All roadmaps
Intermediate4 projects
Threat Modeling
Find the weak points before an attacker does — with a repeatable process.
15+
completed
~9.5h
total time
4
projects
Part 1·Beginner·2h·15+ learners
STRIDE Threat Modeling Fundamentals
Learn Microsoft's STRIDE framework and the Threat Modeling Manifesto's four-question structure, applied to a login flow in OWASP Threat Dragon.
Part 2·Beginner·2h·13+ learners
Building a Data Flow Diagram
Learn standard DFD notation, draw one for a real checkout flow, mark trust boundaries, and build the same model as code with pytm.
Part 3·Intermediate·2.5h·11+ learners
Attack Trees and Risk Scoring
Build a goal-oriented attack tree using Bruce Schneier's methodology, then score every leaf with the OWASP Risk Rating Methodology.
Part 4·Intermediate·3h·10+ learners
Threat Modeling a Real Application
Run a full, end-to-end threat model against a real application — scope, diagram, STRIDE sweep, attack trees, and a mitigation plan.
