// interactive project · threat modelling
A practical guide to STRIDE threat modelling
Threat modelling sounds abstract until you do it on something real. STRIDE gives you six lenses to hold up to a system, and most weaknesses reveal themselves the moment you ask the six questions in the right place. Learn the lenses below, then open any of the eight worked examples, click an element in its diagram, and see the threats and the fixes that element attracts.
Saleem YousafInteractive8 worked examples · 64 threats
// the six lenses
How to read a threat model. Draw the system as elements and the flows between them, then mark the trust boundaries, the dashed lines where data crosses from less trusted to more trusted. At every element and every boundary, ask the six STRIDE questions. A threat is a plausible answer; a control is how you close it. The examples below are that method applied to six real designs.
// explore a worked example
click an element to focus its threats, or use the STRIDE filters
Threat modelling is most valuable before a system is built, when a boundary or a role is still a line on a diagram rather than a production incident. If you want this done properly on your architecture, that is the kind of work I do through
Cyber Spartans.