OWASP Threat Dragon and ThreatTree both start from the same place: draw a data flow diagram of the system, then work out what could go wrong with each part of it. Both are free to start, and neither generates threats from a rules library; your team does the thinking. They differ in what happens after that, and in who runs the software.
Threat Dragon is free, open-source software that you run yourself, with models stored as JSON files in your own repositories. ThreatTree is a hosted product that adds attack trees, a scored risk register, standards mapping and team collaboration. Here's how to decide.
The short version: choose Threat Dragon if you want open source, models versioned in Git next to the code, and no cost at any scale. Choose ThreatTree if you want to break threats down into attack trees, see every risk scored in one register, map mitigations to compliance standards, and work on shared models with your team without managing files.
Side by side
| OWASP Threat Dragon | ThreatTree | |
|---|---|---|
| Licence and price | Open source (Apache 2.0), free | Commercial; Free plan, Pro $29/user/month |
| Runs on | Self-hosted web app, or desktop app for Windows, macOS and Linux | Hosted, in any modern browser |
| Where models live | JSON files, locally or in GitHub, GitLab, Bitbucket or Google Drive | Your ThreatTree account, with optional client-side AES-256-GCM encryption |
| Working together | Through Git: commits, branches and pull requests | Shared models with Owner, Editor and Viewer roles, and company-wide organisations (Pro) |
| Diagram | DFD with processes, stores, actors, flows and trust boundaries | DFD plus cloud-provider trust boundaries and infrastructure elements (WAF, API gateway, queue, identity provider and more) |
| Threat categories | STRIDE, LINDDUN, CIA, CIA-DIE, PLOT4ai | STRIDE, LINDDUN, OWASP Top 10, OWASP LLM and Agentic Top 10, CAPEC, plus MITRE ATT&CK and ATLAS IDs |
| Attack trees | No | Yes, with AND/OR gates, linked to the DFD |
| Scoring | Severity, plus a free-text score field | Likelihood × impact (1–25) with severity bands |
| Risk register across models | No; threats live inside each model | Yes, built automatically for each forest, with owners and filters |
| Treatment | Status: mitigated, accepted, transferred, avoided, eliminated | Treatment plans: mitigate, avoid, transfer, accept |
| Standards mapping | No | ISO 27001:2022, NIST SP 800-53, NIST CSF 2.0, CIS v8, ASVS, PCI DSS v4.0, SOC 2 (Pro) |
| Reports and exports | Printable report; JSON model | Risk register PDF and JSON (all plans); forest PDF report and STIX 2.1 (Pro) |
| AI assistance | Separate community tool generates STRIDE threats using your own LLM API key | None built in |
| Support | Community, through OWASP and GitHub | Email support; priority support on Pro |
Where Threat Dragon is the better choice
- You need open source. Some organisations require it, and Threat Dragon is Apache 2.0, with OWASP Production status and regular releases (2.6.2 shipped in May 2026).
- You want models in Git. Storing the threat model in the same repository as the code means it's reviewed in pull requests and versioned with the system it describes.
- You want to self-host or work offline. The desktop app keeps everything on your own machine.
- You need CIA, CIA-DIE or PLOT4ai categories, which ThreatTree doesn't offer.
- Budget is zero at any scale. Threat Dragon costs nothing however many people use it. ThreatTree's Free plan is single-user and capped at three forests.
Where ThreatTree is the better choice
- You want to see how attacks combine. A flat list per element can't show that an attacker needs a phished password and a missing MFA prompt, or that one control breaks three paths. Attack trees can.
- You need one view of risk. ThreatTree collects every scored threat across a system's attack trees into a single risk register, with owners and filters, so you can prioritise without opening each model.
- Auditors read your output. Mapping each mitigation to ISO 27001, NIST, PCI DSS or SOC 2 controls, and exporting a structured PDF, saves rewriting the model into an audit document.
- Not everyone uses Git. Architects, product owners and compliance leads can work on a shared model with the right role, without learning to branch and merge JSON.
- You don't want to run it. No server to host, patch or back up.
Using both
Some teams do both: developers keep a lightweight Threat Dragon model in each repository, and the security team keeps a ThreatTree forest per system for the attack trees, register and reporting. If you do this, treat ThreatTree as the place risk decisions are recorded, so there's one answer to "which risks did we accept, and who decided?"
Moving from Threat Dragon to ThreatTree
ThreatTree doesn't import Threat Dragon's JSON format, so you redraw the DFD, which for most models is quicker than it sounds. Then turn each open or mitigated threat into an attack tree leaf with the same STRIDE or LINDDUN tag, record the mitigation as a treatment plan, and score it. The register builds itself from there.
Frequently asked questions
Is OWASP Threat Dragon free?
Yes. Threat Dragon is free, open-source software under the Apache 2.0 licence. You run the web app yourself or install the desktop app on Windows, macOS or Linux.
Is ThreatTree open source?
No. ThreatTree is a hosted commercial product with a Free plan. If open source or self-hosting is a requirement, Threat Dragon is the better fit.
Does Threat Dragon support attack trees?
No. Threat Dragon attaches threats to elements of a data flow diagram. ThreatTree supports both: a data flow diagram of the system and attack trees with AND/OR gates linked to it.
Can I import Threat Dragon models into ThreatTree?
Not directly. You redraw the data flow diagram in ThreatTree, then turn each open or mitigated threat into an attack tree leaf with the same STRIDE or LINDDUN category.
Can I use Threat Dragon and ThreatTree together?
Yes. Some teams keep a lightweight Threat Dragon model in each code repository and use ThreatTree for attack trees, the risk register and reporting. Record risk decisions in one place so there's a single answer to which risks were accepted and by whom.
Looking at more options? See our guide to the best threat modeling software in 2026. Threat Dragon details come from the project's documentation and GitHub releases, checked on October 8, 2026. OWASP and Threat Dragon are names of the OWASP Foundation, which is not affiliated with ThreatTree.