stride-threat-modeling

v2026.09.25

Run a STRIDE-based threat modeling workshop — diagram the system, enumerate threats per element, rank them, and drive mitigations into the backlog. Use during design reviews and new feature planning.

GitHub
Install command
npx skhub add securityskills/stride-threat-modeling
Markdown
SKILL.md

STRIDE Threat Modeling

Threat model a system in a structured workshop format.

1. Model the System

Draw the diagram: processes, data stores, data flows, external actors, and trust boundaries (dashed lines where privilege/context changes).

  • Every element numbered; technologies noted on processes/stores
  • Include the boring parts: auth flows, async jobs, admin tooling, backups

2. Enumerate with STRIDE

For each element, apply the applicable categories:

CategoryApplies ToQuestion
SpoofingProcesses, actorsCan someone pretend to be this? (auth)
TamperingFlows, storesCan data be modified in transit/at rest? (integrity)
RepudiationProcessesCan actions be denied? (logging/audit)
Information disclosureFlows, storesCan data leak to unauthorized parties? (confidentiality)
Denial of serviceProcesses, flowsCan this be exhausted or crashed? (availability)
Elevation of privilegeProcessesCan rights be gained? (authz)

Work systematically: element × category grid so nothing is skipped.

3. Rank

Score each threat by impact (worst realistic outcome) × likelihood (attack complexity, exposure). Prioritize: unauthenticated remote > authenticated remote > local > physical.

4. Mitigate

For each accepted threat, pick a strategy: reduce (control), transfer, accept (documented, with owner), or avoid (design change). Map mitigations to concrete backlog tickets with acceptance criteria.

5. Validate

  • Review the model when the architecture changes (trigger: new external dependency, new trust boundary, new data class)
  • Retro: incidents found in prod vs threats previously modeled — feed misses back into the method

Output

System diagram with trust boundaries, element × STRIDE threat grid, ranked risk register, and mitigations as tracked tickets.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.25

Published

Sep 25, 2026

Category

Uncategorized

License

Not specified

Source path

threat-modeling/stride-threat-modeling

Default branch

main

Latest commit

b2b6b52

Tree SHA

8db485b