The Microsoft Threat Modeling Tool is where a lot of teams first learn threat modeling. It's free, its STRIDE-per-element analysis teaches the method well, and it's backed by Microsoft's Security Development Lifecycle. Teams usually start looking for an alternative for practical reasons: it only runs on Windows, each model is a local file, there's no way to work on one model together, and updates are rare.
ThreatTree is one of those alternatives. This page compares the two honestly, including when you should stay with Microsoft's tool.
The short version: keep the Microsoft tool if you're one person on Windows who wants a STRIDE threat list generated for every element. Choose ThreatTree if your team needs to work on shared models from any operating system, break threats down into attack trees, score them into a risk register, and hand auditors a report mapped to ISO 27001, NIST or SOC 2.
Side by side
| Microsoft Threat Modeling Tool | ThreatTree | |
|---|---|---|
| Price | Free | Free plan; Pro $29/user/month |
| Runs on | Windows 10 or later, with .NET 4.7.1 | Any modern browser on Windows, macOS, Linux or ChromeOS |
| Where models live | Local .tm7 files | Your ThreatTree account, with optional client-side AES-256-GCM encryption |
| Working together | Share files; one editor at a time | Shared models with Owner, Editor and Viewer roles (Pro) |
| Diagram | DFD from template stencils, including Azure | DFD with trust boundaries for 16 cloud providers, AWS, Azure and GCP elements, and infrastructure elements such as WAFs, gateways and queues |
| Finding threats | Generated automatically per element (STRIDE) | Identified by your team, tagged with STRIDE, LINDDUN, OWASP Top 10, CAPEC and MITRE ATT&CK |
| Attack trees | No | Yes, with AND/OR gates, linked to the DFD |
| Scoring | Threat priority field | Likelihood × impact (1–25) with severity bands |
| Risk register | No | Built automatically across every attack tree, with treatment plans and owners |
| Standards mapping | No | ISO 27001:2022, NIST SP 800-53, NIST CSF 2.0, CIS v8, ASVS, PCI DSS v4.0, SOC 2 (Pro) |
| Reports | HTML report | Risk register PDF (all plans); full forest PDF report and STIX 2.1 (Pro) |
| Updates | Latest release November 2025; previous one October 2023 | Continuous, delivered in the browser |
Why teams move off the Microsoft tool
It's Windows-only. If half the team uses macOS or Linux, they can't open the models at all, and running a Windows VM just for threat modeling is the kind of friction that stops it happening.
Models are files. A .tm7 file sitting on someone's laptop or in a shared drive has no history, no access control beyond the folder, and no way for two people to edit it at once. The model ends up owned by whoever last saved it.
The threat list is long and generic. STRIDE-per-element generation is a good teaching device. On a real system it produces dozens of near-identical threats per flow, and the useful work is deciding which three matter. You can mark each one's status and justification, but working through the list takes longer than the analysis it supports.
It stops at a list. There's no way to show how an attacker would chain steps together, no scored register to prioritise from, and nothing to tie a mitigation to the control an auditor will ask about.
When to stay with the Microsoft tool
- You work alone, on Windows, and only need a threat list for one application at a time.
- You want threats generated for you rather than identified by your team. ThreatTree doesn't generate threats from a rules library; it gives your team frameworks and structure to find them.
- You rely on the Azure template's platform-specific threats, or on custom templates you've already built.
- You need a tool that works completely offline, for example in an air-gapped environment.
When ThreatTree is the better fit
- Your team uses a mix of operating systems, or you want nothing to install.
- Several people need to work on the same models, with roles and a shared history.
- You want to decompose the threats that matter into attack trees instead of triaging a generated list.
- Someone outside the team, such as leadership or an auditor, reads the output, so you need a scored risk register, standards mapping and a PDF report.
Moving a model across
ThreatTree can't import .tm7 files, so you redraw the diagram. For a typical application model that takes well under an hour, and it's a good moment to check the diagram still matches the system.
- Recreate the DFD. Processes, external entities, data stores and trust boundaries map one-to-one. Use the cloud-provider trust boundaries and infrastructure elements where the Microsoft stencils forced a generic shape.
- Carry over the threats that mattered. Threats you marked "Needs Investigation" or "Mitigated" in the Microsoft tool become leaves in an attack tree, tagged with the same STRIDE category. Ones marked "Not Applicable" usually don't need moving.
- Record mitigations as treatment plans. Each mitigated threat gets a Mitigate entry describing the control, and you can map it to an ISO 27001 or NIST control on Pro.
- Score and assign. Set likelihood and impact on each leaf; the risk register fills itself, and you assign owners there.
Enterprise customers can skip the redrawing for cloud and API systems by importing a DFD from Terraform, CloudFormation or an OpenAPI specification.
Frequently asked questions
Is the Microsoft Threat Modeling Tool discontinued?
No. Microsoft still publishes it as a free download for Windows. Releases are infrequent, though: the latest in Microsoft's release notes is version 7.3.51110.1 from November 2025, and the one before that was October 2023.
Does the Microsoft Threat Modeling Tool run on Mac or Linux?
No. It requires Windows 10 or later and .NET 4.7.1. ThreatTree runs in any modern browser, so it works on macOS, Linux, Windows and ChromeOS with nothing to install.
Can ThreatTree import .tm7 files?
Not at the moment. You redraw the data flow diagram in ThreatTree, which for a typical application takes well under an hour, then carry over the threats you'd marked as needing investigation or mitigated.
Does ThreatTree generate STRIDE threats automatically like the Microsoft tool?
No. ThreatTree doesn't generate threats from a rules library. Your team identifies threats and tags them with STRIDE, LINDDUN, OWASP Top 10, CAPEC or MITRE ATT&CK, and decomposes the important ones into attack trees. If automatic STRIDE-per-element generation is what you need most, the Microsoft tool does that well.
Is ThreatTree free?
ThreatTree has a Free plan with no credit card: up to 3 forests, 3 data flow diagrams per forest and 5 attack trees per diagram, with the risk register and risk register PDF export included. Pro is $29 per user per month and adds unlimited models, team collaboration, standards mapping and full reports.
Comparing more than two tools? Our guide to the best threat modeling software in 2026 covers ten options, free and paid. Product details for the Microsoft Threat Modeling Tool come from Microsoft's documentation and release notes, checked on October 8, 2026. Microsoft is a trademark of Microsoft Corporation, which is not affiliated with ThreatTree.