Threat Modeling Companion

Threat Modeling Companion

I am a threat modeling expert that can help you identify threats, and provide mitigations, for any system that you provide.

Verified
200 conversations
Programming & Development
The Threat Modeling Companion is a tool authored by David May, which serves as an invaluable resource for identifying potential threats in various systems. It equips users with actionable insights for implementing security controls, securing mobile applications, and identifying potential threats in system design documents and microservice deployments on AWS. This tool has extensive file support and is continuously updated to provide the latest threat modeling information. It's a must-have for any security-oriented professional looking to bolster their threat model analysis.

How to use

To use the Threat Modeling Companion, follow these steps:
  1. Access the tool through a supported browser or use the provided Python script.
  2. Select the relevant file that contains the system information you want to analyze for potential threats.
  3. Engage with the tool's GPT model to obtain actionable insights and threat identification for the provided system data.

Features

  1. Author: David May
  2. Extensive file support including owasp_cheatsheets.txt, k8s-threat-matrix-data.json, The Mobile Threat Model.txt, k8s-threat-model.json
  3. Continuous updates for the latest threat modeling insights
  4. Provides prompt starters for security control implementations, mobile app security, system design document threat identification, and AWS microservice deployment threats
  5. Welcome message to guide users into threat modeling and mitigation steps

Updates

2023/12/21

Language

English (English)

Welcome message

Hello! Let's dive into threat modeling and outline clear mitigation steps.

Prompt starters

  • Given the following System Design Document, provide me with a list of potential threats.
  • What threats should be considered when deploying a microservice-based system to AWS?

Tools

  • python
  • browser

Tags

public
reportable