← All courses

Threat Modeling – From Concept to Countermeasure

A hands-on course on threat modeling: why it pays off, what it is, how the process works, which methods exist (with a focus on STRIDE), a fully worked practical example, and the transition into risk management. Note: This course is voiced by AI voices (AI narrated).

What you'll learn

  • Be able to justify the value of threat modeling
  • Define threat modeling and know Shostack's four questions
  • Apply the generic process and STRIDE
  • Model and assess threats using an example
  • Understand the transition into risk management

Tags

securitythreat-modelingstrideeacgAI narrated
Module 01 - Why Threat Modeling?
  • Introduction 1:56
  • Why Threat Modeling Pays Off 7:32
  • Quick check
Module 02 - What is Threat Modeling?
  • What is Threat Modeling? 0:13
  • What Threat Modeling Actually Is 6:14
  • The four questions
Module 03 - How Do You Do Threat Modeling?
  • How Do You Do Threat Modeling? 0:14
  • The Process in Five Steps 5:15
  • Order the five steps
Module 04 - STRIDE & Methods
  • STRIDE & Methods 0:13
  • Finding Threats Systematically with STRIDE 8:56
  • STRIDE ↔ security goal
Module 05 - Show Me – a Practical Example
  • Show Me – a Practical Example 0:15
  • Threat Modeling on a Kubernetes Cluster 8:31
  • Security vs. delivery date
Module 06 - Did We Do It Well? & Transition
  • Did We Do It Well? & Transition 0:15
  • Checking, Handing Over, and Anchoring It in the Team 7:14
  • Review & risk management
  • Take-home messages 0:52