Built for ISO/SAE 21434 TARA work products

Threat Modeling
for Automotive

ISO/SAE 21434 requires a documented Threat Analysis and Risk Assessment for every item and component in scope. ThreatTree gives your cybersecurity engineering team a structured way to identify assets, decompose attack paths, rate feasibility, and produce the risk treatment evidence an assessor expects to see.

Free forever plan Scoped per ECU or full vehicle E/E architecture Export anytime, no lock-in
ISO/SAE 21434

The TARA workflow, mapped to ThreatTree

Threat Analysis and Risk Assessment moves through five stages. Each one has a direct home in a ThreatTree forest.

TARA step In ThreatTree
1 Asset identification
ECUs, buses, gateways, and the data/functions they hold
Model each component as a DFD process or data store, with trust boundaries around domains (e.g. infotainment vs. powertrain CAN)
2 Damage scenario identification
Safety, financial, operational, and privacy impact
Tag DFD nodes and attack tree goals with the impact categories your team scores against
3 Threat scenario identification
What could compromise each asset's CIA properties
STRIDE tagging on every DFD element surfaces spoofing, tampering, and DoS threats systematically, not ad hoc
4 Attack path analysis & feasibility rating
How an attacker reaches the asset, and how feasible each path is
Attack Trees decompose each threat scenario into AND/OR attack steps, linked back to the exact DFD node targeted, tagged with CAPEC and MITRE ATT&CK
5 Risk value determination & treatment
Combine impact and feasibility, decide avoid/reduce/share/accept
Likelihood x Impact scoring generates a ranked risk register automatically across the forest, exportable as a board- and audit-ready PDF

What this is, and isn't: ThreatTree is a threat modeling tool, not a certification body or a substitute for an ISO/SAE 21434-qualified assessor. It gives your team a structured place to build and evidence the TARA work products the standard describes -- feasibility ratings, CAL assignment, and risk acceptance decisions still require your cybersecurity engineers' judgment.

Why teams use ThreatTree

Built for the evidence an assessor asks for

Everything in a ThreatTree forest traces back to a component, and every risk decision traces back to a rated attack path.

  • Architecture-Anchored Assets

    Model ECUs, buses, gateways, and external interfaces as DFD elements, with trust boundaries around each vehicle domain. Every threat traces back to a real component, not a floating assumption.

  • Attack Path Decomposition

    Break each threat scenario into an Attack Tree with AND/OR logic, from attacker goal to atomic step. Score feasibility per node using your team's chosen rating method.

  • Prioritized Risk Register

    Likelihood x Impact scoring generates a ranked risk register automatically across every tree in a forest, so avoid/reduce/share/accept decisions are backed by traceable evidence.

  • Team Collaboration & RBAC

    Invite systems engineers, cybersecurity engineers, and suppliers with owner, editor, or viewer roles. One shared forest instead of TARA spreadsheets emailed between teams.

FAQ

Automotive threat modeling, answered

What automotive cybersecurity teams ask before adopting ThreatTree for TARA work.

Still have questions?

We usually reply within a day.

Get in touch
Does ThreatTree produce a certified TARA report?

No. ThreatTree helps your team build the TARA work products ISO/SAE 21434 describes -- asset and damage scenario identification, attack path analysis, feasibility and risk rating, and treatment decisions -- and export them as evidence. It is not a certification body, and the standard still requires cybersecurity engineers and assessors to exercise judgment on feasibility ratings, CAL assignment, and risk acceptance.

Which ISO/SAE 21434 attack feasibility rating method does ThreatTree support?

ThreatTree's Likelihood x Impact scoring is method-agnostic: score each attack tree node using your team's chosen approach (CVSS-based, attack potential-based per Annex G, or a custom scale) and the resulting risk register reflects that scoring. ThreatTree does not compute the rating for you.

Can I use ThreatTree for a single ECU or a full vehicle E/E architecture?

Both. A forest can scope down to one ECU and its interfaces, or up to a full vehicle E/E architecture spanning multiple domains and buses -- the DFD layer and nested trust boundaries scale to either.

Can I export evidence for a supplier cybersecurity interface agreement?

Yes. Export any forest as a PDF report with the architecture, attack trees, and ranked risk register, or as JSON for programmatic use. Nothing is locked into ThreatTree's format only.

Start your TARA in ThreatTree

Free plan available -- no credit card required. Be up and running in minutes.