OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application used to draw threat modeling diagrams and to list threats for elements in the diagram.
Threat Dragon is designed to be accessible, with an emphasis on flexibility and simplicity. It supports multiple threat modeling frameworks including STRIDE, CIA, LINDDUN, and more.
You can run Threat Dragon as a standalone desktop application or a fully featured, configurable, self-hosted web application.
OWASP Threat Dragon is a modeling tool used to create threat model diagrams as part of a secure development lifecycle. Threat Dragon follows the values and principles of the threat modeling manifesto. It can be used to record possible threats and decide on their mitigations, as well as giving a visual indication of the threat model components and threat surfaces.
Threat Dragon runs either as a web application or as a desktop application.
Threat Dragon supports STRIDE / LINDDUN / CIA / DIE / PLOT4ai, provides modeling diagrams and implements a rule engine to auto-generate threats and their mitigations.
Whether you're a seasoned threat modeling expert or just getting started, you can test out Threat Dragon by visiting our demo website or downloading the desktop app
Threat Dragon comes with sample threat models to help get you started!
Visit the Demo Site
Click "Login to Local Session"
Select "Explore a sample threat model"
Select a threat model that is most relevant to your use case
Click the diagram image
Explore the diagram!
For more information, check out our documentation or click the "Additional Resources" tab on this page.
Have questions? Ideas? Want to contribute? The quickest way to get in touch is by emailing our project's mailing list: threat-dragon-project@owasp.org or joining us in our OWASP slack channel #project-threat-dragon (you'll need a Slack invite first)
Do you want to contribute, but you're note sure where to start?
Contributions come in many shapes - you don't need to be a programmer to contribute! Threat Dragon needs community feedback, issue/bug reports, feature requests, participation in discussions, UI/UX experts, help with translations, distribution and marketing, the list goes on! If you want to get involve, then you belong to our community - one of our leaders will be happy to help you get started.
Reporting an Issue or requesting a feature: https://github.com/OWASP/threat-dragon/issues
Public discussions: https://github.com/OWASP/threat-dragon/discussions
Town halls: https://github.com/OWASP/threat-dragon/discussions/1492
Project Leader
Jon is a leader for the OWASP Threat Dragon and Developer Guide projects. For some years he was an OWASP Chapter leader for Bristol, England, and still helps out with organising these chapter meetings.