<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ThreatTree Blog</title>
    <link>https://threattree.com/blog/</link>
    <description>Threat modeling guides, framework explainers, and practical how-tos from the ThreatTree team.</description>
    <language>en</language>
    <lastBuildDate>Mon, 24 Aug 2026 16:25:03 +0000</lastBuildDate>
    <atom:link href="https://threattree.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How to Threat Model a Microservices Architecture</title>
      <link>https://threattree.com/blog/how-to-threat-model-a-microservices-architecture</link>
      <guid isPermaLink="true">https://threattree.com/blog/how-to-threat-model-a-microservices-architecture</guid>
      <description>Microservices move the interesting threats into the gaps between services. How to scope by request path, draw the right DFD, and adapt the STRIDE sweep.</description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>How to Run Your First Threat Modeling Workshop</title>
      <link>https://threattree.com/blog/how-to-run-your-first-threat-modeling-workshop</link>
      <guid isPermaLink="true">https://threattree.com/blog/how-to-run-your-first-threat-modeling-workshop</guid>
      <description>A practical playbook for a first threat modeling workshop: what to prepare, who to invite, a 90-minute agenda, and what you must leave the room holding.</description>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>What Is Defense in Depth?</title>
      <link>https://threattree.com/blog/what-is-defense-in-depth</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-defense-in-depth</guid>
      <description>Defense in depth means no single control failure is fatal. How the layers work, why five firewalls isn&#x27;t depth, and how attack trees make it measurable.</description>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is Attack Surface?</title>
      <link>https://threattree.com/blog/what-is-attack-surface</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-attack-surface</guid>
      <description>Attack surface is every point an attacker could get in or get data out. How to measure it, why it grows unnoticed, and how a DFD doubles as an inventory.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is Zero Trust Architecture?</title>
      <link>https://threattree.com/blog/what-is-zero-trust-architecture</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-zero-trust-architecture</guid>
      <description>Zero Trust means never trusting a request based on network location alone. Here&#x27;s what that changes about how you draw trust boundaries in a threat model.</description>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Are TTPs?</title>
      <link>https://threattree.com/blog/what-are-ttps</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-are-ttps</guid>
      <description>TTPs — Tactics, Techniques, and Procedures — describe how an adversary operates, at three levels of specificity, and why they outlast an IP or file hash.</description>
      <pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is a Threat Actor?</title>
      <link>https://threattree.com/blog/what-is-a-threat-actor</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-a-threat-actor</guid>
      <description>A threat actor is whoever might attack your system — nation-state, cybercriminal, insider, hacktivist — and why naming them first changes the whole model.</description>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is the OWASP Top 10?</title>
      <link>https://threattree.com/blog/what-is-the-owasp-top-10</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-the-owasp-top-10</guid>
      <description>The OWASP Top 10 ranks the ten most critical web app risks. How to use the 2021 edition as a threat modeling checklist, not just a pentest scorecard.</description>
      <pubDate>Mon, 17 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is CAPEC?</title>
      <link>https://threattree.com/blog/what-is-capec</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-capec</guid>
      <description>CAPEC is MITRE&#x27;s catalog of documented attack patterns — the standard vocabulary for how attackers exploit a weakness, and a source for attack tree leaf nodes.</description>
      <pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is DREAD?</title>
      <link>https://threattree.com/blog/what-is-dread</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-dread</guid>
      <description>DREAD is Microsoft&#x27;s five-factor threat-scoring model — Damage, Reproducibility, Exploitability, Affected Users, Discoverability — and why teams moved to CVSS.</description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is PASTA?</title>
      <link>https://threattree.com/blog/what-is-pasta</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-pasta</guid>
      <description>PASTA is a seven-stage, risk-centric threat modeling process that ties technical threats to business impact, and when to use it over STRIDE.</description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is LINDDUN?</title>
      <link>https://threattree.com/blog/what-is-linddun</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-linddun</guid>
      <description>LINDDUN is a privacy-focused threat modeling framework — seven categories for finding privacy risks that STRIDE&#x27;s security-only lens misses.</description>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is STRIDE?</title>
      <link>https://threattree.com/blog/what-is-stride</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-stride</guid>
      <description>STRIDE is Microsoft&#x27;s six-category threat framework — Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege — explained.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is MITRE ATT&amp;CK?</title>
      <link>https://threattree.com/blog/what-is-mitre-attack</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-mitre-attack</guid>
      <description>MITRE ATT&amp;CK is a knowledge base of adversary tactics and techniques, organized into a matrix. How it differs from STRIDE, and how to map to it.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is CVSS?</title>
      <link>https://threattree.com/blog/what-is-cvss</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-cvss</guid>
      <description>CVSS rates vulnerability severity 0-10 using exploitability and impact metrics. How it&#x27;s calculated, and its key limitation for risk prioritization.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is an Attack Tree?</title>
      <link>https://threattree.com/blog/what-is-an-attack-tree</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-an-attack-tree</guid>
      <description>An attack tree breaks a high-level attacker goal into concrete, ordered attack steps using AND/OR logic, with a worked example.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is a Trust Boundary?</title>
      <link>https://threattree.com/blog/what-is-a-trust-boundary</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-a-trust-boundary</guid>
      <description>A trust boundary marks the point where data crosses between zones of differing trust — where most real vulnerabilities live.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is a Risk Register?</title>
      <link>https://threattree.com/blog/what-is-a-risk-register</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-a-risk-register</guid>
      <description>A risk register is a living record of identified risks — each scored, owned, and tracked to mitigation, not a raw list of threats.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>What Is a Data Flow Diagram (DFD)?</title>
      <link>https://threattree.com/blog/what-is-a-data-flow-diagram</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-a-data-flow-diagram</guid>
      <description>A Data Flow Diagram (DFD) maps how data moves through a system — processes, data stores, external entities, and trust boundaries.</description>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <category>Glossary</category>
    </item>
    <item>
      <title>Threat Modeling for AI Agents and LLM Applications: A Practical Guide</title>
      <link>https://threattree.com/blog/threat-modeling-ai-agents</link>
      <guid isPermaLink="true">https://threattree.com/blog/threat-modeling-ai-agents</guid>
      <description>Why STRIDE and classic DFDs fall short for AI systems, the new trust boundaries agentic apps introduce, and a worked OWASP LLM Top 10 + MITRE ATLAS example.</description>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>Why Your Risk Register Needs to Speak ISO 27001 — And How Threat Modeling Gets You There</title>
      <link>https://threattree.com/blog/threat-model-iso27001-risk-register</link>
      <guid isPermaLink="true">https://threattree.com/blog/threat-model-iso27001-risk-register</guid>
      <description>ISO 27001&#x27;s risk clause is methodology-neutral. Here&#x27;s how threat modeling fills that gap with a register auditors and security teams can both use.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate>
      <category>Compliance</category>
    </item>
    <item>
      <title>Closing the SOC 2 Evidence Gap: Threat Models as Living Compliance Documentation</title>
      <link>https://threattree.com/blog/soc2-threat-model-compliance-evidence</link>
      <guid isPermaLink="true">https://threattree.com/blog/soc2-threat-model-compliance-evidence</guid>
      <description>SOC 2 auditors want continuous evidence of risk management, not a yearly spreadsheet. Here&#x27;s how living threat models satisfy TSC CC3.2, CC3.3, and CC9.2.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate>
      <category>Compliance</category>
    </item>
    <item>
      <title>The CVSS Trap: Why Vulnerability Severity Scores Break Down In Your Environment</title>
      <link>https://threattree.com/blog/cvss-scores-vs-threat-model-risk</link>
      <guid isPermaLink="true">https://threattree.com/blog/cvss-scores-vs-threat-model-risk</guid>
      <description>CVSS measures generic exploitability, not risk in your architecture. Here&#x27;s why it misleads patch prioritisation — and how threat models fix that.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate>
      <category>Opinion</category>
    </item>
    <item>
      <title>What is Threat Modeling and Why Does It Matter?</title>
      <link>https://threattree.com/blog/what-is-threat-modeling</link>
      <guid isPermaLink="true">https://threattree.com/blog/what-is-threat-modeling</guid>
      <description>A plain-language guide to threat modeling: what it is, why every team needs it, and how to get started with STRIDE, PASTA, and LINDDUN.</description>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>From Threat Model to Risk Register — Closing the Loop with ThreatTree</title>
      <link>https://threattree.com/blog/threat-model-to-risk-register</link>
      <guid isPermaLink="true">https://threattree.com/blog/threat-model-to-risk-register</guid>
      <description>How to turn a completed threat model into an actionable risk register, prioritise by severity, and keep it alive as your system evolves.</description>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>How to Build a Data Flow Diagram (DFD) for Threat Modeling</title>
      <link>https://threattree.com/blog/how-to-build-a-dfd</link>
      <guid isPermaLink="true">https://threattree.com/blog/how-to-build-a-dfd</guid>
      <description>Step-by-step guide to drawing a DFD for threat modeling: processes, data stores, trust boundaries, and how they map to STRIDE categories.</description>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <category>Guides</category>
    </item>
  </channel>
</rss>
