awesome-threat-modelling
github.com/hysnsec/awesome-threat-modelling ↗A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me paid resources from awesome-threat-modelling"
Installation instructions →What's inside
Tutorials and Blogs
Threat Model examples
Videos
- Adaptive Threat Modelling
- An Agile Approach to Threat Modeling for Securing Open Source Project EdgeX Foundry
- AWS Summit - How to approach threat modelling
How to approach threat modelling
- Creating a Threat Model using TMT 2016
- Designing for Security through Threat Modelling
- Fixing Threat Models with OWASP Efforts
Courses
- Certified Threat Modeling Professional by Practical DevSecOpsPaid
- CyberSec First Responder: Threat Detection & Response CFR210Paid
- DevSecOps Expert by Practical DevSecOpsPaid
- Kubernetes Threat ModelingPaid
- Learning Threat Modeling for Security ProfessionalsPaid
- Rapid Threat Model Prototyping (RTMP)Free
Methodology to create quick threat models (1) add threat metadata describing the threats and mitigations directly to software diagrams using 11 simple and repeatable steps (2) integrate these steps into Agile workstreams (3) how to best use the outputs of a threat model (Threats & Mitigations)
Tools
- DeciduousFree tools
A web app that simplifies building attack decision trees. Hosted at
- drawio-threatmodelingFree tools
A collection of custom libraries to turn the free and cross-platform Draw.io diagramming application into the perfect tool for threat modeling.
- ForeseetiPaid tools
SecuriCAD Vanguard is an attack simulation and automated threat modeling SaaS service that enables you to automatically simulate attacks on a virtual model of your AWS environment.
- Irius riskPaid tools
Iriusrisk is a threat modeling tool with an adaptive questionnaire driven by an expert system which guides the user through straight forward questions about the technical architecture, the planned features and security context of the application.
- MALFree tools
MAL is an open source project that supports creation of cyber threat modeling systems and attack simulations.
- Microsoft Threat Modeling ToolFree tools
Microsoft Threat Modeling Tool 2016 is a tool that helps in finding threats in the design phase of software projects.
Books
- Designing Usable and Secure Software with IRIS and CAIRIS
- Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis
- Securing Systems: Applied Security Architecture and Threat Models
- Threat Modeling
- Threat Modeling: A Practical Guide for Development Teams
- Threat Modeling: Designing for Security
Fundamentals
Showing a sample of 115 resources. View the full list on GitHub →