Threat Modeling
for Automotive
ISO/SAE 21434 requires a documented Threat Analysis and Risk Assessment for every item and component in scope. ThreatTree gives your cybersecurity engineering team a structured way to identify assets, decompose attack paths, rate feasibility, and produce the risk treatment evidence an assessor expects to see.
The TARA workflow, mapped to ThreatTree
Threat Analysis and Risk Assessment moves through five stages. Each one has a direct home in a ThreatTree forest.
| TARA step | In ThreatTree | |
|---|---|---|
| 1 | Asset identification ECUs, buses, gateways, and the data/functions they hold |
Model each component as a DFD process or data store, with trust boundaries around domains (e.g. infotainment vs. powertrain CAN) |
| 2 | Damage scenario identification Safety, financial, operational, and privacy impact |
Tag DFD nodes and attack tree goals with the impact categories your team scores against |
| 3 | Threat scenario identification What could compromise each asset's CIA properties |
STRIDE tagging on every DFD element surfaces spoofing, tampering, and DoS threats systematically, not ad hoc |
| 4 | Attack path analysis & feasibility rating How an attacker reaches the asset, and how feasible each path is |
Attack Trees decompose each threat scenario into AND/OR attack steps, linked back to the exact DFD node targeted, tagged with CAPEC and MITRE ATT&CK |
| 5 | Risk value determination & treatment Combine impact and feasibility, decide avoid/reduce/share/accept |
Likelihood x Impact scoring generates a ranked risk register automatically across the forest, exportable as a board- and audit-ready PDF |
What this is, and isn't: ThreatTree is a threat modeling tool, not a certification body or a substitute for an ISO/SAE 21434-qualified assessor. It gives your team a structured place to build and evidence the TARA work products the standard describes -- feasibility ratings, CAL assignment, and risk acceptance decisions still require your cybersecurity engineers' judgment.
Built for the evidence an assessor asks for
Everything in a ThreatTree forest traces back to a component, and every risk decision traces back to a rated attack path.
-
Architecture-Anchored Assets
Model ECUs, buses, gateways, and external interfaces as DFD elements, with trust boundaries around each vehicle domain. Every threat traces back to a real component, not a floating assumption.
-
Attack Path Decomposition
Break each threat scenario into an Attack Tree with AND/OR logic, from attacker goal to atomic step. Score feasibility per node using your team's chosen rating method.
-
Prioritized Risk Register
Likelihood x Impact scoring generates a ranked risk register automatically across every tree in a forest, so avoid/reduce/share/accept decisions are backed by traceable evidence.
-
Team Collaboration & RBAC
Invite systems engineers, cybersecurity engineers, and suppliers with owner, editor, or viewer roles. One shared forest instead of TARA spreadsheets emailed between teams.
Automotive threat modeling, answered
What automotive cybersecurity teams ask before adopting ThreatTree for TARA work.
Does ThreatTree produce a certified TARA report?
No. ThreatTree helps your team build the TARA work products ISO/SAE 21434 describes -- asset and damage scenario identification, attack path analysis, feasibility and risk rating, and treatment decisions -- and export them as evidence. It is not a certification body, and the standard still requires cybersecurity engineers and assessors to exercise judgment on feasibility ratings, CAL assignment, and risk acceptance.
Which ISO/SAE 21434 attack feasibility rating method does ThreatTree support?
ThreatTree's Likelihood x Impact scoring is method-agnostic: score each attack tree node using your team's chosen approach (CVSS-based, attack potential-based per Annex G, or a custom scale) and the resulting risk register reflects that scoring. ThreatTree does not compute the rating for you.
Can I use ThreatTree for a single ECU or a full vehicle E/E architecture?
Both. A forest can scope down to one ECU and its interfaces, or up to a full vehicle E/E architecture spanning multiple domains and buses -- the DFD layer and nested trust boundaries scale to either.
Can I export evidence for a supplier cybersecurity interface agreement?
Yes. Export any forest as a PDF report with the architecture, attack trees, and ranked risk register, or as JSON for programmatic use. Nothing is locked into ThreatTree's format only.
Start your TARA in ThreatTree
Free plan available -- no credit card required. Be up and running in minutes.