Threat modeling tools
As already pointed out, there are a number of tools for actually doing threat modeling, but it can be confusing and frustrating as to what to choose. The good news is you do not necessarily have to choose one—or any, for that matter. A simple spreadsheet or diagramming tool with documents can be employed. However, if you go down the tool route, it is not uncommon to use multiple tools to complete the task as each tool has specific features and functions that may not completely align or cover all the areas needed. Here are some of the most popular threat modeling tools available today:
- CVSS 3.0 is used for CVSS modeling and can score vulnerabilities identified from vulnerability assessments. It is provided by NIST at https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator.
- Microsoft’s Threat Modeling Tool was designed to be simple and can be used by non-security experts. The tool works based on the STRIDE threat modeling classification. The...