performing-threat-modeling-with-owasp-threat-dragon - Threat Modeling with OWASP Threat Dragon
Create data flow diagrams, identify threats using STRIDE and LINDDUN, and generate threat model reports
Tags
Updated: 2026-05-09Capabilities
Typical Inputs
Typical Outputs
What this skill does
- create data flow diagrams
- identify threats using STRIDE
- identify threats using LINDDUN
- define mitigation strategies
- generate threat model reports
- export threat models
- import from CycloneDX TMBOM
- apply threat rules engine
Inputs
- application architecture documentation
- network diagrams
- system trust boundaries
- external dependencies
- compliance requirements
Outputs
- JSON threat model files
- PDF threat model reports
- annotated data flow diagrams
- threat inventory with severity
- mitigation recommendations
- CycloneDX TMBOM exports
Requirements
- OWASP Threat Dragon desktop application or web instance
- understanding of data flow diagram notation
- familiarity with STRIDE or LINDDUN threat classification
