THREAT MODELING · 07 min

STRIDE threat modeling explained

STRIDE is one of the most widely used threat modeling frameworks. Its value is greatest when it helps a team ask better questions about a real system and then connect those questions to attack scenarios and mitigations.

What does STRIDE stand for?

STRIDE groups common threat types into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

S — Spoofing

Ask whether an attacker can impersonate a user, service, workload or identity. Review authentication, credential handling, token validation and identity boundaries.

T — Tampering

Ask whether data, messages, configurations or artifacts can be modified without authorization. Consider integrity protections, signing, authorization and pipeline controls.

R — Repudiation

Ask whether important actions can be reliably attributed. Logging, audit trails, correlation and protected telemetry become important here.

I — Information disclosure

Ask whether sensitive information can reach an unauthorized party. Consider data classification, access controls, encryption, logging exposure and unintended data paths.

D — Denial of service

Ask what can exhaust compute, network, storage, API quotas or operational capacity. Resilience and rate limiting are common parts of the control discussion.

E — Elevation of privilege

Ask whether an attacker can move from a lower privilege level to a more powerful identity or operation. Review RBAC, managed identities, administrative interfaces and trust relationships.

Don't stop at STRIDE

STRIDE is a discovery lens, not the complete threat model. Once a potential threat is identified, describe the attacker objective, preconditions, attack path, evidence and mitigation. That produces a result engineers can actually use.