Threat Model

Structured STRIDE threat modeling at design time, before code exists: name assets, actors, and trust boundaries, walk Spoofing/Tampering/Repudiation/Information disclosure/Denial of service/Elevation of privilege at each boundary, rate and prioritize, and turn mitigations into build tasks. Use when designing a system, feature, or API or asking what could go wrong. Defensive only.

AL-JANEF Updated

File contents

AL-JANEF/janef-forge/tree/main/skills/security/threat-model commit c6cb1381a1

Frequently asked questions

npx skillmds@latest add al-janef/threat-model-2