
stride-gpt v0.19.0
An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.
STRIDE GPT is an AI-powered threat modelling tool that leverages Large Language Models (LLMs) to generate threat models and attack trees for a given application based on the STRIDE methodology. Users provide application details, such as the application type, authentication methods, and whether the application is internet-facing or processes sensitive data. The model then generates its output based on the provided information.
Table of Contents
- Support the Project
- Features
- Enterprise Deployment
- Talk at Open Security Summit
- Changelog
- Installation
- Repository layout
- Usage
- Sample output
- Security Best Practices
- Contributing
- License
Support the Project
If you find STRIDE GPT useful, please consider supporting the project:
- ⭐ Star the repository on GitHub to help more people discover the tool
- ☕ Buy me a coffee to support continued development and maintenance
Features
- Agentic codebase analysis: Point the CLI at a codebase and get an autonomous, deep STRIDE threat model — the agent plans, explores, and synthesizes findings across subsystems
- CLI and interactive REPL: Full-featured terminal experience with tab completion, history, and real-time progress — no browser required
- Simple and user-friendly Streamlit web interface
- Generates threat models based on the STRIDE methodology
- Agentic AI support: Specialized threat modeling for agentic AI systems with OWASP Top 10 for Agentic Applications (ASI) integration
- Generative AI support: Threat modeling for GenAI applications with OWASP LLM Top 10 integration
- MITRE ATT&CK & ATLAS mapping: Threats are annotated with standardized adversary technique IDs (MITRE ATT&CK Enterprise for traditional infrastructure attacks, ATLAS for ML/LLM-specific attacks) — surfaced as columns in markdown, linked pills in HTML, and
mitre_attackproperties in SARIF - Architectural pattern detection: Automatically detects RAG pipelines, multi-agent systems, code execution environments, tool ecosystems, and more from application descriptions (inspired by CSA MAESTRO)
- Embedded draw.io diagram editor: Create and edit architecture diagrams directly in STRIDE-GPT using the integrated diagrams.net editor — no external tool needed. Diagrams are parsed as XML to extract components, connections, and trust boundaries, providing significantly richer context for threat model generation than image analysis alone. The existing image upload workflow is unchanged. By default the editor loads from the hosted
embed.diagrams.net; for self-hosted or air-gapped deployments, point it at your own draw.io via theSTRIDE_GPT_DRAWIO_URLenvironment variable - Multi-modal: Use architecture diagrams, flowcharts, etc. as inputs for threat modelling across all supported vision-capable models
- Data Flow Diagrams: Generate DFDs from your application description (or parse an uploaded DFD image), edit the Mermaid source live, and feed the confirmed diagram back into the Threat Model and Attack Tree prompts as the authoritative system model. CLI
/analyzealso emits a system-level DFD alongside its findings - Generates attack trees to enumerate possible attack paths
- Suggests possible mitigations for identified threats
- Supports DREAD risk scoring for identified threats
- Generates Gherkin test cases based on identified threats
- GitHub repository analysis for comprehensive threat modelling (including GitHub Enterprise support)
- Multiple output formats: Markdown, JSON, SARIF (imports into GitHub, GitLab, Azure DevOps, IDEs), and a self-contained HTML view for sharing with stakeholders
- Advanced reasoning model support (OpenAI GPT-5.4/5.5 series, Anthropic Claude 4.6/4.8 with Extended Thinking, Google Gemini 3, Mistral Magistral series)
- Comprehensive LLM provider support via LiteLLM: OpenAI, Anthropic, Google AI, Mistral, Groq, DeepSeek, plus local hosting via LM Studio Server
- No data storage; application details are not saved
- Available as a Docker container image for easy deployment
- Environment variable support for secure configuration
Enterprise Deployment
Want to customize STRIDE-GPT for your organization? Check out our comprehensive Operationalization Guide to learn how to:
- 🎯 Inject organizational security controls and standards
- 📋 Customize threat models with your compliance requirements
- 🔧 Fork and deploy STRIDE-GPT internally
- 📊 Get context-aware, actionable threat models specific to your environment
The guide includes step-by-step instructions, code examples, and deployment patterns for organizations looking to scale AI-powered threat modeling across their teams.
Talk at Open Security Summit
In January 2024 I gave a talk about STRIDE GPT at the Open Security Summit. During the talk, I discussed the project's inception, its core functionalities, recent updates, and some future plans. You can watch the full presentation below:
This video is an excellent resource for anyone interested in understanding how STRIDE GPT works and how it can be used to improve threat modelling.
