Model / threat-modeling
Threat modeling and data flows
Trust boundaries, flows that cross them, STRIDE and the threat report.
Create a model or view with the Security / data flow notation. Draw trust boundaries as containers and set each one's zone type (public, DMZ, internal or restricted). Elements drawn inside a boundary are in that zone, and so are the parts of a system inside it and whatever a node inside it hosts.
Data flows
Connect elements with flows to and give the flow a payload, a classification and a protocol. On the canvas a flow shows what it carries and its classification.
Boundary crossings
The Threats tab of a model lists every flow whose ends sit in different zones. A crossing with no control that protects either end is flagged, in that tab and in Validation, and so is a crossing without a classification.
STRIDE
Each crossing suggests STRIDE threats: tampering and denial of service always; spoofing, elevation of privilege and, without a control, repudiation when data enters a more trusted zone; information disclosure when the data is sensitive or unclassified. Suggestions are not added until you choose Add threat, which records a threat the element exposes. Link a control that mitigates it to close it.
Controls
Each threat in the Threats tab offers controls from a curated set of NIST SP 800-53 Rev. 5 controls suited to its STRIDE category, such as IA-2 for spoofing or SC-8 for tampering in transit. Choosing one adds the control once (it is reused across threats), records that it mitigates the threat and protects the element that exposes it, so the crossing counts as protected.
Threat report
Download threat report writes a Markdown report of zones, crossings, threats and their mitigations, open candidates and findings, for a review or a ticket.