STRIDE Threat Model
Threat-model a system using the STRIDE taxonomy.
Rendering…
Make it your own.
mindmap
root((STRIDE))
Spoofing
Steal session token
Phishing for credentials
Replay JWT
Tampering
Modify request payload
Tamper with stored data
Corrupt CI artifacts
Repudiation
No audit log of admin actions
No signed receipts
InformationDisclosure
Leaky error messages
Unencrypted backups
Logs containing PII
DenialOfService
Resource exhaustion
Slowloris on TLS handshake
Expensive queries
ElevationOfPrivilege
Missing authorization checks
SSRF to metadata service
Misconfigured IAM roles