Skip to content

Mitigations & Status

[!NOTE] Required license feature: threat

Countermeasures for a threat are proposed by the Threat Modeling Agent during its Develop countermeasures stage — typically one to three per threat. They aren't a separate list page — they show up in two places, both driven by the same underlying data:

  • On each threat card, in the Data Flow Diagram side panel — the countermeasures for that specific threat, with status and, where the threat was promoted to a risk, a link through to it.
  • On the model's Lifecycle dropdown — the "Develop countermeasures" stage row shows whether countermeasures exist yet for the model and lets you (re-)run just that stage.

Once you mark a countermeasure as completed or verified, later agent runs leave it alone.

A threat generated by the agent can be promoted to a risk, with origin "Threat Model Assessment (TMA)". The risk carries its full threat-model context — STRIDE/ENISA categories, CWEs, affected element, trust-boundary crossing, run id and threat id — wherever the risk is viewed or edited.

📸 Screenshot: a threat card in the side panel showing its countermeasures and linked risk.