Threat Modeling
Version 1.0.0 · Updated 2026-07-30
CORE DEFINITION
Systematically identify "who might attack", "what might be attacked", "how attacks might occur", and "how to defend", considering security threats at the design stage.
SCAFFOLDING EFFECT
Reduce cognitive load
Think from the attacker's perspective. Ask "If I wanted to cause damage, how would I do it?" Use the attacker's viewpoint to discover defensive blind spots.
Anchor fast decisions
At the design stage, systematically enumerate assets, threat actors, attack surfaces, and defensive measures from the attacker's perspective, shifting security left rather than patching after the fact. A structured approach covers threat paths that might be missed by ad-hoc thinking.
MINIMUM ACTION
In progress 0/1Practice this model in one real situation:
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more
Source support: Explicit
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Threat_modelverified
PRIVATE NOTES · Only visible to you
SAVED Q&A
ENTRY Q&A · Private saving available
Ask with a clear boundary
thinkingmodels answers from published entry context only.
Your question is sent to thinkingmodels. The answer uses public entry context only.
RELATED MODELS