Best Threat Modeling Software in 2026: 10 Tools Compared

Search for threat modeling software and you get two kinds of answer. Vendor pages say their tool is the only serious option, and list articles rank twenty tools without anyone having opened them. Neither helps much when what you actually need to know is which three to try this week.

This guide compares ten tools that teams really use in 2026: commercial platforms, free desktop and web apps, and threat-modeling-as-code projects. For each one it covers what it's like to use, what it costs, how it finds threats, and who it suits.

A note on bias: we make ThreatTree, which is one of the ten. We've tried to be fair: every tool gets the same structure, ThreatTree's limitations are listed as plainly as anyone else's, and we say where another tool is the better choice. Facts about other products come from their own documentation, release notes and pricing pages, checked on October 8, 2026. Products change, so if something here is out of date, tell us and we'll fix it.

The short answer

All ten at a glance

ToolTypePriceFree optionRuns onHow threats are found
ThreatTreeSaaS$29/user/month (Pro)Free plan, 3 forestsBrowserYour team, guided by STRIDE, LINDDUN, OWASP, CAPEC and ATT&CK tags
IriusRiskSaaS or on-premiseOn requestCommunity Edition, 3 models, 1 userBrowserGenerated from component rules, plus an AI assistant
ThreatModelerSaaSOn requestNoBrowserGenerated from a threat library, plus agentic AI features
SD ElementsSaaS or on-premiseOn requestNoBrowserGenerated as security requirements from an application profile
DeviciSaaSOn request (Pro)Free tierBrowserSuggested from its threat libraries, with AI assistance
Microsoft Threat Modeling ToolDesktop appFreeFreeWindows onlyGenerated per element (STRIDE) from a template
OWASP Threat DragonOpen source (Apache 2.0)FreeFreeBrowser, Windows, macOS, LinuxYour team, by STRIDE, LINDDUN, CIA or PLOT4ai category
AWS Threat ComposerOpen source (Apache 2.0)FreeFreeBrowser, VS CodeYour team, written with a threat grammar; optional AI draft from code
OWASP pytmOpen source, PythonFreeFreeAnywhere Python runsGenerated from a rule set against a model written in code
ThreagileOpen source (MIT)FreeFreeCLI, Docker, REST serverGenerated by 40+ risk rules against a YAML model

What to look for in threat modeling software

Before the individual reviews, it helps to know which differences actually matter. Most tools can draw a diagram and hold a list of threats. They differ in eight places.

  1. How you describe the system. A data flow diagram on a canvas, a questionnaire, or a model written in code. Diagrams are best for workshops; code is best for pipelines; questionnaires scale to hundreds of applications with little security staff time.
  2. How threats are found. Rule-based tools generate threats from the elements you draw. That gets you a long list in minutes, but much of it is generic and still needs triage. Framework-guided tools leave identification to people, using STRIDE or similar as a checklist. That's slower, and tends to produce threats that are specific to the system.
  3. Whether threats can be decomposed. A flat list says what could go wrong. An attack tree also shows how: which steps an attacker needs, which are alternatives, and which single control breaks several paths at once.
  4. Scoring and a risk register. If threats aren't scored and collected somewhere, the model ends up as a document rather than something that drives work. Look for likelihood and impact, a treatment decision, and an owner. Our guide to turning a threat model into a risk register covers what that should look like.
  5. Standards mapping. If an auditor will read the output, being able to tie each mitigation to ISO 27001, NIST, SOC 2 or PCI DSS controls saves a translation step later.
  6. Collaboration. Threat modeling is done in groups. Single-user desktop files and Git-stored JSON work for one person; a team usually needs shared models with roles.
  7. Exports and integrations. PDF for auditors and leadership, JSON for scripts, and tickets in Jira or similar so mitigations get done.
  8. Where the data lives and what it costs. A threat model is a map of your weakest points. Check where it's stored and who can read it. Check, too, whether the price is published or you'll be talking to sales before you can try the tool with your team.

Commercial platforms

1. ThreatTree

Best for: security teams, consultancies and solo builders who want architecture-anchored threat models, attack trees and a scored risk register without an enterprise sales process.

ThreatTree organises each system into a "forest". You map the architecture as a data flow diagram, with trust boundaries for 16 cloud providers, then build attack trees against it using AND/OR gates down to individual attack steps. Each step can be tagged with STRIDE, LINDDUN, OWASP Top 10 (including the LLM and Agentic AI lists), CAPEC and MITRE ATT&CK or ATLAS technique IDs, and scored on likelihood and impact. Every scored step flows into a forest-wide risk register automatically, with a treatment plan (mitigate, avoid, transfer or accept) and an owner.

  • Strengths: attack trees linked to the DFD, which few other tools have; a register that fills itself from the trees; mitigations mappable to ISO 27001:2022, NIST SP 800-53, NIST CSF 2.0, CIS Controls v8, OWASP ASVS, PCI DSS v4.0 and SOC 2 on Pro; optional client-side AES-256-GCM encryption on every plan, so the server stores only ciphertext; published pricing.
  • Limitations: no rule engine that generates threats for you, so your team does the thinking, guided by the frameworks; no self-hosted community edition (Enterprise offers a dedicated deployment); a younger product from a small team, without a SOC 2 or ISO 27001 certification of its own, which some procurement processes require.
  • Pricing: Free (3 forests, 3 DFDs per forest, 5 attack trees per DFD, risk register and PDF register export included). Pro is $29 per user per month and adds unlimited models, collaboration, standards mapping, full PDF reports and STIX 2.1 export. Enterprise is quoted and adds SSO/SAML, SCIM, two-way Jira, ServiceNow, Linear and Azure DevOps sync, and DFD import from OpenAPI, CloudFormation and Terraform.

See the full feature list, or how it compares directly with IriusRisk and ThreatModeler.

2. IriusRisk

Best for: large organisations that want threats and countermeasures generated automatically and pushed into developer workflows, at scale.

IriusRisk is one of the best-known names in the category. You draw the architecture on a draw.io-based canvas using components from its libraries, and a rules engine generates the threats and countermeasures that apply to each component. It ships with standards and compliance libraries, an AI assistant called Jeff that can draft models from descriptions, issue tracker integrations and an API. It runs as SaaS or on-premise. In January 2026 IriusRisk was acquired by ThreatModeler, so the two are now one company; both products were still being sold separately when we checked.

  • Strengths: mature rules engine and content libraries; strong integration story for large development organisations; on-premise option.
  • Limitations: enterprise pricing only; generated threat lists can be long and need tuning to be useful; the free Community Edition is limited to three active threat models and one user; the product roadmap is less predictable while two platforms are being combined.
  • Pricing: Community Edition is free. Enterprise is priced on request.

Read our full IriusRisk alternative comparison.

3. ThreatModeler

Best for: enterprises modelling many applications and cloud environments, who want automation and a vendor that can support a large rollout.

ThreatModeler generates threats from a large threat library as you diagram applications, cloud infrastructure and devices. It has invested heavily in AI: "Intelligent Threat Modeling" launched in September 2025 and ThreatModeler Nexus, which the company describes as an agentic threat modeling platform, reached general availability in June 2026. With the IriusRisk acquisition it now claims the industry's largest proprietary threat-model dataset.

  • Strengths: broad coverage across application, cloud and infrastructure models; heavy automation; enterprise support and services.
  • Limitations: no free tier and no published pricing; built and priced for large programmes, which can be more than a small team needs; a major merger is under way, so it's worth asking about roadmap commitments for the product you're buying.
  • Pricing: annual subscription, priced on request.

Read our full ThreatModeler alternative comparison.

4. SD Elements

Best for: organisations that want a security-requirements programme across a large application portfolio, more than diagram-driven threat modeling.

SD Elements, from Security Compass, approaches the problem from the requirements side. You describe each application (its technology, data and deployment) and it generates the threats and security requirements that apply, along with countermeasures and training, then delivers them as tasks in tools such as Jira and GitLab. It suits a central security team that needs consistent requirements across hundreds of applications without running a workshop for each one.

  • Strengths: scales across a large portfolio with little security staff time per application; strong compliance and requirements content; developer-facing tasks and training.
  • Limitations: less suited to exploring a specific system's architecture in depth; enterprise pricing; a programme to roll out rather than a tool to pick up on a Tuesday.
  • Pricing: on request.

5. Devici

Best for: development teams that want a modern, collaborative canvas with AI help and a free tier to start.

Devici started as an independent product and was acquired by Security Compass in June 2025, where it now sits alongside SD Elements. You build data flow diagrams on a real-time collaborative canvas, and its "Codex" libraries (covering STRIDE, OWASP Top 10, the OWASP LLM and API Security lists, LINDDUN and CWE, among others) suggest threats and mitigations for each element. AI features can draft attributes and diagrams from plain-language descriptions or from code.

  • Strengths: polished, developer-friendly canvas; live collaboration; AI assistance available on the free tier.
  • Limitations: paid tiers are quote-only; no attack-tree view of how threats combine; its long-term position next to SD Elements inside Security Compass is still taking shape.
  • Pricing: a free tier (third-party listings put it at up to three threat models and three users); Pro and Enterprise on request.

Free desktop and web tools

6. Microsoft Threat Modeling Tool

Best for: individual developers on Windows learning STRIDE, especially on Azure-hosted applications.

Microsoft's tool has probably introduced more people to threat modeling than any other. You pick a template (the generic SDL template or an Azure one), draw a DFD from its stencils, and switch to Analysis view, where it generates a STRIDE threat list for every element and flow. You can then mark each threat as needing investigation, not applicable or mitigated, and export an HTML report. Templates can be customised.

  • Strengths: free; automatic STRIDE-per-element threat generation that teaches the method; an Azure template with platform-specific threats; a large body of tutorials.
  • Limitations: Windows 10 or later only, with .NET 4.7.1; models are local .tm7 files, so collaboration means passing files around; generated lists are long and generic; no attack trees, scoring workflow or cross-application risk register; updates are infrequent (the latest release in Microsoft's notes is 7.3.51110.1 from November 2025, the first since October 2023).
  • Pricing: free.

If you're outgrowing it, see our Microsoft Threat Modeling Tool alternative page.

7. OWASP Threat Dragon

Best for: teams that want a free, open-source, cross-platform tool and are happy to store threat models in Git.

Threat Dragon has OWASP Production status and is actively maintained, with version 2.6.2 released in May 2026. You draw a DFD in the browser or the desktop app (Windows, macOS, Linux), then add threats to each element, categorised by STRIDE, LINDDUN, CIA, CIA-DIE or PLOT4ai. Each threat has a status (including mitigated, accepted, transferred and avoided), a severity, a free-text score and mitigations. Models are JSON files stored locally or in GitHub, GitLab, Bitbucket or Google Drive. A separate community-built AI tool can generate STRIDE threats into a model using your own LLM API key.

  • Strengths: free and Apache 2.0 licensed; runs anywhere; models live in your own repositories; simple enough to learn in an afternoon.
  • Limitations: threats are mostly entered by hand; collaboration happens through Git rather than live editing; no attack trees, no register across models and no standards mapping; you run and support it yourself.
  • Pricing: free.

See OWASP Threat Dragon vs ThreatTree for a side-by-side.

8. AWS Threat Composer

Best for: teams that think in written threat statements, and AWS-centred teams that want a lightweight, free tool.

Threat Composer, from AWS Labs, is built around a "threat grammar": a fill-in-the-blanks structure (threat source, prerequisites, action, impact, affected assets) that produces consistent, specific threat statements. You record assumptions and mitigations against them, attach architecture and data flow diagrams, and an insights dashboard flags gaps in coverage. It runs as a static web app or inside VS Code through the AWS Toolkit, and an AI-assisted CLI and MCP server can draft a starter model from source code. It's actively maintained, with releases through August 2026.

  • Strengths: free and Apache 2.0 licensed; the grammar produces better-written threats than most tools; runs in the browser or the IDE.
  • Limitations: diagrams are reference images, not modelled elements; no attack trees, scoring workflow or multi-user collaboration built in; data stays in the browser or files, which is good for privacy but means you organise sharing yourself.
  • Pricing: free.

Threat modeling as code

9. OWASP pytm

Best for: engineering teams who want threat models versioned, reviewed and regenerated like any other code.

pytm is a Python framework. You declare the system's elements, data flows and boundaries in a Python file, and pytm generates a data flow diagram, a sequence diagram and a threat report by applying its threat rules to each element. Version 1.4.0 shipped in July 2026, after a two-year gap.

  • Strengths: models live in the repository and change through pull requests; output is reproducible and scriptable; free.
  • Limitations: needs someone comfortable with Python; not something you can run a workshop in; rule-generated threats need review like any other generated list.
  • Pricing: free.

10. Threagile

Best for: DevSecOps teams who want risk rules run against an architecture model on every build.

Threagile takes a YAML description of your assets, components, communication links and trust boundaries and runs more than 40 built-in risk rules against it, with support for custom rules. It produces diagrams, PDF and Excel reports and JSON, and runs as a CLI, in Docker or as a REST server.

  • Strengths: designed for pipelines; detailed reports; MIT licensed.
  • Limitations: YAML models get long for big systems; the last tagged release was v0.9.1 in July 2024, so check recent commit activity before you depend on it.
  • Pricing: free.

Also worth knowing about

  • AI-first newcomers. A wave of tools that read design documents, tickets or code and produce threat models with LLMs has appeared since 2024. Some are promising. Before you use one, read our take on where AI helps a threat model and where it misleads, and remember that sending your architecture to a third-party AI service is itself a decision to threat-model.
  • CAIRIS. An open-source platform that combines security, usability and requirements engineering. It's powerful and academically grounded, though its last tagged release was in 2023.
  • A drawing tool and a spreadsheet. Draw.io and a spreadsheet are how most teams start, and there's no shame in it. It stops working when the diagram and the spreadsheet drift apart, when nobody can tell which risks were accepted and by whom, or when an auditor asks to see the history. Our free templates are a reasonable way to start before choosing a tool.

How to choose: four questions

1. Who will build the models? If it's a central security team running workshops, pick a diagram-first tool with good collaboration. If it's developers inside their own repositories, look at Threat Composer, pytm or Threagile. If it's hundreds of application teams with little security support, a requirements-driven platform like SD Elements, or rule-based generation from IriusRisk or ThreatModeler, scales better.

2. Do you want threats generated or thought through? Generation gives you coverage quickly and is easier to standardise; identification by people is slower but finds the threats that matter for this particular system, such as the business-logic abuse that no rule library knows about. Many teams combine the two, using a generated list as a checklist and attack trees for the risks that need real analysis.

3. Who reads the output? If it's only engineers, a list of threats with mitigations and tickets is enough. If leadership or auditors read it, you'll want scoring, a risk register, standards mapping and a report you can hand over without rewriting.

4. How will you buy it? Quote-only enterprise platforms usually mean a procurement cycle measured in months. Free and self-serve tools let you try a real system this week. Whatever you choose, test it on one real system with the people who'll use it, not on a vendor demo model.

Frequently asked questions

What is the best threat modeling software?

There isn't one best tool, because the right choice depends on who builds the models and who reads them. Large enterprises that want generated threats usually shortlist IriusRisk, ThreatModeler and SD Elements. Small and mid-sized teams that want diagrams, attack trees and a register at a published price look at ThreatTree or Devici. Teams that want free and open source pick Threat Dragon or Threat Composer, and teams that want models as code use pytm or Threagile.

Is there free threat modeling software?

Yes. Microsoft Threat Modeling Tool, OWASP Threat Dragon, AWS Threat Composer, OWASP pytm and Threagile are free outright. ThreatTree, IriusRisk and Devici have free plans with limits on the number of models. See our page on ThreatTree as a free threat modeling tool for what its Free plan includes.

Is the Microsoft Threat Modeling Tool still maintained?

Yes, but slowly. Microsoft's release notes list version 7.3.51110.1 in November 2025 as the latest release, the first since October 2023. It remains a Windows-only desktop application.

Do threat modeling tools generate threats automatically?

Some do. Microsoft Threat Modeling Tool, IriusRisk, ThreatModeler, pytm and Threagile generate threats from rules attached to the elements you draw or declare. ThreatTree, Threat Dragon and Threat Composer leave identification to your team and give it structure through frameworks such as STRIDE, or a threat grammar. Generated lists are faster to produce but need triage; hand-built threats take longer but are usually more specific.

Can't we just use a spreadsheet?

You can start that way, and for one small system it's fine. The problems come with time: the diagram and the spreadsheet drift apart, nobody can tell which risks were accepted and why, and there's no history to show an auditor. That's the point at which a dedicated tool pays for itself.

New to the practice? Start with what threat modeling is and how to run your first workshop, then come back to choose a tool.

Try ThreatTree on a real system

Map the architecture as a data flow diagram, decompose threats into attack trees, and watch every scored step land in a risk register. The Free plan covers three systems with no credit card, and Pro is $29 per user per month when you need more.

Get started free

Not ready to sign up? Get new threat-modeling guides by email instead.