A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
☆1,731Aug 2, 2024Updated last year
Alternatives and similar repositories for awesome-threat-modelling
Users that are interested in awesome-threat-modelling are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This project is about creating and publishing threat model examples.☆430Nov 10, 2021Updated 4 years ago
- A Pythonic framework for threat modeling☆1,113Mar 16, 2026Updated last week
- Agile Threat Modeling Toolkit☆737Mar 12, 2026Updated 2 weeks ago
- threatspec - continuous threat modeling, through code☆383Dec 30, 2020Updated 5 years ago
- A Continuous Threat Modeling methodology☆324Jun 24, 2022Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Curating the best DevSecOps resources and tooling.☆1,649Aug 2, 2024Updated last year
- Draw.io libraries for threat modeling diagrams☆788Nov 12, 2020Updated 5 years ago
- An open source threat modeling tool from OWASP☆1,359Updated this week
- a curated list of useful threat modeling resources☆148Jun 28, 2024Updated last year
- Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS…☆1,535Jan 28, 2026Updated 2 months ago
- A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigatin…☆489Jun 12, 2025Updated 9 months ago
- An authoritative list of awesome devsecops tools with the help from community experiments and contributions.☆5,363May 11, 2024Updated last year
- The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.☆1,042Jan 5, 2026Updated 2 months ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestrat…☆281Feb 17, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- ☆569Updated this week
- An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRI…☆994Mar 2, 2026Updated 3 weeks ago
- This is a step-by-step guide to implementing a DevSecOps program for any size organization☆2,038Dec 21, 2024Updated last year
- A simple threat modeling tool to help humans to reduce time-to-value when threat modeling☆693Updated this week
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,541Jan 5, 2026Updated 2 months ago
- Segment's Threat Modeling training for our engineers☆245May 4, 2021Updated 4 years ago
- Security Champions Playbook v 2.1☆392Sep 25, 2023Updated 2 years ago
- This repository stores content that can be used to design a Rapid Threat Model Prototyping process for a software development group.☆165Mar 14, 2023Updated 3 years ago
- Checklist for container security - devsecops practices☆1,614Sep 15, 2025Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- An online multiplayer version of the Elevation of Privilege (EoP) threat modeling card game☆160Feb 27, 2026Updated last month
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆47Nov 24, 2016Updated 9 years ago
- ♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎☆2,098Mar 3, 2026Updated 3 weeks ago
- List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.☆9,416Oct 16, 2025Updated 5 months ago
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆206Dec 6, 2023Updated 2 years ago
- Ultimate DevSecOps library☆6,655Mar 5, 2026Updated 3 weeks ago
- Multi-Cloud Security Auditing Tool☆7,585Sep 23, 2025Updated 6 months ago
- A curated list of tools for incident response☆8,901Jul 18, 2024Updated last year
- Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exh…☆681Aug 7, 2020Updated 5 years ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆70Jun 25, 2025Updated 9 months ago
- A curated list of Awesome Threat Intelligence resources☆9,991Jan 19, 2026Updated 2 months ago
- 🛡️ Awesome Cloud Security Resources ⚔️☆2,377Mar 17, 2026Updated last week
- ☆69Jul 18, 2025Updated 8 months ago
- Open-Source Unified Vulnerability Management, DevSecOps & ASPM☆4,596Updated this week
- Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.☆1,917Oct 1, 2025Updated 5 months ago
- Application Security Verification Standard☆3,377Mar 17, 2026Updated last week