A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
☆1,753Aug 2, 2024Updated last year
Alternatives and similar repositories for awesome-threat-modelling
Users that are interested in awesome-threat-modelling are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This project is about creating and publishing threat model examples.☆428Nov 10, 2021Updated 4 years ago
- A Pythonic framework for threat modeling☆1,124May 22, 2026Updated last week
- Agile Threat Modeling Toolkit☆764Apr 8, 2026Updated last month
- threatspec - continuous threat modeling, through code☆385Dec 30, 2020Updated 5 years ago
- A Continuous Threat Modeling methodology☆328Jun 24, 2022Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Curating the best DevSecOps resources and tooling.☆1,689Aug 2, 2024Updated last year
- Draw.io libraries for threat modeling diagrams☆793Nov 12, 2020Updated 5 years ago
- An open source threat modeling tool from OWASP☆1,484Updated this week
- a curated list of useful threat modeling resources☆151Jun 28, 2024Updated last year
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,559Apr 3, 2026Updated last month
- A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigatin…☆505Jun 12, 2025Updated 11 months ago
- An authoritative list of awesome devsecops tools with the help from community experiments and contributions.☆5,404May 11, 2024Updated 2 years ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestrat …☆281Feb 17, 2026Updated 3 months ago
- The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.☆1,060Jan 5, 2026Updated 4 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- ☆575May 20, 2026Updated last week
- This is a step-by-step guide to implementing a DevSecOps program for any size organization☆2,041Dec 21, 2024Updated last year
- An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRI…☆1,044Updated this week
- A simple threat modeling tool to help humans to reduce time-to-value when threat modeling☆733May 20, 2026Updated last week
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,604Jan 5, 2026Updated 4 months ago
- Segment's Threat Modeling training for our engineers☆246May 4, 2021Updated 5 years ago
- Security Champions Playbook v 2.1☆393Sep 25, 2023Updated 2 years ago
- This repository stores content that can be used to design a Rapid Threat Model Prototyping process for a software development group.☆165Mar 14, 2023Updated 3 years ago
- Checklist for container security - devsecops practices☆1,617Sep 15, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- An online multiplayer version of the Elevation of Privilege (EoP) threat modeling card game☆161Apr 22, 2026Updated last month
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆48Nov 24, 2016Updated 9 years ago
- ♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎☆2,122Apr 25, 2026Updated last month
- List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.☆9,453Apr 17, 2026Updated last month
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆209Dec 6, 2023Updated 2 years ago
- Ultimate DevSecOps library☆6,734Mar 5, 2026Updated 2 months ago
- Multi-Cloud Security Auditing Tool☆7,678Sep 23, 2025Updated 8 months ago
- A curated list of tools for incident response☆9,052May 6, 2026Updated 3 weeks ago
- Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exh…☆684Aug 7, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A curated list of Awesome Threat Intelligence resources☆10,219Jan 19, 2026Updated 4 months ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,422Mar 17, 2026Updated 2 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆72Jun 25, 2025Updated 11 months ago
- ☆69Jul 18, 2025Updated 10 months ago
- Open-Source Unified Vulnerability Management, DevSecOps & ASPM☆4,717Updated this week
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,975Oct 1, 2025Updated 7 months ago
- Application Security Verification Standard☆3,430Mar 17, 2026Updated 2 months ago