Threat Modeling Tool

Draw the data flows and trust boundaries, pin each threat to the element it targets, and keep its score and mitigation one click behind it.

Free forever on the Personal plan

Threat models: an example

STRIDE threat model of an online ordering platform as a data-flow diagram: customers and staff, an API gateway, identity and order services, data stores and third parties inside red trust boundaries, with six threats pinned to the elements they target.
  • Threats where they apply

    Each threat sits on the element it targets, lettered by STRIDE category.

  • Trust boundaries drawn

    Red dashed boundaries show where data crosses from one level of trust to another.

  • A register behind it

    Scores, owners and mitigations in a register that links back to the diagram.

The basics

What is a threat model?

A threat model is a structured look at what could go wrong with a system's security: what the system is made of, where data flows and crosses trust boundaries, which threats apply to each part, how serious each is and what mitigates it. STRIDE is the most widely used method: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

Threat modelling usually starts from a data-flow diagram drawn in a workshop, and the findings end up in a spreadsheet that drifts away from the design. Keeping the threats on the diagram shows which parts were analysed, and which change needs a fresh look.

In Blueprintr each threat is a marker on the element it targets, with its category, score and mitigation in a stratum, and a register that links back to every marker.

Why Blueprintr

Threat models that stay with the design

The data-flow diagram on the canvas, every threat one click behind it.

  • Data-flow diagram shapes

    Draw processes as ellipses, entities and stores as boxes, trust boundaries as red dashed containers and numbered flows between them.

    Vellum
  • A threat behind each marker

    Give every threat a stratum with its category, score, mitigation, owner and status, and a register table that links to each one.

    Stratum
  • A STRIDE template to start from

    The Compendium's STRIDE template sets out a data-flow diagram, analysis per element, a scored register and derived security requirements.

  • What is exposed in the cloud

    On the Team plan, Continuum Cloud's Public exposure and Security groups views show what in AWS or Azure can be reached, to check against the model.

    Continuum
  • Reviewed with the security team

    Share the model privately with reviewers, who raise questions in the Discussion tab; on team-owned blueprints, changes can need approval.

  • Revisited at every change

    Each publish keeps a snapshot, so you can see how the model looked at the last review. On the Team plan you can compare the text of two versions.

How to

How to build a threat model in Blueprintr

  1. Create a blueprint

    Sign up free and create a private blueprint, or start from the STRIDE template in the Compendium.

  2. Draw the data flows

    Add entities, processes and data stores, and number every flow between them.

  3. Mark the trust boundaries

    Draw a red dashed container around each zone of trust, so every crossing is visible.

  4. Pin the threats

    Place a lettered marker on each element at risk and add a stratum with its score and mitigation.

  5. Review and revisit

    Review the model with the security team, and revisit it whenever the design changes.

Start from a template

STRIDE threat model (data-flow diagram)

A web application's data-flow diagram with trust boundaries and numbered flows, STRIDE analysis per element in strata, a scored threat register and security requirements.

Open the Compendium

FAQ

Questions about threat models

Is this threat modeling tool free?

Yes. The Vellum editor, strata and the Compendium's STRIDE template are available on the free Personal plan. Continuum Cloud's exposure views are part of the Team plan.

What is STRIDE?

A way to look for threats by category: spoofing identity, tampering with data, repudiation of actions, information disclosure, denial of service and elevation of privilege. You check each element of the data-flow diagram against each category.

Does Blueprintr generate threats automatically?

No. There is no threat library or automatic threat generation. Your team identifies the threats in a workshop and records them on the diagram, which keeps the analysis specific to your system.

How should I score threats?

A simple scale works: likelihood from 1 to 5 times impact from 1 to 5, with a threshold above which a threat must be mitigated before launch. Blueprintr records the scores you set; it does not calculate them.

When should a threat model be updated?

Whenever the design changes: a new flow, a new data store, a new boundary crossing. Publish after each review, so the snapshot shows what was analysed and when.

Can I share the threat model with a penetration tester?

Yes. Share the blueprint privately with named people, or send an unlisted link, with a password on Premium and above.

Model the threats on the design, and keep every fix one click away