Posts

Showing posts with the label Threat Modeling

STRIDE Threat Modeling Explained for the Security+ Exam

STRIDE is a threat modeling framework — a structured way of asking "what could go wrong with this system?" before it is built, rather than discovering the answer afterwards. Developed at Microsoft in the late 1990s, it remains the most widely taught model of its kind. STRIDE works by turning each security property you want into the threat that violates it, then walking every component of the design against all six. That inversion is the useful part. Rather than asking the open-ended and unanswerable "how might this be attacked?", you ask six specific questions of every element, and the structure does the remembering for you. The Six Categories Threat Violates Meaning Primary defense S poofing Authentication Pretending to be someone or something else Strong authentication, MFA, certificates T ampering Integrity Unauthorized modification of data or code Hashing, digital signatures, access control R epudiation Non-repudiation Denying an action you performe...