Threat Models¶
[!NOTE] Required role:
developer,compliance_manager,manageroraccount_adminRequired license feature:threatStatus: BETA
TrustSource maintains a threat model per project. The model is produced by the Threat Modeling Agent (TMA) — an automated service that reads your project inventory, elicits STRIDE-classified threats, proposes countermeasures, and stores each run as an interactive Data Flow Diagram (DFD) — or you can import an existing OTM / OWASP Threat Dragon document instead. Reviewing findings and tracking mitigations happens in the app; the agent handles the analysis.
📸 Screenshot: the Threat Models list with project, run, format and threat count.
Two ways to run the agent¶
- Run all (the default) — runs the whole pipeline (build model → generate risks → develop countermeasures) in one pass.
- Individual stages — trigger Build model, Generate risks or Develop countermeasures separately, in any order, from the same dialog or later from a model's Lifecycle menu. Useful when you want to review one stage before committing to the next, or re-trigger a single stage after new findings.
Both paths are automated and idempotent — re-running with no new material changes nothing. See Run Modes for per-stage use-cases and details.
In this section¶
| Page | What it covers |
|---|---|
| Generate or Import a Threat Model | Starting a run, choosing a stage, importing an existing document. |
| Data Flow Diagram & Threat Detail | Reading the diagram and the threat side panel (STRIDE / ENISA / CWE). |
| Mitigations & Status | Where countermeasures show up and how their status is tracked. |
| Run Modes | Complete run vs. individual stages, and when to use each. |
Background reading¶
New to STRIDE and threat modelling? The EACG Threat Modeling course in the Academy walks through the method and the vocabulary the agent uses (trust zones, data flows, STRIDE categories) in about an hour.
Related¶
- Threat Modeling Agent — capability overview and guarantees
- Application goals upload — the
architecture.mdupload the agent reads when building the model