THREAT MODELING · 07 min
STRIDE threat modeling explained
STRIDE is one of the most widely used threat modeling frameworks. Its value is greatest when it helps a team ask better questions about a real system and then connect those questions to attack scenarios and mitigations.
What does STRIDE stand for?
STRIDE groups common threat types into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
S — Spoofing
Ask whether an attacker can impersonate a user, service, workload or identity. Review authentication, credential handling, token validation and identity boundaries.
T — Tampering
Ask whether data, messages, configurations or artifacts can be modified without authorization. Consider integrity protections, signing, authorization and pipeline controls.
R — Repudiation
Ask whether important actions can be reliably attributed. Logging, audit trails, correlation and protected telemetry become important here.
I — Information disclosure
Ask whether sensitive information can reach an unauthorized party. Consider data classification, access controls, encryption, logging exposure and unintended data paths.
D — Denial of service
Ask what can exhaust compute, network, storage, API quotas or operational capacity. Resilience and rate limiting are common parts of the control discussion.
E — Elevation of privilege
Ask whether an attacker can move from a lower privilege level to a more powerful identity or operation. Review RBAC, managed identities, administrative interfaces and trust relationships.
Don't stop at STRIDE
STRIDE is a discovery lens, not the complete threat model. Once a potential threat is identified, describe the attacker objective, preconditions, attack path, evidence and mitigation. That produces a result engineers can actually use.