Cybersecurity and AI Architecture Fellow of the British Computer Society (FBCS)
1-Day Course · Intermediate · Hands-on
Threat Modeling · SEC-411

Threat Modeling for Developers

Find the threats before you write the code. This one-day course covers STRIDE methodology, PASTA framework, attack trees, data flow diagrams, trust boundaries and hands-on threat modeling for web applications, APIs and microservices. You leave with a threat model template and the skills to use it.

SEC-411. The syllabus

One day, from diagram to threat model

A practical threat modeling course for developers. Every module builds toward the capstone: producing a complete threat model document. (Times are approximate.)

Morning

Methodology and Frameworks

S1-00 Why Developers Should Threat Model 0.5 hr

Threat modeling is not just for security teams. Developers who threat model write more secure code because they understand the attack surface before writing the first line. This module makes the case with real examples of vulnerabilities that threat modeling would have caught at design time.

S1-01 STRIDE Methodology 1 hr

STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) is the most widely used threat modeling framework. Apply STRIDE to each element in a system: processes, data stores, data flows, and external entities. Work through a complete example from diagram to threat list.

S1-02 PASTA Framework 1 hr

Process for Attack Simulation and Threat Analysis (PASTA) is a risk-centric threat modeling framework. Walk through all seven stages, from business objective definition through attack simulation. Understand when PASTA is more appropriate than STRIDE (when business risk drives the analysis).

S1-03 Attack Trees 1 hr

Attack trees decompose a threat goal into the steps an attacker would take. Build attack trees for common goals: steal user credentials, exfiltrate data, achieve remote code execution. Use attack trees to identify the most likely and most impactful attack paths.

S1-04 Data Flow Diagrams and Trust Boundaries 1 hr

Data flow diagrams (DFDs) are the foundation of most threat modeling approaches. Draw DFDs at Level 0 (context) and Level 1 (detailed). Identify and mark trust boundaries. Every element that crosses a trust boundary needs security controls. Practice drawing DFDs for real applications.

S1-05 Identifying the Attack Surface 1 hr

The attack surface is everything an attacker can interact with: endpoints, protocols, file formats, APIs, configuration, dependencies, and human interfaces. Systematically enumerate the attack surface of a sample application. Understand attack surface reduction as a design principle.

Afternoon

Applied Threat Modeling and Labs

S1-06 Threat Modeling a Web Application 1 hr

Apply STRIDE to a three-tier web application: browser frontend, API backend, and database. Draw the DFD, identify trust boundaries, enumerate threats, and prioritize by risk. Produce a threat model document that a development team can act on.

S1-07 Threat Modeling an API 1 hr

APIs have a different threat profile than web applications. Apply STRIDE to a REST API: authentication, authorization, input validation, rate limiting, and inter-service communication. Cover API-specific threats: BOLA, mass assignment, and excessive data exposure.

S1-08 Threat Modeling a Microservice 1 hr

Microservices distribute the attack surface. Threat model service-to-service communication, service mesh trust, secret distribution, and the blast radius of a single compromised service. Cover the unique challenges: lateral movement, confused deputy, and shared data stores.

S1-09 The Threat Model Document 0.5 hr

A threat model is only useful if it is documented and maintained. Cover the standard threat model document structure: scope, DFD, threat list, mitigations, residual risks, and assumptions. Build a template that works for your team.

S1-10 Integrating Threat Modeling into Sprints 0.5 hr

Threat modeling does not have to be a heavyweight process. Cover lightweight approaches: 15-minute threat modeling for new features, threat modeling as part of design review, and maintaining the threat model as the system evolves. Make it a habit, not a ceremony.

S1-11 Capstone Lab: Threat Model Exercise 2 hrs

Given a system architecture description, produce a complete threat model: DFD, trust boundaries, STRIDE analysis, prioritized threats, and recommended mitigations. Present your threat model and defend your prioritization. Debriefed as a group.

S1-12 Course Wrap-Up 0.5 hr

Review the threat modeling methodology, templates, and checklists you take away. Cover how to champion threat modeling in your organization and how to train your team.

~14 hrs
Total instructional hours
14
Individual modules
1 day
Delivery days
Reserve a place

Find the threats at design time.

One day of hands-on threat modeling for developers. STRIDE, PASTA, attack trees, data flow diagrams and applied threat modeling for web apps, APIs and microservices.

1 day intensive Templates included Private corporate cohorts available
Reserve a Place

Corporate and sovereign cohorts, and bespoke on-site delivery, on request.