Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

OWASP Threat Dragon helps you map a system, associate threats and mitigations with its components, and keep that analysis in a model you can revisit. It organizes the work; your team still needs to decide what belongs in the model and validate the risks. Here’s how to use it to create a useful first pass.

What is Threat Dragon?

OWASP describes Threat Dragon as a free, open-source, cross-platform application for drawing threat-model diagrams and listing threats for elements in those diagrams. Its central representation is a data-flow diagram (DFD): a visual map of components and the flows between them. Threat details are stored alongside the diagram in the model, and the tool can produce a PDF report containing the diagram and associated threats. OWASP’s project page and Developer Guide describe its role in the threat-modeling process.

Threat Dragon also includes a rule engine that can suggest or generate threats and mitigations. Treat these suggestions as prompts for discussion, not a completeness check or security decision: teams must review whether each item applies, identify missing risks, and choose appropriate mitigations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the version and where models will live

Threat Dragon has desktop and web variants. The desktop application is available for Windows, macOS, and Linux and saves models locally. The web application can run in a container or from source; it can use local files or be configured to store models with supported repository and cloud services. Choose based on who needs access, how the team manages model files, and what deployment and access controls your organization can support.

Choice Where it runs Model storage and collaboration Useful when
Desktop Windows, macOS, or Linux Models are saved locally. An individual or small working group wants to begin without operating a web deployment.
Web Containerized or run from source Can use local files or configured integrations: GitHub, GitHub Enterprise, Google Drive, Bitbucket, Bitbucket Enterprise, and GitLab. A team needs a shared deployment or wants model files managed through an existing supported provider.

Provider integrations require configuration; the repository says external repository access requires registering the application with the repository account. Confirm the current setup instructions and access requirements in the OWASP Threat Dragon repository before selecting an integration. A PDF report is useful for a printable record, but producing one does not amount to compliance approval.

Build a model for your system

  1. Open a sample model. Use it to learn the interface and see how diagrams and threat details relate. Do not treat sample architecture as a substitute for your own system map.
  2. Review model metadata and the DFD. Name and describe the system and make sure the diagram reflects the scope you intend to assess.
  3. Map the architecture. Add or remove components and edit their properties so the diagram represents the relevant parts of your system and how data moves between them.
  4. Make trust boundaries and assumptions explicit. Show where data crosses between components or environments, and record assumptions that affect the analysis. Review these with people who understand the system.
  5. Examine threats associated with diagram elements. Use any rule-engine suggestions as a starting point. Add, revise, or remove threats based on your architecture and review objective.
  6. Record mitigations. For each applicable threat, document the action the team intends to take or the reason an item is not being addressed. Keep the rationale clear enough to revisit as the design changes.
  7. Review and share the artifact. Validate the diagram, assumptions, threats, and mitigations with relevant developers, architects, and security practitioners. Generate the PDF report when a printable record is useful; retain the model file as the working artifact.

Select an approach for categorizing threats

Threat Dragon lists several approaches and categorizations, including STRIDE, LINDDUN, CIA, DIE, CIA-DIE, and PLOT4ai. They help structure a review; availability in the tool does not prove that every risk has been found. Select an approach that fits the system and the question the review needs to answer, then validate its results against the actual design.

  • STRIDE: a way to organize threat discussions around common threat categories.
  • LINDDUN: a privacy-focused threat-modeling approach.
  • CIA and DIE/CIA-DIE: categorizations that help frame security objectives.
  • PLOT4ai: an approach listed by OWASP for AI-related threat modeling.

OWASP’s project page and documentation name the supported approaches; they do not provide a comparative benchmark showing one to be superior. The review team should determine which categories suit its scope and whether additional analysis is needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Version and project status

The OWASP documentation home page identifies version 2.6.2. Because release information can change, check the project releases page for the current release rather than assuming that number remains latest. The repository says v1.x is no longer actively maintained, following the end of life of AngularJS 1.x, while v2.x is a rewrite using Vue.js. It labels the project Production status and specifies the Apache 2.0 license. See the repository for project details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Learn the practice beyond the interface

For background on threat modeling as a broader security practice, Adam Shostack’s Threat Modeling: Designing for Security is an optional resource, not a Threat Dragon manual. Wiley lists its first edition as a 2014, 624-page softcover. The author’s site announces a second edition, Threat Modeling: Designing for Security in an AI World, with availability planned for February 2, 2027; that planned date is in the future as of October 2026. Check the Wiley listing and author’s book page for current publication information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.