: reassess later when more info available
  • Transfer: insurance, contractual shift

For mitigations, pick controls across all containers (technical + physical + people) — OCTAVE's strength is cross-container thinking.

When to Use OCTAVE

  • Enterprise-wide risk programs
  • Regulated organizations needing defensible risk-rating process
  • Cross-functional risk assessments spanning IT, physical security, HR
  • Mergers & acquisitions due diligence

When NOT to Use OCTAVE

  • Single application or microservice — too heavy
  • Rapid agile iterations — cycle time is weeks, not hours
  • Technical-only analysis — STRIDE/PASTA are a better fit

Relation to Other Methodologies

  • OCTAVE is orthogonal to STRIDE: use STRIDE to enumerate technical threats within an OCTAVE asset container.
  • PASTA shares the business-alignment spirit but is more technical.
  • OCTAVE's container model complements data-classification programs and DLP.

References

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling