Threat Modelling

Guidance for threat modelling using STRIDE and the Microsoft Security Development Lifecycle (SDL). Covers data-flow diagrams, trust boundaries, the STRIDE categories, mitigation mapping, and tooling (Microsoft Threat Modeling Tool). WHEN: threat modeling, STRIDE, data flow diagram, trust boundary, identify threats, SDL threat modeling, security design review, threat model a system, mitigation mapping, Microsoft Threat Modeling Tool, secure design review, design-time security. DO NOT USE for org-wide security architecture (use security-architecture) or for runtime detection (use sentinel / defender-xdr).

vinayaklatthe 8ad1bb4 6.8 KB Updated

File contents

vinayaklatthe/microsoft-security-skills/tree/main/skills/threat-modelling commit 8ad1bb44f4

Frequently asked questions

npx skillmds@latest add vinayaklatthe/threat-modelling