OWASP Threat Modeling Process

Threat Modeling for Everyone

Identify security risks before attackers do. Build a structured threat model for your organisation using the STRIDE framework — no security expertise required.

No sign-up required Data never leaves your browser Multiple saved projects STRIDE & OWASP aligned
Payment API — Threat Model
14
Threats
3
Critical
5
High
8
Mitigated

Threat Register

S JWT forgery via weak signing secret CRIT
E Missing authorisation on admin endpoint (BFLA) CRIT
I Excessive data exposure in API responses HIGH
D Rate limiting bypass — resource exhaustion HIGH
R No per-request audit log MED
Overall
71%

How It Works

A guided, step-by-step process aligned to the OWASP Threat Modeling Process — from blank canvas to complete threat model in under an hour.

Step 1 / 8·OWASP Step 1 — Scope

Define Your System

Start by documenting your application — its name, version, owner, and a high-level description of what it does and what data it handles. This metadata anchors the entire OWASP threat model and creates an auditable record.

Try it in the tool
Application Information
Application Name *
Customer Portal
Document Owner *
Jane Smith, Security
Version
2.1.0
Description
Customer-facing web portal handling account management and order history…

Continuous security workflow

From blank canvas to complete threat model

A repeatable, audit-ready process aligned to the OWASP Threat Modeling standard — not a one-time exercise, but a control you run on every system and every release.

🏗️ 01

Design

Document scope, trust levels, entry and exit points, assets, and dependencies before writing a line of code.

OWASP Step 1
🗺️ 02

Map

Build a Data Flow Diagram showing every component, trust boundary, and cross-boundary data flow.

OWASP Step 1
🔍 03

Identify

Apply STRIDE to every element. Pre-built templates surface the most common attack patterns for your stack.

OWASP Step 2
📊 04

Assess

Score Likelihood × Impact to rank threats. The 5×5 risk matrix shows exactly where to focus first.

OWASP Step 2
🛡️ 05

Control

Document preventive, detective, and corrective controls. Track ownership, status, and residual risk.

OWASP Step 3
✓ OWASP Threat Modeling Process ✓ STRIDE Framework (Microsoft) ✓ NIST SP 800-154 Aligned ✓ Runs entirely in your browser

Ready to Secure Your System?

No sign-up required. Your data never leaves your browser. Start your first threat model in seconds.

Start Threat Modelling