Free plan available — no credit card required

Threat Modeling Software
Features

Everything ThreatTree does, in one place: map the architecture as a data flow diagram, decompose threats into attack trees, tag them with the frameworks your team already uses, and turn them into a scored risk register and audit-ready reports.

Free forever plan Runs in any browser Export anytime, no lock-in
Product tour

Real screens from the app

A data flow diagram of the system, and an attack tree built against one of its components.

Map your architecture as a Data Flow Diagram

Trust boundaries, processes, data stores and external entities, including AWS, Azure and GCP-specific elements, so every threat is grounded in a real component of your system.

A Data Flow Diagram in ThreatTree: an AWS trust boundary containing a nested Private Subnet with Amazon EC2 and Amazon RDS nodes connected by a labeled data flow, linked to 3 Attack Trees, next to an on-premise SQL Server database and a site-to-site VPN link

Decompose every threat into an Attack Tree

Break a threat down with AND/OR logic, from the attacker's goal to individual attack steps. Tag each step with STRIDE and CAPEC, and link the tree back to the DFD it targets.

A finished Attack Tree in ThreatTree: the goal 'Exfiltrate Customer Data from Amazon RDS' broken down through an OR gate into three attack steps, each tagged with STRIDE, CAPEC, and OWASP Top 10 categories
Modeling

Architecture first, then the attacks against it

A data flow diagram describes what the system is; attack trees describe how it could be broken. ThreatTree keeps both in one forest, linked.

  • Data Flow Diagram editor All plans

    Processes, external entities, data stores and trust boundaries, plus infrastructure elements such as firewalls, WAFs, load balancers, API gateways, message queues, caches and identity providers. Data stores carry a database system and a data classification.

  • Cloud-aware trust boundaries All plans

    Physical boundaries for trusted and untrusted networks, the internet and on-premise, and cloud-provider boundaries for 16 providers. AWS, Azure, GCP and OCI boundaries carry their brand colours, and AWS elements such as EC2, Lambda, RDS and S3 are built in.

  • Attack trees with AND/OR logic All plans

    Start from the attacker's goal and branch through OR gates (any one path works) and AND gates (every condition is needed) down to individual attack steps. Auto Layout tidies the tree.

  • Linked DFDs and attack trees All plans

    Link each attack tree to the DFD it threatens. The DFD shows how many trees target it and lets you jump straight to any of them, so the model stays traceable to the architecture.

  • Import a DFD from code Enterprise

    Generate a first-draft DFD from Terraform, CloudFormation/SAM or an OpenAPI/Swagger spec, with VPCs and subnets as nested boundaries. Preview every element before it's created.

  • Keyboard-first editors All plans

    Undo and redo, fit-to-view, a minimap for large diagrams, and shortcuts for every common action. Every item in the DFD palette can be placed from the keyboard.

Frameworks

Tag threats with the frameworks you already use

ThreatTree doesn't generate threats from a rules library. It gives your team structure to find the ones that matter for this system, using STRIDE and the other frameworks as a checklist.

  • STRIDE and LINDDUN All plans

    Classify each threat as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service or Elevation of Privilege, and cover privacy threats with LINDDUN.

  • OWASP Top 10, LLM and Agentic All plans

    Tag web application risks with the OWASP Top 10, and AI systems with the OWASP Top 10 for LLM Applications and for Agentic Applications.

  • CAPEC attack patterns All plans

    Attach concrete, technique-level attack patterns such as SQL injection, CSRF or credential stuffing to individual attack steps.

  • MITRE ATT&CK and ATLAS All plans

    Add ATT&CK technique IDs to any step; ATLAS IDs appear for AI threats. Each ID becomes a chip linking to MITRE's page for that technique.

Risk register

From threats to a ranked risk register, automatically

Every scored step in every attack tree lands in one risk register per forest, with nothing to copy across.

  • Likelihood × impact scoring All plans

    Score each goal and attack step from 1 to 5 on likelihood and impact. The 1–25 score maps to Low, Medium, High and Critical, with a coloured badge on the node.

  • Auto-populated register All plans

    Terminal attack steps are included by default and you can override any node. The register shows score, tree, MITRE techniques and mitigation count, and filters by tree, minimum risk, owner and status.

  • Treatment plans All plans

    Record each response as Mitigate, Avoid, Transfer or Accept, with a description, so accepted risks are decisions on record rather than silence.

  • Owners and collaborators All plans

    Assign a risk owner and collaborators directly in the register, with autocomplete from the forest's members.

Compliance & reports

Evidence an auditor can follow

Map mitigations to the controls auditors ask about, and export reports that need no rewriting. See how this works for SOC 2 and other industries.

  • Standards controls mapping Pro

    Attach controls from ISO 27001:2022, NIST SP 800-53 Rev 5, NIST CSF 2.0, CIS Controls v8, OWASP ASVS 4.0, PCI DSS v4.0 and SOC 2 to any threat.

  • Board-ready forest report Pro

    One PDF with document control, an executive summary and risk posture, the ranked register, threat analysis per attack tree, architecture per DFD, controls mapping and an activity appendix, with your logo on the cover.

  • Risk register PDF All plans

    Export the register as filtered, with a severity summary cover page, on every plan including Free.

  • JSON and STIX 2.1 exports Pro

    JSON on every plan for backup and scripting; STIX 2.1 bundles with ATT&CK references for SIEMs and threat-intel platforms on Pro.

  • Industry Modules Pro

    Extra fields, frameworks and controls for Automotive (ISO/SAE 21434), Medical Devices, Fintech, Healthcare (HIPAA), Critical Infrastructure (IEC 62443, NERC CIP) and AI & ML systems (NIST AI RMF).

  • Backup and restore Pro

    Point-in-time snapshots of a whole forest. Restoring takes a safety snapshot first, so a restore is never one-way.

Collaboration

One model, the whole team

Architects, developers and compliance leads work on the same forest instead of passing files around.

  • Forest roles Pro

    Invite people to a forest as Owner, Editor or Viewer. Only owners manage members, delete forests or change encryption.

  • Company organisations Pro

    Register your company domain once and every member gets access to the organisation's forests, with Owner, Admin and Member roles and self-serve seat management.

  • Audit logs and activity Pro

    See who changed what, and when, across the organisation's forests.

  • Slack and Teams alerts Pro

    Get a message when a node is scored High or Critical, so new serious risks don't wait for the next review.

Security

Built for the most sensitive document you have

A threat model is a map of where your system is weakest. Read more on the security page.

  • Client-side forest encryption All plans

    Lock a forest and your browser encrypts its names, labels and properties with a fresh AES-256-GCM key. The server stores only ciphertext and never sees the key.

  • Two-factor authentication All plans

    Protect every account with a second factor, alongside account lockout after repeated failed sign-ins.

  • SSO / SAML and SCIM Enterprise

    Sign in through Okta, Microsoft Entra ID or any SAML 2.0 identity provider, and provision users and groups automatically with SCIM.

  • IP allowlisting, custom roles, data retention Enterprise

    Restrict sign-in to your networks, define roles beyond Owner/Editor/Viewer, and set how long logs and history are kept.

Integrations

Where the rest of your work happens

Push risks to the tools your teams already use, and keep diagrams current wherever they're documented.

  • Two-way ticketing sync Enterprise

    Open tickets in Jira, ServiceNow, Linear or Azure DevOps when a risk is scored High or Critical, and mark it mitigated in the register when every linked ticket closes.

  • SIEM feed Enterprise

    Push a STIX 2.1 feed of every forest to Splunk on a schedule.

  • GRC evidence sync Enterprise

    Send risk register evidence to Vanta or Drata weekly or monthly.

  • Live Confluence and Notion embeds Enterprise

    Embed a read-only, always-current diagram in your documentation instead of pasting screenshots.

By plan

What's included in each plan

The Free plan is fully featured for modeling, just capped in size. See pricing for the full details.

FeatureFreeProEnterprise
Forests (systems)3UnlimitedUnlimited
DFDs per forest / attack trees per DFD3 / 5UnlimitedUnlimited
Data flow diagrams, attack trees, risk register✓✓✓
STRIDE, LINDDUN, OWASP Top 10, CAPEC, MITRE ATT&CK✓✓✓
Client-side AES-256-GCM encryption✓✓✓
Risk register PDF and JSON export✓✓✓
Compliance standards mapping—✓✓
Team collaboration and organisations—✓✓
Board-ready forest PDF report, STIX 2.1 export—✓✓
Backup & restore snapshots, audit logs—✓✓
Industry Modules—✓✓
Slack and Teams critical-risk alerts—✓✓
SSO / SAML, SCIM, IP allowlisting, custom roles——✓
Import DFDs from Terraform, CloudFormation, OpenAPI——✓
Jira, ServiceNow, Linear, Azure DevOps sync——✓
Splunk feed, Vanta and Drata evidence sync——✓
Live Confluence and Notion embeds——✓
Price$0$29/user/moOn request
FAQ

Features, answered

What teams ask before choosing ThreatTree.

Still have questions?

We usually reply within a day.

Get in touch
Is ThreatTree free?

Yes. The Free plan needs no credit card and includes data flow diagrams, attack trees, STRIDE, LINDDUN, OWASP, CAPEC and MITRE ATT&CK tagging, the risk register with PDF export, and client-side encryption, for up to 3 forests. Pro is $29 per user per month.

Does ThreatTree generate threats automatically?

No. ThreatTree doesn't generate threats from a rules library. Your team identifies them with STRIDE and the other frameworks as a checklist, and decomposes the important ones into attack trees. That takes more thought than a generated list, and produces threats specific to your system.

Which compliance standards can I map to?

On Pro and Enterprise: ISO 27001:2022, NIST SP 800-53 Rev 5, NIST CSF 2.0, CIS Controls v8, OWASP ASVS 4.0, PCI DSS v4.0 and SOC 2. Industry Modules add ISO/SAE 21434, HIPAA, IEC 62443, NERC CIP and NIST AI RMF.

Do I need to install anything?

No. ThreatTree runs in any modern browser on Windows, macOS, Linux or ChromeOS.

Can I get my data out?

Yes. Export any diagram as JSON at any time on every plan, and the risk register as a PDF. Pro adds the full forest report and STIX 2.1. See how we protect your data.

See every feature on a real system

Free plan available — no credit card required. Be up and running in minutes.