Built for ISO/SAE 21434 TARA work products

Threat Modeling
for Automotive

ISO/SAE 21434 requires a documented Threat Analysis and Risk Assessment for every item and component in scope. ThreatTree gives your cybersecurity engineering team a structured way to identify assets, decompose attack paths, rate feasibility, and produce the risk treatment evidence an assessor expects to see.

Free forever plan Scoped per ECU or full vehicle E/E architecture Export anytime, no lock-in
ISO/SAE 21434

The TARA workflow, mapped to ThreatTree

Threat Analysis and Risk Assessment moves through five stages. Each one has a direct home in a ThreatTree forest.

TARA step In ThreatTree
1 Asset identification
ECUs, buses, gateways, and the data/functions they hold
Model each component as a DFD process or data store, with trust boundaries around domains (e.g. infotainment vs. powertrain CAN)
2 Damage scenario identification
Safety, financial, operational, and privacy impact
Tag DFD nodes and attack tree goals with the impact categories your team scores against
3 Threat scenario identification
What could compromise each asset's CIA properties
STRIDE tagging on every DFD element surfaces spoofing, tampering, and DoS threats systematically, not ad hoc
4 Attack path analysis & feasibility rating
How an attacker reaches the asset, and how feasible each path is
Attack Trees decompose each threat scenario into AND/OR attack steps, linked back to the exact DFD node targeted, tagged with CAPEC and MITRE ATT&CK
5 Risk value determination & treatment
Combine impact and feasibility, decide avoid/reduce/share/accept
Likelihood x Impact scoring generates a ranked risk register automatically across the forest, exportable as a board- and audit-ready PDF

What this is, and isn't: ThreatTree is a threat modeling tool, not a certification body or a substitute for an ISO/SAE 21434-qualified assessor. It gives your team a structured place to build and evidence the TARA work products the standard describes -- feasibility ratings, CAL assignment, and risk acceptance decisions still require your cybersecurity engineers' judgment.

Why teams use ThreatTree

Built for the evidence an assessor asks for

Everything in a ThreatTree forest traces back to a component, and every risk decision traces back to a rated attack path.

  • Architecture-Anchored Assets

    Model ECUs, buses, gateways, and external interfaces as DFD elements, with trust boundaries around each vehicle domain. Every threat traces back to a real component, not a floating assumption.

  • Attack Path Decomposition

    Break each threat scenario into an Attack Tree with AND/OR logic, from attacker goal to atomic step. Score feasibility per node using your team's chosen rating method.

  • Prioritized Risk Register

    Likelihood x Impact scoring generates a ranked risk register automatically across every tree in a forest, so avoid/reduce/share/accept decisions are backed by traceable evidence.

  • Team Collaboration & RBAC

    Invite systems engineers, cybersecurity engineers, and suppliers with owner, editor, or viewer roles. One shared forest instead of TARA spreadsheets emailed between teams.

FAQ

Automotive threat modeling, answered

What automotive cybersecurity teams ask before adopting ThreatTree for TARA work.

Still have questions?

We usually reply within a day.

Get in touch
Does ThreatTree produce a certified TARA report?

No. ThreatTree helps your team build the TARA work products ISO/SAE 21434 describes -- asset and damage scenario identification, attack path analysis, feasibility and risk rating, and treatment decisions -- and export them as evidence. It is not a certification body, and the standard still requires cybersecurity engineers and assessors to exercise judgment on feasibility ratings, CAL assignment, and risk acceptance.

Which ISO/SAE 21434 attack feasibility rating method does ThreatTree support?

ThreatTree's Automotive Industry Module (Settings > Membership & Billing, Pro and Enterprise plans) adds a built-in Attack Feasibility rating on Attack Tree leaf nodes: score elapsed time, expertise, knowledge of the item, window of opportunity, and equipment, and ThreatTree computes an attack-potential-style High/Medium/Low/Very Low rating automatically. This is ThreatTree's own point scale, not a reproduction of ISO/SAE 21434 Annex G -- check the banding against your organization's TARA methodology if exact alignment matters. Prefer a different method? Likelihood x Impact scoring on every node stays method-agnostic, so you can also score using CVSS, Annex G directly, or a custom scale.

Can I use ThreatTree for a single ECU or a full vehicle E/E architecture?

Both. A forest can scope down to one ECU and its interfaces, or up to a full vehicle E/E architecture spanning multiple domains and buses -- the DFD layer and nested trust boundaries scale to either.

Can I export evidence for a supplier cybersecurity interface agreement?

Yes. Export any forest as a PDF report with the architecture, attack trees, and ranked risk register, or as JSON for programmatic use. Nothing is locked into ThreatTree's format only.

Working through a TARA? Get new threat-modeling guides by email — no more than one a week.

Start your TARA in ThreatTree

Free plan available -- no credit card required. Be up and running in minutes.