Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
threatmap — IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes. | Kitploit
Tools/GitHubGitHub/bogdanticu88/threatmap
Static AnalysisContainer SecurityVulnerability AnalysisConfiguration AuditingCloud SecurityDevSecOpsThreat IntelligenceAPI Security
GitHubbogdanticu88/threatmap

threatmap

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes.

View Repository
619153 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
2026-03-25_12-36

threatmap

CI Version PyPI Python Docker STRIDE MITRE PASTA GraphQL API License: MIT Offline

Static IaC threat modeler that parses Terraform, CloudFormation, and Kubernetes manifests and produces structured threat model reports using STRIDE, MITRE ATT&CK, or PASTA frameworks. No network calls, no cloud credentials, fully offline. Runs as a CLI, REST API, or containerized service.


Quick Start

CLI:

pip install threatmap
threatmap scan ./examples --output report.md --fail-on HIGH

Docker:

docker run -v $(pwd):/workspace bogdynn/threatmap:2.1.0 threatmap scan /workspace --output /workspace/report.md

REST API Server:

threatmap serve --host 0.0.0.0 --port 8000
# Or via Docker:
docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# API endpoints: /health, /version, /rules, /analyze

GraphQL API:

docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# GraphQL endpoint: http://localhost:8000/graphql
# Queries: health, version, rules
# Mutations: analyze(content, filename, framework)

Supported Formats and Providers

FormatProviderExtension
Terraform HCLAWS, Azure, GCP.tf
CloudFormationAWS.yaml, .yml, .json
Kubernetes manifestsKubernetes.yaml, .yml

Install

Install from PyPI:

pip install threatmap

Or for local development:

git clone https://github.com/bogdanticu88/threatmap.git
cd threatmap
pip install -e .

Usage

Scan a directory and print a Markdown report to stdout:

threatmap scan ./terraform/

Scan multiple paths and write a JSON report to a file:

threatmap scan ./terraform/ ./k8s/ ./cloudformation/ --format json --output report.json

Generate an interactive HTML report or a SARIF report for GitHub Security:

threatmap scan ./infra/ --format html --output report.html
threatmap scan ./infra/ --format sarif --output report.sarif

CI gate — exit code 1 if any CRITICAL or HIGH threat is found:

threatmap scan ./infra/ --fail-on HIGH --output threat-report.md

Print a terminal summary table only, without writing a full report:

threatmap scan ./infra/ --summary

Use ASCII-only severity indicators (no emojis) for environments that don't support Unicode:

threatmap scan ./infra/ --ascii --output report.md

Analyze using different threat modeling frameworks:

# STRIDE (default)
threatmap scan ./infra/ --framework stride

# MITRE ATT&CK (maps to tactics and techniques)
threatmap scan ./infra/ --framework mitre --format json

# PASTA (asset-centric threat modeling)
threatmap scan ./infra/ --framework pasta --format json

Threat Modeling Frameworks

STRIDE (73 rules)

  • Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege
  • Threat-centric approach ideal for identifying attack surface
  • Provider-specific: AWS (22 rules), Azure (19 rules), GCP (15 rules), Kubernetes (17 rules)
  • Best for: Traditional threat modeling, security architecture reviews

MITRE ATT&CK (11 rules, 14 tactics)

  • Maps infrastructure threats to real-world adversary tactics and techniques
  • Resource-aware technique selection for accurate TTP mapping
  • Tactics: Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Collection, Command & Control, Exfiltration, Impact, Lateral Movement
  • Best for: Aligning with threat intelligence, incident response planning, red team exercises

PASTA (12 rules, asset-centric)

  • Process for Attack Simulation and Threat Analysis
  • Asset-centric approach focusing on what needs protection
  • Asset types: Data, Identity, Compute, Network, Infrastructure
  • Threat actors: Internal, External, Misconfiguration, Supply Chain
  • Best for: Risk-based prioritization, asset protection strategies, supply chain threats

Sample Report Output

Running threatmap scan ./examples --output report.md against the bundled examples produces a full Markdown report. Below is a representative excerpt.

STRIDE Threat Table

IDSeveritySTRIDE CategoryResourceDescription
T-001🔴 CRITICALInformation DisclosureAuditBucketS3 bucket 'AuditBucket' has no public access block configured — bucket may be publicly accessible.
T-002🔴 CRITICALSpoofingWebSecurityGroupSecurity group 'WebSecurityGroup' exposes SSH/RDP (port 22/3389) to 0.0.0.0/0.
T-003🔴 CRITICALElevation of Privilegeapp_contributorRole assignment 'app_contributor' grants the privileged role 'Contributor'.
T-006🟠 HIGHInformation DisclosureAuditBucketS3 bucket 'AuditBucket' does not have server-side encryption configured.
T-008🟠 HIGHElevation of PrivilegeapiContainer 'api' in Deployment 'api' may run as root (no runAsNonRoot=true or runAsUser=0).
T-011🟠 HIGHElevation of PrivilegewebEC2 instance 'web' allows IMDSv1 — metadata service accessible without session tokens, enabling SSRF-based credential theft.

Mitigation Detail (excerpt)

### T-002 — Spoofing (CRITICAL)

Resource:   AWS::EC2::SecurityGroup.WebSecurityGroup
Property:   ingress.ssh_rdp_open
Finding:    Security group 'WebSecurityGroup' exposes SSH/RDP (port 22/3389) to 0.0.0.0/0.
Mitigation: Remove public SSH/RDP access. Use AWS Systems Manager Session Manager
            or a bastion host with IP restrictions.

Data Flow Diagram (Mermaid)

The report appends a Mermaid flowchart LR diagram. Nodes are coloured by worst-case severity (🔴 red = CRITICAL, 🟠 orange = HIGH). Paste the block into any Mermaid renderer or view it directly on GitHub.

Download Tool