All roadmaps
Intermediate4 projects

Threat Modeling

Find the weak points before an attacker does — with a repeatable process.

15+

completed

~9.5h

total time

4

projects

Part 1·Beginner·2h·15+ learners

STRIDE Threat Modeling Fundamentals

Learn Microsoft's STRIDE framework and the Threat Modeling Manifesto's four-question structure, applied to a login flow in OWASP Threat Dragon.

Start
Part 2·Beginner·2h·13+ learners

Building a Data Flow Diagram

Learn standard DFD notation, draw one for a real checkout flow, mark trust boundaries, and build the same model as code with pytm.

Start
Part 3·Intermediate·2.5h·11+ learners

Attack Trees and Risk Scoring

Build a goal-oriented attack tree using Bruce Schneier's methodology, then score every leaf with the OWASP Risk Rating Methodology.

Start
Part 4·Intermediate·3h·10+ learners

Threat Modeling a Real Application

Run a full, end-to-end threat model against a real application — scope, diagram, STRIDE sweep, attack trees, and a mitigation plan.

Start