STRIDE Threat Modeling Guide for Builders and Defenders
STRIDE is a practical threat-modeling checklist from Microsoft: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege. Use it on a simple diagram of your system to find mitigations early — educational design work, not an attack playbook or exploit list.
Friends! Drawing boxes on a whiteboard before coding builds confidence in security interviews. STRIDE = six questions per box / arrow. Today: threat modeling habit — no PoC exploits. Your app / lab design only.
मित्रांनो! Code लिहण्या आधी whiteboard वर boxes आणल्या की security interview मध्ये confidence येतो. STRIDE = six questions per box / arrow. आज threat modeling habit – PoC exploits नाही. तुमचा app / lab design only.
मित्रों! Code लिखने से पहले whiteboard पर boxes बनाने से security interview में confidence आता है. STRIDE = six questions per box / arrow. आज threat modeling habit – PoC exploits नहीं. आपका app / lab design only.
Quick answer
Threat-model with STRIDE:
- Draw a simple data-flow diagram: users, apps, data stores, trust boundaries (internet vs LAN vs admin).
- For each process / data store / flow, ask the six STRIDE questions.
- Write mitigations next to each realistic threat (authN, integrity checks, logs, rate limits, least privilege).
- Track residual risk and owners — “accepted” needs a name and review date.
- Revisit when architecture changes (new API, new vendor, new admin tool).
- Keep models short enough that builders read them — a 2-page living doc beats a 80-page shelf ornament.
- Never use threat modeling as cover to attack third-party systems; model what you build or are authorised to review.
Tiny mental model:
Diagram → STRIDE questions → mitigations → owners
No diagram = security debates stay vague
What do I need before this guide?
- Web risk vocabulary: OWASP Top 10.
- Identity mindset: Cloud IAM least privilege.
- Optional: Zero Trust explained.
- A whiteboard, paper, or draw.io for a system you design (even a college project).
What is STRIDE?
Draw the system, walk STRIDE categories, then record mitigations — a design habit for defenders, not an attack recipe.
System draw करा, STRIDE categories walk करा, मग mitigations record करा — defenders साठी design habit, attack recipe नाही.
System draw करो, STRIDE categories walk करो, फिर mitigations record करो — defenders के लिए design habit, attack recipe नहीं.
The six categories (defender definitions)
- Spoofing — pretending to be another user, service or host (fix with strong authentication, MFA, mutual TLS where needed).
- Tampering — changing data or code in transit or at rest (integrity: signatures, checksums, authenticated APIs, locked configs).
- Repudiation — denying an action with no proof (non-repudiation: good audit logs, signed transactions, time sync).
- Information disclosure — reading data you should not (encryption, access control, minimise PII, careful errors).
- Denial of service — making the system unavailable (rate limits, quotas, capacity, graceful degradation — high-level).
- Elevation of privilege — acting with more power than intended (least privilege, secure admin paths, input validation).
Educational warning: STRIDE finds design weaknesses. It is not a licence to probe production without authorisation, and this page does not provide exploit payloads for any category.
Real incident: Capital One (2019) — design / metadata lesson
Public reporting on the Capital One 2019 breach described abuse of a misconfigured web application firewall and access to cloud metadata-style credentials, leading to significant data exposure. Threat-modeling fans read it as a reminder: trust boundaries around management interfaces and instance metadata must appear on the diagram with explicit Spoofing / Elevation / Disclosure mitigations — not only “we have encryption at rest”.
Takeaways (vertical):
- What happened — cloud-hosted application path led to broad data access.
- What went wrong (theme) — a trust-boundary control did not match the intended model.
- Care-take — draw metadata / IMDS and admin APIs as separate elements with STRIDE notes.
- Care-take — least privilege on roles that apps receive.
- Care-take — logging and detection for unusual role usage.
- Bonus parallel — many SSRF-class lessons are really “we never put that flow on the whiteboard”.
How to sketch a beginner DFD
- Boxes: Browser, App server, Database, Identity provider, Email/SMS vendor.
- Arrows: login, read order, password reset, admin export.
- Dashed line: trust boundary between internet and VPC / private subnet.
- Note where secrets live (vault vs env vs none).
- Fictional Nashik grape exporter portal: farmers upload invoices — mark the upload bucket and the admin export arrow for Disclosure + Elevation questions.
Red Team vs Blue Team (awareness only)
Red Team — what attackers try
- Spoof support identity; abuse password-reset flows (high-level social + tech mix).
- Tamper with unsigned client updates or weak API authorisation.
- Overwhelm public endpoints (DoS) to hide other noise.
- Climb from a low-privilege bug into admin functions (Elevation).
Blue Team — defend, detect, respond
- Put mitigations in tickets before coding “nice to have”.
- Log security-relevant decisions (authZ denials, admin exports).
- Rate-limit and cache thoughtfully; know your provider’s shields.
- Re-run STRIDE when adding AI tools, webhooks or new admin panels.
- Share the one-page model in onboarding so juniors inherit context.
How do I run a STRIDE session step by step?
Step 1 — Scope one feature
- Pick a thin slice (e.g. “password reset” or “invoice upload”), not the whole company.
- Time-box 60–90 minutes with a developer + someone security-curious.
- Write assumptions (“admins use SSO”, “DB not on internet”).
Step 2 — Apply STRIDE with a table
| Element | S | T | R | I | D | E | Mitigation |
|---|---|---|---|---|---|---|---|
| Login API | … | … | … | … | … | … | MFA, lockout policy, logs |
| Invoice bucket | … | … | … | … | … | … | Private ACL, encryption, signed URLs |
Fill cells with short phrases, not essays. Skip empty theoretical noise; mark “N/A” when honest.
Step 3 — Prioritise
- Internet-facing + sensitive data first.
- Missing authentication / authorisation beats polishing TLS ciphers for a beginner backlog.
- Assign owners and target dates; accepted risks need a review month.
Step 4 — Feed engineering
- Convert rows into user stories or security acceptance checks.
- Link related OWASP items for builders.
- Store the diagram next to the repo README.
Step 5 — Lab / classroom only
- Threat-model a toy app you wrote.
- Optionally validate mitigations with authorised tests on that app.
- Do not STRIDE someone else’s bank and then “verify” with scans.
Ravindra Bagale's Tip
💡 Students drop STRIDE as a buzzword on a PowerPoint with no diagram. The interviewer asks: "name one trust boundary." Boxes + arrows + MFA/least-privilege mitigation = concrete. No exploit poetry. Got it?
Ravindra Bagale's Tip – मराठी
💡 Students STRIDE ला buzzword म्हणून powerpoint मध्ये टाकतात पण diagram नाही. Interviewer विचारतो: "एक trust boundary सांगा." Boxes + arrows + MFA/least privilege mitigation = concrete. Exploit poetry नको. समजलं का?
Ravindra Bagale's Tip – हिंदी
💡 Students STRIDE को buzzword कहकर powerpoint में डालते हैं लेकिन diagram नहीं. Interviewer पूछता है: "एक trust boundary बताओ." Boxes + arrows + MFA/least privilege mitigation = concrete. Exploit poetry नहीं. समझ में आया?
STRIDE vs “we will pentest later”
- Pentests find what slipped through; STRIDE reduces what you ship broken.
- Ethical pentest still needs rules of engagement — modeling is earlier and cheaper.
- Use both: model → build → authorised test → fix → re-model changed pieces.
When STRIDE is “good enough”
- Startups: one afternoon per major feature beats zero modeling.
- Enterprises: align STRIDE rows to existing risk registers without duplicating jargon.
- Students: a single graded diagram with six honest mitigations proves skill.
Care-take — organisation habits
- New microservice template includes an empty STRIDE table.
- Architecture review gate: “show the DFD”.
- Vendor onboarding: where does our data flow into their trust zone?
- Update the model after incidents — living document.
- Do not confuse compliance paperwork with thinking; keep language plain.
- Pair with IR planning for high-impact rows.
How do I fix common threat-modeling mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| 80-page model nobody reads | Boiling the ocean | One feature per session |
| Only crypto discussed | Comfort zone | Force Spoofing + Elevation rows |
| “Hackers gonna hack” fatalism | No owners | Mitigation + name + date |
| Model outdated in 3 months | No trigger | Revisit on architecture RFCs |
| Used as attack brainstorm only | Wrong culture | End every item with a control |
| Scanned prod to “confirm” | Scope creep | Authorised test environments only |
Try it at home
Educational design practice:
- Draw a 6-box diagram of an app you use daily (e.g. notes app) as a learning sketch — no testing their servers.
- Fill STRIDE for the login arrow and the sync cloud store.
- Write three mitigations you would want if you built it.
- Time yourself: 45 minutes maximum.
- Bring the paper to study group; compare vocabulary, not attack ideas.
Learn it properly
Course lessons:
Related guides: OWASP Top 10 · Zero Trust · Cloud IAM · Ethical pentest (RoE)
Got it? STRIDE = Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation. Diagram → questions → mitigations → owners. No attack recipes — design habit. Capital One-style lessons = trust boundaries on the whiteboard. Next: digital forensics beginners guide.
समजलं का? STRIDE = Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation. Diagram → questions → mitigations → owners. Attack recipes नाही – design habit. Capital One-style lessons = trust boundaries on the whiteboard. आता digital forensics beginners guide.
समझ में आया? STRIDE = Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation. Diagram → questions → mitigations → owners. Attack recipes नहीं – design habit. Capital One-style lessons = trust boundaries on the whiteboard. आगे digital forensics beginners guide.
Frequently asked questions
What does STRIDE stand for?
Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
Is threat modeling the same as a pentest?
No. Modeling is early design review; pentests are later authorised tests with RoE.
How detailed should the diagram be?
Short enough that builders read it — one feature per session beats an unread 80-page binder.
How does Capital One 2019 relate?
Public lessons highlight trust boundaries around cloud metadata and app roles — put them on the diagram.
Does this page include exploits?
No. Categories map to mitigations only.
Where should I read next?
OWASP Top 10, Zero Trust and ethical pentest guides on this site.