STRIDE Threat Model Risk Explorer
Interactive 3D system-architecture threat model: pick a data flow between five components, score it with the DREAD formula, and watch STRIDE-classified risk propagate as color-coded, speed-scaled traffic pulses.
A small system — user, web server, API, admin console and database — is laid out in 3D with six real data flows between its components, each pre-classified under Microsoft's STRIDE threat taxonomy (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). Pick any flow and score its Damage potential, Reproducibility and Exploitability with the sliders; Affected-users and Discoverability are computed from the architecture itself — a flow terminating at the database structurally affects more than one ending at the web server, and a public-facing flow is inherently easier to find than an internal one. The five factors combine through the classic DREAD formula into a 0–10 risk score, and every edge's color and pulse speed update live to reflect it, alongside a system-wide aggregate across all six flows.
Score six data flows in a small 3D system architecture with the DREAD risk formula, classify each under Microsoft's STRIDE threat model, and watch color-coded, speed-scaled traffic pulses reveal which flow is the real weak point.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install