Low risk (0–3) Medium risk (4–6) High risk (7–10)
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

STRIDE Threat Model Risk Explorer

A small system — user, web server, API, admin console and database — is laid out in 3D with six real data flows between its components, each pre-classified under Microsoft's STRIDE threat taxonomy (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). Pick any flow and score its Damage potential, Reproducibility and Exploitability with the sliders; Affected-users and Discoverability are computed from the architecture itself — a flow terminating at the database structurally affects more than one ending at the web server, and a public-facing flow is inherently easier to find than an internal one. The five factors combine through the classic DREAD formula into a 0–10 risk score, and every edge's color and pulse speed update live to reflect it, alongside a system-wide aggregate across all six flows.