
IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes.
Static IaC threat modeler that parses Terraform, CloudFormation, and Kubernetes manifests and produces structured threat model reports using STRIDE, MITRE ATT&CK, or PASTA frameworks. No network calls, no cloud credentials, fully offline. Runs as a CLI, REST API, or containerized service.
CLI:
pip install threatmap
threatmap scan ./examples --output report.md --fail-on HIGH
Docker:
docker run -v $(pwd):/workspace bogdynn/threatmap:2.1.0 threatmap scan /workspace --output /workspace/report.md
REST API Server:
threatmap serve --host 0.0.0.0 --port 8000
# Or via Docker:
docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# API endpoints: /health, /version, /rules, /analyze
GraphQL API:
docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# GraphQL endpoint: http://localhost:8000/graphql
# Queries: health, version, rules
# Mutations: analyze(content, filename, framework)
| Format | Provider | Extension |
|---|---|---|
| Terraform HCL | AWS, Azure, GCP | .tf |
| CloudFormation | AWS | .yaml, .yml, .json |
| Kubernetes manifests | Kubernetes | .yaml, .yml |
Install from PyPI:
pip install threatmap
Or for local development:
git clone https://github.com/bogdanticu88/threatmap.git
cd threatmap
pip install -e .
Scan a directory and print a Markdown report to stdout:
threatmap scan ./terraform/
Scan multiple paths and write a JSON report to a file:
threatmap scan ./terraform/ ./k8s/ ./cloudformation/ --format json --output report.json
Generate an interactive HTML report or a SARIF report for GitHub Security:
threatmap scan ./infra/ --format html --output report.html
threatmap scan ./infra/ --format sarif --output report.sarif
CI gate — exit code 1 if any CRITICAL or HIGH threat is found:
threatmap scan ./infra/ --fail-on HIGH --output threat-report.md
Print a terminal summary table only, without writing a full report:
threatmap scan ./infra/ --summary
Use ASCII-only severity indicators (no emojis) for environments that don't support Unicode:
threatmap scan ./infra/ --ascii --output report.md
Analyze using different threat modeling frameworks:
# STRIDE (default)
threatmap scan ./infra/ --framework stride
# MITRE ATT&CK (maps to tactics and techniques)
threatmap scan ./infra/ --framework mitre --format json
# PASTA (asset-centric threat modeling)
threatmap scan ./infra/ --framework pasta --format json
STRIDE (73 rules)
MITRE ATT&CK (11 rules, 14 tactics)
PASTA (12 rules, asset-centric)
Running threatmap scan ./examples --output report.md against the bundled examples produces a full Markdown report. Below is a representative excerpt.
| ID | Severity | STRIDE Category | Resource | Description |
|---|---|---|---|---|
| T-001 | 🔴 CRITICAL | Information Disclosure | AuditBucket | S3 bucket 'AuditBucket' has no public access block configured — bucket may be publicly accessible. |
| T-002 | 🔴 CRITICAL | Spoofing | WebSecurityGroup | Security group 'WebSecurityGroup' exposes SSH/RDP (port 22/3389) to 0.0.0.0/0. |
| T-003 | 🔴 CRITICAL | Elevation of Privilege | app_contributor | Role assignment 'app_contributor' grants the privileged role 'Contributor'. |
| T-006 | 🟠 HIGH | Information Disclosure | AuditBucket | S3 bucket 'AuditBucket' does not have server-side encryption configured. |
| T-008 | 🟠 HIGH | Elevation of Privilege | api | Container 'api' in Deployment 'api' may run as root (no runAsNonRoot=true or runAsUser=0). |
| T-011 | 🟠 HIGH | Elevation of Privilege | web | EC2 instance 'web' allows IMDSv1 — metadata service accessible without session tokens, enabling SSRF-based credential theft. |
### T-002 — Spoofing (CRITICAL)
Resource: AWS::EC2::SecurityGroup.WebSecurityGroup
Property: ingress.ssh_rdp_open
Finding: Security group 'WebSecurityGroup' exposes SSH/RDP (port 22/3389) to 0.0.0.0/0.
Mitigation: Remove public SSH/RDP access. Use AWS Systems Manager Session Manager
or a bastion host with IP restrictions.
The report appends a Mermaid flowchart LR diagram. Nodes are coloured by worst-case severity (🔴 red = CRITICAL, 🟠 orange = HIGH). Paste the block into any Mermaid renderer or view it directly on GitHub.