All skills
hardw00t avatar

/threat-modeling

@f9bb3b2

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. Use when assessing security architecture, creating data flow diagrams (Mermaid), enumerating threats from OpenAPI specs or architecture docs, building attack trees, mapping threats to NIST/CIS/OWASP ASVS controls, or producing a threat model report. Triggers on requests to threat model, analyze attack surface, create a DFD, apply STRIDE, or design security mitigations.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/threat-modeling

This session only. Nothing lands on disk.

referencesframework_comparison.md

≈965 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Framework Comparison — Which Methodology to Pick

Decision matrix for selecting a threat modeling methodology.

Quick-Pick Decision Tree

Is privacy / personal data the primary concern?
├── Yes → LINDDUN (methodology/linddun.md)
└── No
    │
    Is this an enterprise-wide / cross-org risk assessment?
    ├── Yes → OCTAVE Allegro (methodology/octave.md)
    └── No
        │
        Is compliance / business risk alignment required (regulated industry)?
        ├── Yes → PASTA (methodology/pasta.md)
        └── No
            │
            Do you need a single-threat deep dive?
            ├── Yes → Attack Trees (methodology/attack_trees.md)
            └── No → STRIDE (methodology/stride.md)   [DEFAULT]

Default: STRIDE. Most agile teams, most applications, most of the time.

Full Comparison

Aspect STRIDE PASTA Attack Trees DREAD LINDDUN OCTAVE
Primary focus Threats per element Business-aligned risk Attack paths per goal Risk scoring Privacy threats Org-wide asset risk
Granularity Component System + Business Goal-specific Per-threat Data-subject data Portfolio
Complexity Medium High Low-Medium Low Medium High
Cycle time Hours-Days Weeks Hours Minutes Days Weeks-Months
Owner Dev + Security Security + Business Security Anyone Privacy + Security Risk mgmt + IT
Input needed DFD Business context + architecture Single threat Identified threat DFD + data flows Asset inventory
Output Threat list Risk register Prioritized attack paths Ranked threats Privacy threat list Risk register + mitigations
Best for Apps, APIs, microservices Regulated enterprise apps Specific high-impact scenarios Quick triage GDPR/CCPA systems Enterprise programs
Weakness Not risk-quantified Heavy overhead Doesn't enumerate goals Subjective Narrow scope Not agile
Tooling MS TMT, Threat Dragon, Threagile CTI platforms, manual Graphviz, ADTool Spreadsheet LINDDUN GO (TU Leuven) CERT workbooks

Combine, Don't Choose Exclusively

Real programs combine methodologies:

  • STRIDE + Attack Trees: STRIDE enumerates threats; build attack trees for the top N.
  • STRIDE + LINDDUN: STRIDE covers security; LINDDUN adds privacy layer for PII flows.
  • STRIDE + DREAD: STRIDE enumerates; DREAD scores for prioritization (warn on DREAD critiques).
  • PASTA wrapping STRIDE: PASTA's Stage 4 threat analysis uses STRIDE internally.
  • OCTAVE Allegro + STRIDE: OCTAVE picks assets; STRIDE threat-models systems holding them.

Anti-Patterns

Situation Don't do this Do this instead
Microservice PR review Full PASTA every PR Lightweight STRIDE-per-interaction (workflows/stride_from_openapi.md)
New privacy feature Generic STRIDE only STRIDE + LINDDUN layer
Need to prioritize 100 threats Eyeball it CVSS or OWASP Risk Rating (not DREAD)
One CEO-level high-consequence threat Skim STRIDE Deep attack tree
Enterprise new initiative Jump to STRIDE OCTAVE Allegro first, then STRIDE per system

Selection Heuristics

  • Team is 1-5 devs, single service → STRIDE, done in a meeting.
  • Regulated (PCI, HIPAA, SOX, GDPR) → PASTA (with LINDDUN for GDPR).
  • Multi-tenant SaaS → STRIDE + extra focus on tenant-isolation trust boundary.
  • AI/ML inference or training system → STRIDE + MITRE ATLAS overlay.
  • High-assurance (finance, critical infra) → PASTA + attack trees for top threats.
  • Privacy-by-design mandate → LINDDUN.
  • Enterprise risk dashboard → OCTAVE Allegro outputs roll into ERM.

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe. It consists entirely of markdown documentation, templates, and workflows for threat modeling methodologies (such as STRIDE, PASTA, and LINDDUN) to guide AI agent security reviews. It contains no executable code or scripts, and no malicious patterns were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/threat-modeling