STRIDE, DREAD, and attack trees — systematically identify and prioritize security threats before they're exploited.
Five passes over the same idea, each from a different angle. Do them in order, or jump to whichever you need.
Threat modeling is a structured approach to identifying security threats. STRIDE categorizes threats (Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege). DREAD scores risk. Attack trees map attack paths. Data flow diagrams (DFDs) identify trust boundaries. Threat modeling should happen during design, not after deployment.