Threat Modeling Software
Features
Everything ThreatTree does, in one place: map the architecture as a data flow diagram, decompose threats into attack trees, tag them with the frameworks your team already uses, and turn them into a scored risk register and audit-ready reports.
Real screens from the app
A data flow diagram of the system, and an attack tree built against one of its components.
Map your architecture as a Data Flow Diagram
Trust boundaries, processes, data stores and external entities, including AWS, Azure and GCP-specific elements, so every threat is grounded in a real component of your system.
Decompose every threat into an Attack Tree
Break a threat down with AND/OR logic, from the attacker's goal to individual attack steps. Tag each step with STRIDE and CAPEC, and link the tree back to the DFD it targets.
Architecture first, then the attacks against it
A data flow diagram describes what the system is; attack trees describe how it could be broken. ThreatTree keeps both in one forest, linked.
-
Data Flow Diagram editor All plans
Processes, external entities, data stores and trust boundaries, plus infrastructure elements such as firewalls, WAFs, load balancers, API gateways, message queues, caches and identity providers. Data stores carry a database system and a data classification.
-
Cloud-aware trust boundaries All plans
Physical boundaries for trusted and untrusted networks, the internet and on-premise, and cloud-provider boundaries for 16 providers. AWS, Azure, GCP and OCI boundaries carry their brand colours, and AWS elements such as EC2, Lambda, RDS and S3 are built in.
-
Attack trees with AND/OR logic All plans
Start from the attacker's goal and branch through OR gates (any one path works) and AND gates (every condition is needed) down to individual attack steps. Auto Layout tidies the tree.
-
Linked DFDs and attack trees All plans
Link each attack tree to the DFD it threatens. The DFD shows how many trees target it and lets you jump straight to any of them, so the model stays traceable to the architecture.
-
Import a DFD from code Enterprise
Generate a first-draft DFD from Terraform, CloudFormation/SAM or an OpenAPI/Swagger spec, with VPCs and subnets as nested boundaries. Preview every element before it's created.
-
Keyboard-first editors All plans
Undo and redo, fit-to-view, a minimap for large diagrams, and shortcuts for every common action. Every item in the DFD palette can be placed from the keyboard.
Tag threats with the frameworks you already use
ThreatTree doesn't generate threats from a rules library. It gives your team structure to find the ones that matter for this system, using STRIDE and the other frameworks as a checklist.
-
STRIDE and LINDDUN All plans
Classify each threat as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service or Elevation of Privilege, and cover privacy threats with LINDDUN.
-
OWASP Top 10, LLM and Agentic All plans
Tag web application risks with the OWASP Top 10, and AI systems with the OWASP Top 10 for LLM Applications and for Agentic Applications.
-
CAPEC attack patterns All plans
Attach concrete, technique-level attack patterns such as SQL injection, CSRF or credential stuffing to individual attack steps.
-
MITRE ATT&CK and ATLAS All plans
Add ATT&CK technique IDs to any step; ATLAS IDs appear for AI threats. Each ID becomes a chip linking to MITRE's page for that technique.
From threats to a ranked risk register, automatically
Every scored step in every attack tree lands in one risk register per forest, with nothing to copy across.
-
Likelihood × impact scoring All plans
Score each goal and attack step from 1 to 5 on likelihood and impact. The 1–25 score maps to Low, Medium, High and Critical, with a coloured badge on the node.
-
Auto-populated register All plans
Terminal attack steps are included by default and you can override any node. The register shows score, tree, MITRE techniques and mitigation count, and filters by tree, minimum risk, owner and status.
-
Treatment plans All plans
Record each response as Mitigate, Avoid, Transfer or Accept, with a description, so accepted risks are decisions on record rather than silence.
-
Owners and collaborators All plans
Assign a risk owner and collaborators directly in the register, with autocomplete from the forest's members.
Evidence an auditor can follow
Map mitigations to the controls auditors ask about, and export reports that need no rewriting. See how this works for SOC 2 and other industries.
-
Standards controls mapping Pro
Attach controls from ISO 27001:2022, NIST SP 800-53 Rev 5, NIST CSF 2.0, CIS Controls v8, OWASP ASVS 4.0, PCI DSS v4.0 and SOC 2 to any threat.
-
Board-ready forest report Pro
One PDF with document control, an executive summary and risk posture, the ranked register, threat analysis per attack tree, architecture per DFD, controls mapping and an activity appendix, with your logo on the cover.
-
Risk register PDF All plans
Export the register as filtered, with a severity summary cover page, on every plan including Free.
-
JSON and STIX 2.1 exports Pro
JSON on every plan for backup and scripting; STIX 2.1 bundles with ATT&CK references for SIEMs and threat-intel platforms on Pro.
-
Industry Modules Pro
Extra fields, frameworks and controls for Automotive (ISO/SAE 21434), Medical Devices, Fintech, Healthcare (HIPAA), Critical Infrastructure (IEC 62443, NERC CIP) and AI & ML systems (NIST AI RMF).
-
Backup and restore Pro
Point-in-time snapshots of a whole forest. Restoring takes a safety snapshot first, so a restore is never one-way.
One model, the whole team
Architects, developers and compliance leads work on the same forest instead of passing files around.
-
Forest roles Pro
Invite people to a forest as Owner, Editor or Viewer. Only owners manage members, delete forests or change encryption.
-
Company organisations Pro
Register your company domain once and every member gets access to the organisation's forests, with Owner, Admin and Member roles and self-serve seat management.
-
Audit logs and activity Pro
See who changed what, and when, across the organisation's forests.
-
Slack and Teams alerts Pro
Get a message when a node is scored High or Critical, so new serious risks don't wait for the next review.
Built for the most sensitive document you have
A threat model is a map of where your system is weakest. Read more on the security page.
-
Client-side forest encryption All plans
Lock a forest and your browser encrypts its names, labels and properties with a fresh AES-256-GCM key. The server stores only ciphertext and never sees the key.
-
Two-factor authentication All plans
Protect every account with a second factor, alongside account lockout after repeated failed sign-ins.
-
SSO / SAML and SCIM Enterprise
Sign in through Okta, Microsoft Entra ID or any SAML 2.0 identity provider, and provision users and groups automatically with SCIM.
-
IP allowlisting, custom roles, data retention Enterprise
Restrict sign-in to your networks, define roles beyond Owner/Editor/Viewer, and set how long logs and history are kept.
Where the rest of your work happens
Push risks to the tools your teams already use, and keep diagrams current wherever they're documented.
-
Two-way ticketing sync Enterprise
Open tickets in Jira, ServiceNow, Linear or Azure DevOps when a risk is scored High or Critical, and mark it mitigated in the register when every linked ticket closes.
-
SIEM feed Enterprise
Push a STIX 2.1 feed of every forest to Splunk on a schedule.
-
GRC evidence sync Enterprise
Send risk register evidence to Vanta or Drata weekly or monthly.
-
Live Confluence and Notion embeds Enterprise
Embed a read-only, always-current diagram in your documentation instead of pasting screenshots.
What's included in each plan
The Free plan is fully featured for modeling, just capped in size. See pricing for the full details.
| Feature | Free | Pro | Enterprise |
|---|---|---|---|
| Forests (systems) | 3 | Unlimited | Unlimited |
| DFDs per forest / attack trees per DFD | 3 / 5 | Unlimited | Unlimited |
| Data flow diagrams, attack trees, risk register | ✓ | ✓ | ✓ |
| STRIDE, LINDDUN, OWASP Top 10, CAPEC, MITRE ATT&CK | ✓ | ✓ | ✓ |
| Client-side AES-256-GCM encryption | ✓ | ✓ | ✓ |
| Risk register PDF and JSON export | ✓ | ✓ | ✓ |
| Compliance standards mapping | — | ✓ | ✓ |
| Team collaboration and organisations | — | ✓ | ✓ |
| Board-ready forest PDF report, STIX 2.1 export | — | ✓ | ✓ |
| Backup & restore snapshots, audit logs | — | ✓ | ✓ |
| Industry Modules | — | ✓ | ✓ |
| Slack and Teams critical-risk alerts | — | ✓ | ✓ |
| SSO / SAML, SCIM, IP allowlisting, custom roles | — | — | ✓ |
| Import DFDs from Terraform, CloudFormation, OpenAPI | — | — | ✓ |
| Jira, ServiceNow, Linear, Azure DevOps sync | — | — | ✓ |
| Splunk feed, Vanta and Drata evidence sync | — | — | ✓ |
| Live Confluence and Notion embeds | — | — | ✓ |
| Price | $0 | $29/user/mo | On request |
Features, answered
What teams ask before choosing ThreatTree.
Is ThreatTree free?
Yes. The Free plan needs no credit card and includes data flow diagrams, attack trees, STRIDE, LINDDUN, OWASP, CAPEC and MITRE ATT&CK tagging, the risk register with PDF export, and client-side encryption, for up to 3 forests. Pro is $29 per user per month.
Does ThreatTree generate threats automatically?
No. ThreatTree doesn't generate threats from a rules library. Your team identifies them with STRIDE and the other frameworks as a checklist, and decomposes the important ones into attack trees. That takes more thought than a generated list, and produces threats specific to your system.
Which compliance standards can I map to?
On Pro and Enterprise: ISO 27001:2022, NIST SP 800-53 Rev 5, NIST CSF 2.0, CIS Controls v8, OWASP ASVS 4.0, PCI DSS v4.0 and SOC 2. Industry Modules add ISO/SAE 21434, HIPAA, IEC 62443, NERC CIP and NIST AI RMF.
Do I need to install anything?
No. ThreatTree runs in any modern browser on Windows, macOS, Linux or ChromeOS.
Can I get my data out?
Yes. Export any diagram as JSON at any time on every plan, and the risk register as a PDF. Pro adds the full forest report and STIX 2.1. See how we protect your data.
See every feature on a real system
Free plan available — no credit card required. Be up and running in minutes.