2 comments

[ 3.5 ms ] story [ 13.8 ms ] thread
From "Architectural Retrospectives: The Key to Getting Better at Architecting" https://news.ycombinator.com/item?id=41234471 :

> Is there already a good way to link an ADR Architectural Decision Record with Threat Modeling primitives and considerations?

Awesome-threat-modeling > Tools: https://github.com/hysnsec/awesome-threat-modelling#free-too...

- pytm: https://github.com/izar/pytm

- threatspec has a docstring spec for adding threat modeling annotations to source code: https://threatspec.org/

- OWASP Threat Dragon : https://owasp.org/www-project-threat-dragon/ :

> Threat Dragon supports STRIDE / LINDDUN / CIA / DIE / PLOT4ai, provides modeling diagrams and implements a rule engine to auto-generate threats and their mitigations.

- OWASP Threat Modeling Cheat Sheet > Systems Modeling: https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeli...

- https://github.com/dehydr8/elevation-of-privilege:

> An online multiplayer version of the Elevation of Privilege (EoP) threat modeling card game