Application Security

Threat Model Calculator

Enter a component or feature to apply STRIDE threat modeling and calculate OWASP Risk Rating methodology scores for likelihood and impact.

No data is transmitted — everything runs locally

Example — Representative default scenario — internet facing services 8 · open ports 15 · privileged accounts 25.

Spoofing risk
Medium
authentication component
Info Disclosure
Medium
standard
Top STRIDE threat
Tampering
for this component type

Threat Model Calculator

The Threat Model Calculator applies STRIDE categorization and OWASP Risk Rating methodology to compute likelihood, impact, and priority scores for system components.

• Apply STRIDE to a new authentication flow before implementation

• Calculate OWASP risk score for a threat finding to prioritize remediation

• Generate threat model outputs for a security design review

• Compare STRIDE vs DREAD methodology outputs for a specific threat

Credential and secrets management for teams. 1Password provides enterprise password management and secrets infrastructure for development teams.
View threat model credentials with 1Password
External site · Independent provider · We may receive a commission · Not a recommendation
What does this tool tell you?
The Threat Model Calculator applies STRIDE categorization and OWASP Risk Rating methodology to compute likelihood, impact, and priority scores for system components.
What affects the result most?
STRIDE classification: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege. Attack surface components: network interfaces, APIs, user inputs, file uploads, third-party integrations. Risk = Likelihood × Impact — qualitative 1-5 scale per OWASP Risk Rating Methodology.
How should I use the result?
The calculation is deterministic — the same inputs always produce the same output — so the most useful workflow is to vary one input at a time and see which factor moves the result most. That tells you where to focus your attention before committing to a decision.
Application security certification details. Practical DevSecOps certification — CZTP and related courses for AppSec practitioners. Maps to OWASP, JWT, TLS, dependency security tools.
View AppSec certification details →
External site · Independent provider · We may receive a commission · Not a recommendation