threatdragon
by threatdragon
OWASP Threat Dragon is a free, open-source, cross-platform threat modeling tool designed to simplify and automate risk assessment.
OWASP Threat Dragon threat modeling tool
Primary Use Case
Threat Dragon is primarily used by security professionals and developers to create threat models that identify and mitigate potential security risks in software systems. It facilitates risk assessment and security training by providing an intuitive interface for designing threat models, making it suitable for organizations focused on Governance, Risk, and Compliance (GRC).
- Free and open-source
- Cross-platform compatibility
- Graphical threat modeling application
- Supports risk assessment and security automation
- Encourages community contributions
- Developed and maintained by OWASP
- Integrate Threat Dragon into secure SDLC pipelines to automate threat modeling during development.
- Use generated threat models to guide both red team attack simulations and blue team defense hardening.
- Leverage Threat Dragon outputs to create targeted security training scenarios for developers and security teams.
- Combine with automated risk assessment tools to prioritize remediation efforts based on modeled threats.
- Encourage cross-team collaboration by sharing threat models as living documents to enhance purple team exercises.
Docs Take 2 Hours. AI Takes 10 Seconds.
Ask anything about threatdragon. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.
This tool hasn't been indexed yet. Request indexing to enable AI chat.
Admin will review your request within 24 hours
Related Tools

unleash
Unleash/unleash
Open-source feature management platform
the-practical-linux-hardening-guide
trimstray/the-practical-linux-hardening-guide
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
how-to-secure-anything
veeral-patel/how-to-secure-anything
How to systematically secure anything: a repository about security engineering
404StarLink
knownsec/404StarLink
404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目
steampipe
turbot/steampipe
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Security-101
microsoft/Security-101
8 Lessons, Kick-start Your Cybersecurity Learning.
