
threatcl v0.6.1
अपने थ्रेट मॉडल्स को HCL के साथ दस्तावेज़ित करना
threatcl
HCL के साथ धमकी मॉडलिंग
hcltm का क्या हुआ?
hcltm का नाम बदलकर threatcl कर दिया गया है। स्वागत है!
अवलोकन
[!TIP] नया दस्तावेज़ पढ़ना चाहते हैं? threatcl.dev पर जाएँ।
एक धमकी मॉडल को दस्तावेज़ित करने के कई अलग-अलग तरीके हैं। एक सरल टेक्स्ट फ़ाइल से लेकर, अधिक गहन वर्ड दस्तावेज़ों तक, केंद्रीकृत समाधान में पूरी तरह से साधनबद्ध धमकी मॉडल तक। धमकी मॉडल के दो सबसे मूल्यवान गुण हैं: धमकियों को स्पष्ट रूप से दस्तावेज़ित करने की क्षमता, और मूल्यवान परिवर्तन लाने की क्षमता।
threatcl का उद्देश्य निम्नलिखित लक्ष्यों पर ध्यान केंद्रित करके एक सिस्टम धमकी मॉडल को दस्तावेज़ित करने के लिए DevOps-प्रथम दृष्टिकोण प्रदान करना है:
- सरल टेक्स्ट-फ़ाइल प्रारूप
- सरल CLI-संचालित उपयोगकर्ता अनुभव
- संस्करण नियंत्रण प्रणालियों (VCS) में एकीकरण
यह रिपॉज़िटरी threatcl CLI सॉफ़्टवेयर का घर है। threatcl spec HCL2 पर आधारित है, जो HashiCorp की कॉन्फ़िगरेशन भाषा है, जिसका उद्देश्य "मनुष्यों के लिए पढ़ने और लिखने में सुखद, और एक JSON-आधारित वैरिएंट जो मशीनों के लिए उत्पन्न करना और पार्स करना आसान है" होना है। threatcl spec github.com/threatcl/spec पर रहता है। threatcl CLI सॉफ़्टवेयर और threatcl spec को मिलाकर, चिकित्सक HCL में एक सिस्टम धमकी मॉडल परिभाषित कर सकते हैं, उदाहरण के लिए:```hcl
threatmodel "Tower of London" {
description = "A historic castle"
author = "@xntrik"
attributes { new_initiative = "true" internet_facing = "true" initiative_size = "Small" }
information_asset "crown jewels" { description = "including the imperial state crown" information_classification = "Confidential" }
usecase { description = "The Queen can fetch the crown" }
third_party_dependency "community watch" { description = "The community watch helps guard the premise" uptime_dependency = "degraded" }
threat "Crown theft" { description = "Someone who isn't the Queen steals the crown" impacts = ["Confidentiality"]
control "Guards" {
description = "Trained guards patrol tower"
risk_reduction = 75
}
}
data_flow_diagram_v2 "dfd name" { // ... see below for more information }
}
See [Data Flow Diagram](#data-flow-diagram) for more information on how to construct data flow diagrams that may be converted to PNGs automatically.
To see an example of how to reference pre-defined control libraries for the [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/) and [AWS Security Checklist](https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Checklist.pdf) see [examples/tm3.hcl](https://github.com/threatcl/threatcl/blob/main/examples/tm3.hcl). We also have the [MITRE ATT&CK Controls](https://attack.mitre.org/mitigations/enterprise/) [here](https://github.com/threatcl/threatcl/blob/main/examples/MITRE_ATTACK_controls.hcl).
You can also include an external threatmodel into your own, to reference and use all its information. You can see [examples/including-example/corp-app.hcl](https://github.com/threatcl/threatcl/blob/main/examples/including-example/corp-app.hcl) as an example.
To see a full description of the spec, see [here](https://github.com/threatcl/threatcl/blob/main/spec.hcl) or run:```bash
threatcl generate boilerplate
threatcl JSON फ़ाइलों को भी प्रोसेस करेगा, लेकिन एकमात्र चेतावनी यह है कि आयात मॉड्यूल और वेरिएबल काम नहीं करेंगे। आप एक उदाहरण के रूप में examples/tm1.json देख सकते हैं।
HCL क्यों?
HCL, HashiCorp के उत्पादों में उपयोग की जाने वाली प्राथमिक कॉन्फ़िगरेशन भाषा है, विशेष रूप से, Terraform - उनका ओपन-सोर्स इन्फ्रास्ट्रक्चर-एज़-कोड सॉफ़्टवेयर। मैंने कुछ समय के लिए HashiCorp में काम किया और भाषा वास्तव में मुझे पसंद आ गई, साथ ही, यदि DevOps और सॉफ़्टवेयर इंजीनियर भाषा का उपयोग कर रहे हैं, तो वे थ्रेट मॉडल को कैसे दस्तावेज़ित करते हैं, इसे सरल बनाना threatcl के लक्ष्यों के अनुरूप है।
आप threatcl का उपयोग JSON के साथ कर सकते हैं, लेकिन आप कुछ सुविधाएं खो देंगे। अधिक जानकारी के लिए, examples/ फ़ोल्डर देखें।
उन्हें केवल MD में दस्तावेज़ित क्यों नहीं करते?
मुझे ऐसे फॉर्मेट का उपयोग करने का विचार पसंद आया जिसके साथ प्रोग्रामेटिक रूप से इंटरैक्ट किया जा सके।
प्रशंसा और संदर्भ
threatcl की एक विशेषता HCL फ़ाइलों से डेटा फ़्लो डायग्राम का स्वचालित निर्माण है। यह Marqeta और Blake Hitchcock द्वारा go-dfd पैकेज का लाभ उठाता है। DevOps की गति पर थ्रेट मॉडल पर उनका ब्लॉग पोस्ट ज़रूर देखें।
इसके अलावा, मैं HashiCorp में Jamie Finnigan और Talha Tariq को धन्यवाद देना चाहूंगा, जिन्होंने मुझे HashiCorp के साथ काम खत्म करने के बाद भी इस ओपन-सोर्स टूल पर काम जारी रखने की अनुमति दी।
साथ ही OpenThreatModel specification के लिए IriusRisk टीम को भी धन्यवाद।
threatcl cli
स्थापना
नवीनतम संस्करण releases से डाउनलोड करें और threatcl बाइनरी को अपने PATH में ले जाएं।
Homebrew के साथ स्थापित करें
threatcl को Homebrew के साथ स्थापित करें — फॉर्मूला homebrew-core में रहता है:```bash
brew install threatcl
## Docker के साथ चलाएं```bash
docker run --rm -it ghcr.io/threatcl/threatcl:latest
रिलीज़ का सत्यापन (बिल्ड प्रोवेनेंस)
प्रत्येक टैग किया गया रिलीज़ SLSA बिल्ड प्रोवेनेंस के साथ आता है —
Sigstore-हस्ताक्षरित, कुंजीहीन प्रमाणपत्र जो GitHub Actions रिलीज़ पाइपलाइन द्वारा उत्पन्न होते हैं
(GitHub OIDC → Fulcio, कोई साइनिंग कुंजी नहीं)। आप सत्यापित कर सकते हैं कि कोई बाइनरी या
कंटेनर छवि वास्तव में इस रेपो की रिलीज़ वर्कफ़्लो से बनाई गई है,
GitHub CLI (gh attestation verify — कोई अतिरिक्त टूलिंग या विश्वसनीय कुंजी प्रबंधित करने की आवश्यकता नहीं) का उपयोग करके।
डाउनलोड किए गए आर्काइव (या SHA256SUMS फ़ाइल) को सत्यापित करें:```bash
gh attestation verify threatcl_.tar.gz --repo threatcl/threatcl
कंटेनर इमेज को सत्यापित करें (टैग स्वचालित रूप से इसके डाइजेस्ट में हल हो जाता है):```bash
gh attestation verify oci://ghcr.io/threatcl/threatcl:<version> --repo threatcl/threatcl
आप जो सटीक इमेज चलाते हैं उसे पिन करने के लिए, स्वयं डाइजेस्ट हल करें और डाइजेस्ट द्वारा सत्यापित (और पुल) करें:```bash digest=$(docker buildx imagetools inspect ghcr.io/threatcl/threatcl: --format '{{ .Manifest.Digest }}') gh attestation verify oci://ghcr.io/threatcl/threatcl@${digest} --repo threatcl/threatcl
See [docs/SLSA.md](https://github.com/threatcl/threatcl/blob/main/docs/SLSA.md) for the full supply-chain posture.
## GitHub Actions के साथ चलाएं
`threatcl` को https://github.com/threatcl/threatcl-action के साथ सीधे आपके GitHub रेपो में एकीकृत किया जा सकता है। यह आपके खतरे के मॉडल को प्रबंधित करने के आदर्श तरीकों में से एक है, और आपके संस्करण नियंत्रण प्रणालियों में एकीकृत करने के लक्ष्य को पूरा करने में मदद करता है।
## स्रोत से निर्माण
1. इस रिपॉजिटरी को क्लोन करें।
2. निर्देशिका में बदलें, `threatcl`
3. `make bootstrap`
4. `make build`
`threatcl` में योगदान पर और सहायता के लिए कृपया [CHANGELOG.md](https://github.com/threatcl/threatcl/blob/main/CHANGELOG.md) देखें।
## उपयोग
किसी भी उप-कमांड पर सहायता के लिए `-h` फ़्लैग का उपयोग करें।```bash
$ threatcl
Usage: threatcl [--version] [--help] <command> [<args>]