Threat Modeling – From Concept to Countermeasure
A hands-on course on threat modeling: why it pays off, what it is, how the process works, which methods exist (with a focus on STRIDE), a fully worked practical example, and the transition into risk management. Note: This course is voiced by AI voices (AI narrated).
What you'll learn
- Be able to justify the value of threat modeling
- Define threat modeling and know Shostack's four questions
- Apply the generic process and STRIDE
- Model and assess threats using an example
- Understand the transition into risk management
Tags
securitythreat-modelingstrideeacgAI narrated
Module 01 - Why Threat Modeling? ▶
- ▶ Introduction 1:56
- ▶ Why Threat Modeling Pays Off 7:32
- ? Quick check
Module 02 - What is Threat Modeling? ▶
- ▶ What is Threat Modeling? 0:13
- ▶ What Threat Modeling Actually Is 6:14
- ? The four questions
Module 03 - How Do You Do Threat Modeling? ▶
- ▶ How Do You Do Threat Modeling? 0:14
- ▶ The Process in Five Steps 5:15
- ? Order the five steps
Module 04 - STRIDE & Methods ▶
- ▶ STRIDE & Methods 0:13
- ▶ Finding Threats Systematically with STRIDE 8:56
- ? STRIDE ↔ security goal
Module 05 - Show Me – a Practical Example ▶
- ▶ Show Me – a Practical Example 0:15
- ▶ Threat Modeling on a Kubernetes Cluster 8:31
- ? Security vs. delivery date
Module 06 - Did We Do It Well? & Transition ▶
- ▶ Did We Do It Well? & Transition 0:15
- ▶ Checking, Handing Over, and Anchoring It in the Team 7:14
- ? Review & risk management
- ▶ Take-home messages 0:52