Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
From various assets and countermeasures to factoids, personas, and architectural components, you can enter or upload a diverse array of data related to security, usability, and requirements to uncover valuable insights, including the links between requirements and risks as well as the rationale behind persona traits. Since no single perspective can encompass the complexity of a system, you can effortlessly create 12 distinct views of your developing design that examine aspects such as people, risks, requirements, architecture, and even geographical location. Additionally, as your preliminary design progresses, you can automatically produce threat models like Data Flow Diagrams (DFDs). Utilize open-source intelligence regarding potential threats and viable security architectures to assess your attack surface effectively. Furthermore, you can visualize all the security, usability, and design factors related to the risks associated with your product and how they interact with one another. This comprehensive approach ensures a thorough understanding of your system's vulnerabilities and strengths.
Description
OWASP Threat Dragon serves as a modeling tool designed for creating diagrams that represent potential threats within a secure development lifecycle. Adhering to the principles of the threat modeling manifesto, Threat Dragon enables users to document potential threats and determine appropriate mitigation strategies, while also providing a visual representation of the various components and surfaces related to the threat model. This versatile tool is available as both a web-based application and a desktop version. The Open Web Application Security Project (OWASP) is a nonprofit organization dedicated to enhancing software security, and all of its projects, tools, documents, forums, and chapters are accessible for free to anyone eager to improve application security practices. By facilitating collaboration and knowledge sharing, OWASP encourages a community-focused approach to achieving higher security standards in software development.
API Access
Has API
No
API Access
Has API
Yes
Integrations
Amazon CodeWhisperer
No
Bizzy
No
CycloneDX
No
Escape
No
EthicalCheck
No
Jit
No
Kiuwan Code Security
No
Seconize DeRisk Center
No
SecureFlag
No
ShieldForce
No
Integrations
Amazon CodeWhisperer
Yes
Bizzy
Yes
CycloneDX
Yes
Escape
Yes
EthicalCheck
Yes
Jit
Yes
Kiuwan Code Security
Yes
Seconize DeRisk Center
Yes
SecureFlag
Yes
ShieldForce
Yes
Pricing Details
Free
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
No
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
CAIRIS
Website
cairis.org
Vendor Details
Company Name
OWASP
Founded
2001
Country
United States
Website
owasp.org/www-project-threat-dragon/
Product Features
Requirements Management
Automated Functional Sizing
No
Automated Requirements QA
No
Automated Test Generation
No
Automated Use Case Modeling
No
Change Management
No
Collaboration
No
History Tracking
No
Prioritization
No
Reporting
No
Status Reporting
No
Status Tracking
No
Summary Reports
No
Task Management
No
To-Do List
No
Traceability
No
User Defined Attributes
No