अपडेट पर वापस जाएँ
New releaseAug 1, 2026

threatcl v0.6.5

अपने थ्रेट मॉडल्स को HCL के साथ दस्तावेज़ित करना

साझा करें

threatcl

HCL के साथ धमकी मॉडलिंग

hcltm का क्या हुआ?

hcltm का नाम बदलकर threatcl कर दिया गया है। स्वागत है!

अवलोकन

[!TIP] नया दस्तावेज़ पढ़ना चाहते हैं? threatcl.dev पर जाएँ।

एक धमकी मॉडल को दस्तावेज़ित करने के कई अलग-अलग तरीके हैं। एक सरल टेक्स्ट फ़ाइल से लेकर, अधिक गहन वर्ड दस्तावेज़ों तक, केंद्रीकृत समाधान में पूरी तरह से साधनबद्ध धमकी मॉडल तक। धमकी मॉडल के दो सबसे मूल्यवान गुण हैं: धमकियों को स्पष्ट रूप से दस्तावेज़ित करने की क्षमता, और मूल्यवान परिवर्तन लाने की क्षमता।

threatcl का उद्देश्य निम्नलिखित लक्ष्यों पर ध्यान केंद्रित करके एक सिस्टम धमकी मॉडल को दस्तावेज़ित करने के लिए DevOps-प्रथम दृष्टिकोण प्रदान करना है:

  • सरल टेक्स्ट-फ़ाइल प्रारूप
  • सरल CLI-संचालित उपयोगकर्ता अनुभव
  • संस्करण नियंत्रण प्रणालियों (VCS) में एकीकरण

यह रिपॉज़िटरी threatcl CLI सॉफ़्टवेयर का घर है। threatcl spec HCL2 पर आधारित है, जो HashiCorp की कॉन्फ़िगरेशन भाषा है, जिसका उद्देश्य "मनुष्यों के लिए पढ़ने और लिखने में सुखद, और एक JSON-आधारित वैरिएंट जो मशीनों के लिए उत्पन्न करना और पार्स करना आसान है" होना है। threatcl spec github.com/threatcl/spec पर रहता है। threatcl CLI सॉफ़्टवेयर और threatcl spec को मिलाकर, चिकित्सक HCL में एक सिस्टम धमकी मॉडल परिभाषित कर सकते हैं, उदाहरण के लिए:```hcl threatmodel "Tower of London" { description = "A historic castle" author = "@xntrik"

attributes { new_initiative = "true" internet_facing = "true" initiative_size = "Small" }

information_asset "crown jewels" { description = "including the imperial state crown" information_classification = "Confidential" }

usecase { description = "The Queen can fetch the crown" }

third_party_dependency "community watch" { description = "The community watch helps guard the premise" uptime_dependency = "degraded" }

threat "Crown theft" { description = "Someone who isn't the Queen steals the crown" impacts = ["Confidentiality"]

control "Guards" {
  description = "Trained guards patrol tower"
  risk_reduction = 75
}

}

data_flow_diagram_v2 "dfd name" { // ... see below for more information }

}

See [Data Flow Diagram](#data-flow-diagram) for more information on how to construct data flow diagrams that may be converted to PNGs automatically.

To see an example of how to reference pre-defined control libraries for the [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/) and [AWS Security Checklist](https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Checklist.pdf) see [examples/tm3.hcl](https://github.com/threatcl/threatcl/blob/HEAD/examples/tm3.hcl). We also have the [MITRE ATT&CK Controls](https://attack.mitre.org/mitigations/enterprise/) [here](https://github.com/threatcl/threatcl/blob/HEAD/examples/MITRE_ATTACK_controls.hcl).

You can also include an external threatmodel into your own, to reference and use all its information. You can see [examples/including-example/corp-app.hcl](https://github.com/threatcl/threatcl/blob/HEAD/examples/including-example/corp-app.hcl) as an example.

To see a full description of the spec, see [here](https://github.com/threatcl/threatcl/blob/HEAD/spec.hcl) or run:```bash
threatcl generate boilerplate

threatcl JSON फ़ाइलों को भी प्रोसेस करेगा, लेकिन एकमात्र चेतावनी यह है कि आयात मॉड्यूल और वेरिएबल काम नहीं करेंगे। आप एक उदाहरण के रूप में examples/tm1.json देख सकते हैं।

HCL क्यों?

HCL, HashiCorp के उत्पादों में उपयोग की जाने वाली प्राथमिक कॉन्फ़िगरेशन भाषा है, विशेष रूप से, Terraform - उनका ओपन-सोर्स इन्फ्रास्ट्रक्चर-एज़-कोड सॉफ़्टवेयर। मैंने कुछ समय के लिए HashiCorp में काम किया और भाषा वास्तव में मुझे पसंद आ गई, साथ ही, यदि DevOps और सॉफ़्टवेयर इंजीनियर भाषा का उपयोग कर रहे हैं, तो वे थ्रेट मॉडल को कैसे दस्तावेज़ित करते हैं, इसे सरल बनाना threatcl के लक्ष्यों के अनुरूप है।

आप threatcl का उपयोग JSON के साथ कर सकते हैं, लेकिन आप कुछ सुविधाएं खो देंगे। अधिक जानकारी के लिए, examples/ फ़ोल्डर देखें।

उन्हें केवल MD में दस्तावेज़ित क्यों नहीं करते?

मुझे ऐसे फॉर्मेट का उपयोग करने का विचार पसंद आया जिसके साथ प्रोग्रामेटिक रूप से इंटरैक्ट किया जा सके।

प्रशंसा और संदर्भ

threatcl की एक विशेषता HCL फ़ाइलों से डेटा फ़्लो डायग्राम का स्वचालित निर्माण है। यह Marqeta और Blake Hitchcock द्वारा go-dfd पैकेज का लाभ उठाता है। DevOps की गति पर थ्रेट मॉडल पर उनका ब्लॉग पोस्ट ज़रूर देखें।

इसके अलावा, मैं HashiCorp में Jamie Finnigan और Talha Tariq को धन्यवाद देना चाहूंगा, जिन्होंने मुझे HashiCorp के साथ काम खत्म करने के बाद भी इस ओपन-सोर्स टूल पर काम जारी रखने की अनुमति दी।

साथ ही OpenThreatModel specification के लिए IriusRisk टीम को भी धन्यवाद।

threatcl cli

स्थापना

नवीनतम संस्करण releases से डाउनलोड करें और threatcl बाइनरी को अपने PATH में ले जाएं।

Homebrew के साथ स्थापित करें

threatcl को Homebrew के साथ स्थापित करें — फॉर्मूला homebrew-core में रहता है:```bash brew install threatcl

## Docker के साथ चलाएं```bash
docker run --rm -it ghcr.io/threatcl/threatcl:latest

रिलीज़ का सत्यापन (बिल्ड प्रोवेनेंस)

प्रत्येक टैग किया गया रिलीज़ SLSA बिल्ड प्रोवेनेंस के साथ आता है — Sigstore-हस्ताक्षरित, कुंजीहीन प्रमाणपत्र जो GitHub Actions रिलीज़ पाइपलाइन द्वारा उत्पन्न होते हैं (GitHub OIDC → Fulcio, कोई साइनिंग कुंजी नहीं)। आप सत्यापित कर सकते हैं कि कोई बाइनरी या कंटेनर छवि वास्तव में इस रेपो की रिलीज़ वर्कफ़्लो से बनाई गई है, GitHub CLI (gh attestation verify — कोई अतिरिक्त टूलिंग या विश्वसनीय कुंजी प्रबंधित करने की आवश्यकता नहीं) का उपयोग करके।

डाउनलोड किए गए आर्काइव (या SHA256SUMS फ़ाइल) को सत्यापित करें:```bash gh attestation verify threatcl_.tar.gz --repo threatcl/threatcl

कंटेनर इमेज को सत्यापित करें (टैग स्वचालित रूप से इसके डाइजेस्ट में हल हो जाता है):```bash
gh attestation verify oci://ghcr.io/threatcl/threatcl:<version> --repo threatcl/threatcl

आप जो सटीक इमेज चलाते हैं उसे पिन करने के लिए, स्वयं डाइजेस्ट हल करें और डाइजेस्ट द्वारा सत्यापित (और पुल) करें:```bash digest=$(docker buildx imagetools inspect ghcr.io/threatcl/threatcl: --format '{{ .Manifest.Digest }}') gh attestation verify oci://ghcr.io/threatcl/threatcl@${digest} --repo threatcl/threatcl

See [docs/SLSA.md](https://github.com/threatcl/threatcl/blob/HEAD/docs/SLSA.md) for the full supply-chain posture.

## GitHub Actions के साथ चलाएं

`threatcl` को https://github.com/threatcl/threatcl-action के साथ सीधे आपके GitHub रेपो में एकीकृत किया जा सकता है। यह आपके खतरे के मॉडल को प्रबंधित करने के आदर्श तरीकों में से एक है, और आपके संस्करण नियंत्रण प्रणालियों में एकीकृत करने के लक्ष्य को पूरा करने में मदद करता है।

## स्रोत से निर्माण

1. इस रिपॉजिटरी को क्लोन करें।
2. निर्देशिका में बदलें, `threatcl`
3. `make bootstrap`
4. `make build`

`threatcl` में योगदान पर और सहायता के लिए कृपया [CHANGELOG.md](https://github.com/threatcl/threatcl/blob/HEAD/CHANGELOG.md) देखें।

## उपयोग

किसी भी उप-कमांड पर सहायता के लिए `-h` फ़्लैग का उपयोग करें।```bash
$ threatcl
Usage: threatcl [--version] [--help] <command> [<args>]

Available commands are:
    cloud        Interact with ThreatCL Cloud services
    dashboard    Generate markdown files from existing HCL threatmodel file(s)
    dfd          Generate Data Flow Diagram PNG or DOT files from existing HCL threatmodel file(s)
    export       Export threat models into other formats
    generate     Generate an HCL Threat Model
    list         List Threatmodels found in HCL file(s)
    mcp          Model Context Protocol (MCP) server for threatcl
    mermaid      Output raw mermaid source from 'mermaid' blocks in existing HCL threatmodel file(s)
    query        Execute GraphQL queries against threat model data
    server       Start a GraphQL API server for threat models
    terraform    Parse output from 'terraform show -json'
    validate     Validate existing HCL Threatmodel file(s)
    view         View existing HCL Threatmodel file(s)

(वैकल्पिक) कॉन्फ़िग फ़ाइल

अधिकांश threatcl कमांड में एक -config फ़्लैग होता है जो आपको एक config.hcl फ़ाइल निर्दिष्ट करने की अनुमति देता है। इस फ़ाइल के अंतर्गत HCL का उपयोग threatcl की कुछ डिफ़ॉल्ट विशेषताओं को ओवरराइट करने के लिए किया जा सकता है। ये नीचे सूचीबद्ध हैं:

  • इनिशिएटिव आकार - डिफ़ॉल्ट: "Undefined", "Small", "Medium", "Large"
  • डिफ़ॉल्ट इनिशिएटिव आकार - डिफ़ॉल्ट: "Undefined"
  • सूचना वर्गीकरण - डिफ़ॉल्ट: "Restricted", "Confidential", "Public"
  • डिफ़ॉल्ट सूचना वर्गीकरण - डिफ़ॉल्ट: "Confidential"
  • प्रभाव प्रकार - डिफ़ॉल्ट: "Confidentiality", "Integrity", "Availability"
  • STRIDE तत्व - डिफ़ॉल्ट: "Spoofing", "Tampering", "Info Disclosure", "Denial Of Service", "Elevation Of Privilege"
  • अपटाइम निर्भरता वर्गीकरण - डिफ़ॉल्ट: "none", "degraded", "hard", "operational"
  • डिफ़ॉल्ट अपटाइम निर्भरता वर्गीकरण - डिफ़ॉल्ट: "none"

उदाहरण के लिए:```hcl initiative_sizes = ["S", "M", "L"] default_initiative_size = "M" info_classifications = ["1", "2"] default_info_classification = "1" impact_types = ["big", "small"] strides = ["S", "T"] uptime_dep_classifications = ["N", "D"] default_uptime_dep_classification = "N"

यदि आप इन विशेषताओं को संशोधित करते हैं, तो आपको अन्य कार्यों के लिए कॉन्फ़िग फ़ाइल प्रदान करना याद रखना होगा, क्योंकि इससे मान्यकरण या डैशबोर्ड निर्माण प्रभावित हो सकता है।

## क्लाउड कमांड्स

क्लाउड उप-कमांड्स के बारे में अधिक जानने के लिए https://threatcl.dev/cloud/overview/ पर जाएं।

## सूची और देखें

`threatcl list` और `threatcl view` कमांड्स का उपयोग `threatcl` स्पेक HCL फ़ाइलों से डेटा को सूचीबद्ध और देखने के लिए किया जा सकता है।```bash
$ threatcl list examples/*
#  File              Threatmodel      Author
1  examples/tm1.hcl  Tower of London  @xntrik
2  examples/tm1.hcl  Fort Knox        @xntrik
3  examples/tm2.hcl  Modelly model    @xntrik

मान्य करें

threatcl validate कमांड का उपयोग threatcl विनिर्देश HCL फ़ाइल को मान्य करने के लिए किया जाता है।```bash $ threatcl validate examples/* Validated 3 threatmodels in 3 files

### अपरिवर्तनीयताएँ

`threatcl validate` संगठन-व्यापी अपरिवर्तनीयताएँ भी लागू कर सकता है — मशीन-जाँचे गए नियम जैसे "कोई सार्वजनिक एंडपॉइंट अप्रमाणित नहीं होना चाहिए" या "सभी इंटरनेट-मुखी सुविधाओं को ऑडिट लॉगिंग का दस्तावेजीकरण करना चाहिए" — प्रत्येक मान्य खतरे के मॉडल के विरुद्ध:```bash
$ threatcl validate -invariants=invariants.hcl ./models/
Validated 4 threatmodels in 3 files
Invariant violation [error] 'threats_have_implemented_controls': threat 'Credential theft' in threatmodel 'Payments' (models/payments.hcl): Every threat must have at least one implemented control
Checked 3 invariants against 4 threatmodels: 1 errors, 0 warnings, 1 exemptions

Invariants live in their own HCL file, target a specific collection (threats, controls, DFD processes, flows, ...), और अपनी शर्त को मूल HCL अभिव्यक्ति के रूप में व्यक्त करते हैं। वे error/warning गंभीरता और औचित्य के साथ प्रति-मॉडल छूट का समर्थन करते हैं। देखें docs/invariants.md

Export

The threatcl export command का उपयोग threatcl खतरा मॉडल (या मॉडल) को मूल JSON प्रतिनिधित्व (डिफ़ॉल्ट रूप से), या OTM json प्रतिनिधित्व में, या यहां तक कि hcl में वापस निर्यात करने के लिए किया जाता है (जो गतिशील खतरा मॉडल से ताजा HCL आउटपुट करने के लिए उपयोगी है)। आप उन्हें -output ध्वज के साथ सीधे एक फ़ाइल में भी सहेज सकते हैं।```bash $ threatcl export -format=otm examples/tm1.hcl [{"assets":[{"description":"including the imperial state crown","id":"crown-jewels","name":"crown jewels","risk":{"availability":0,"confidentiality":0,"integrity":0}}],"mitigations":[{"attributes":{"implementation_notes":"They are trained to be guards as well","implemented":true},"description":"Lots of guards patrol the area","id":"lots-of-guards","name":"Lots of Guards","riskReduction":80}],"otmVersion":"0.2.0","project":{"attributes":{"initiative_size":"Small","internet_facing":true,"network_segment":"dmz","new_initiative":true},"description":"A historic castle","id":"tower-of-london","name":"Tower of London","owner":"@xntrik"},"threats":[{"categories":["Confidentiality"],"description":"Someone who isn't the Queen steals the crown","id":"threat-1","name":"Threat 1","risk":{"impact":0,"likelihood":null}}]},{"assets":[{"description":"Lots of gold","id":"gold","name":"Gold","risk":{"availability":0,"confidentiality":0,"integrity":0}}],"mitigations":[{"attributes":{"implemented":true},"description":"A large wall surrounds the fort","id":"big-wall","name":"Big Wall","riskReduction":80}],"otmVersion":"0.2.0","project":{"attributes":{"initiative_size":"Small","internet_facing":true,"new_initiative":false},"description":"A .. fort?","id":"fort-knox","name":"Fort Knox","owner":"@xntrik"},"threats":[{"categories":["Confidentiality"],"description":"Someone steals the gold","id":"threat-1","name":"Threat 1","risk":{"impact":0,"likelihood":null}}]}]

## Generate

`threatcl generate` कमांड का उपयोग या तो एक सामान्य `boilerplate` `threatcl` स्पेक HCL फ़ाइल आउटपुट करने के लिए किया जाता है, या, इंटरैक्टिव रूप से उपयोगकर्ता से प्रश्न पूछकर फिर एक `threatcl` स्पेक HCL फ़ाइल आउटपुट करने के लिए।

### Generate Interactive

निम्नलिखित उदाहरण देखें:```bash
threatcl generate interactive

इंटरैक्टिव संपादक उत्पन्न करें

यदि आप सीधे अपने $EDITOR में काम करना पसंद करते हैं, तो चलाएँ:```bash threatcl generate interactive editor

यह आपके संपादक को एक बुनियादी HCL खतरा मॉडल के साथ खोलेगा। यदि आप निर्माण के बाद मॉडल को मान्य करना चाहते हैं, तो `-validate` फ्लैग का उपयोग करें।

## MCP

`threatcl mcp` कमांड एक स्थानीय [MCP](https://modelcontextprotocol.io/introduction) सर्वर को उजागर करता है ताकि आप MCP होस्ट के माध्यम से threatcl hcl फ़ाइलों के साथ बातचीत कर सकें, उदाहरण के लिए AI/LLM अनुप्रयोग जैसे [Claude Desktop](https://claude.ai/download), [Cursor](https://www.cursor.com/), या कोई भी अन्य एप्लिकेशन जो MCP का समर्थन करते हैं।

कमांड एक एकल, वैकल्पिक तर्क `-dir=<path>` लेता है जो अतिरिक्त MCP टूल्स को उस पथ के भीतर फ़ाइलों के साथ बातचीत करने की अनुमति देता है। इस सेटिंग के बिना, MCP टूल्स स्ट्रिंग्स के साथ बातचीत कर सकते हैं, लेकिन अंतर्निहित फ़ाइल सिस्टम के साथ बातचीत करने के लिए MCP होस्ट के भीतर अन्य तंत्रों पर निर्भर होंगे।

यह कहना उचित होगा कि यह कार्यक्षमता इस समय काफी बीटा है।

## LSP (Language Server)

`threatcl lsp` कमांड stdio पर एक [Language Server Protocol](https://microsoft.github.io/language-server-protocol/) सर्वर चलाता है, जो LSP-सक्षम संपादकों को threatcl HCL खतरा मॉडल के लिए लाइव डायग्नोस्टिक्स, पूर्णता, होवर, दस्तावेज़ प्रतीक और फ़ॉर्मेटिंग प्रदान करता है।

इसे आपके संपादक के LSP क्लाइंट द्वारा लॉन्च किया जाता है, न कि हाथ से चलाया जाता है। क्योंकि threatcl फ़ाइलें टेराफ़ॉर्म और अन्य HCL बोलियों के साथ `.hcl` एक्सटेंशन साझा करती हैं, `*.tm.hcl` पर मैच करना (या क्लाइंट को आपके threat-model वर्कस्पेस तक सीमित करना) टेराफ़ॉर्म लैंग्वेज सर्वर से लड़ने से बचाता है।

एडिटर वायरिंग (Neovim, Helix, VS Code, Zed) और वर्तमान सीमाओं के लिए [docs/lsp.md](https://github.com/threatcl/threatcl/blob/HEAD/docs/lsp.md) देखें।

## Server (GraphQL API)

`threatcl server` कमांड एक GraphQL API सर्वर शुरू करता है जो आपके खतरा मॉडल को प्रोग्रामेटिक क्वेरी और एकीकरण के लिए HTTP के माध्यम से उजागर करता है।

### Basic Usage```bash
# Start the server
$ threatcl server -dir ./examples

# With file watching for auto-reload
$ threatcl server -dir ./examples -watch

# Custom port
$ threatcl server -dir ./examples -port 3000

http://localhost:8080 पर जाकर इंटरैक्टिव GraphQL Playground तक पहुँचें।

उदाहरण क्वेरी```graphql

query { stats { totalThreatModels totalThreats implementedControls }

threatModels(filter: { internetFacing: true }) { name threats { description controls { name implemented } } } }

### दस्तावेज़ीकरण

पूर्ण API दस्तावेज़ीकरण, स्कीमा संदर्भ, उन्नत क्वेरी और एकीकरण उदाहरणों के लिए, देखें:
- **पूर्ण API दस्तावेज़ीकरण**: [docs/graphql-api.md](https://github.com/threatcl/threatcl/blob/HEAD/docs/graphql-api.md)
- **क्वेरी उदाहरण**: [examples/graphql-queries.md](https://github.com/threatcl/threatcl/blob/HEAD/examples/graphql-queries.md)

## क्वेरी (GraphQL CLI)

`threatcl query` कमांड सर्वर शुरू किए बिना सीधे कमांड लाइन से GraphQL क्वेरी निष्पादित करता है। यह ऑटोमेशन, CI/CD पाइपलाइन और शेल स्क्रिप्टिंग के लिए आदर्श है।

### मूल उपयोग```bash
# Get statistics
$ threatcl query -dir ./examples -query '{ stats { totalThreats } }'

# Query from file
$ threatcl query -dir ./examples -file queries/get-stats.graphql

# Use in scripts
$ THREATS=$(threatcl query -dir ./examples \
    -query '{ stats { totalThreats } }' \
    -output compact | jq -r '.data.stats.totalThreats')
$ echo "Found $THREATS threats"

आउटपुट प्रारूप

  • pretty (डिफ़ॉल्ट): इंडेंटेशन के साथ स्वरूपित JSON
  • json: pretty के समान
  • compact: स्क्रिप्टिंग के लिए एकल-पंक्ति JSON

चर के साथ क्वेरी```bash

$ threatcl query -dir ./examples
-query 'query($author: String) { threatModels(filter: {author: $author}) { name } }'
-vars '{"author": "John Doe"}'

### CI/CD उदाहरण```bash
#!/bin/bash
# Check if all controls are implemented before deployment

UNIMPLEMENTED=$(threatcl query -dir ./threatmodels \
  -query '{ stats { totalControls implementedControls } }' \
  -output compact | jq -r '.data.stats.totalControls - .data.stats.implementedControls')

if [ "$UNIMPLEMENTED" -gt 0 ]; then
  echo "ERROR: $UNIMPLEMENTED controls are not yet implemented"
  exit 1
fi

echo "All controls implemented, proceeding with deployment"

उपलब्ध क्वेरी और GraphQL स्कीमा के लिए docs/graphql-api.md देखें।

डैशबोर्ड

threatcl dashboard कमांड threatcl स्पेक HCL फ़ाइलों को लेता है, और कई markdown और png फ़ाइलें उत्पन्न करता है, उन्हें चयनित फ़ोल्डर में डालता है।```bash $ threatcl dashboard -overwrite -outdir=dashboard-example examples/* Created the 'dashboard-example' directory Writing dashboard markdown files to 'dashboard-example' and overwriting existing files Successfully wrote to 'dashboard-example/tm1-toweroflondon.md' Successfully wrote to 'dashboard-example/tm1-fortknox.md' Successfully wrote to 'dashboard-example/tm2-modellymodel.png' Successfully wrote to 'dashboard-example/tm2-modellymodel.md' Successfully wrote to 'dashboard-example/dashboard.md'

### कस्टम मार्कडाउन टेम्पलेट्स

`threatcl dashboard` कमांड वैकल्पिक फ़्लैग्स भी ले सकता है ताकि कस्टम टेम्पलेट्स निर्दिष्ट किए जा सकें (जैसा कि Golang के [text/template](https://pkg.go.dev/text/template) में है)।

डैशबोर्ड टेम्पलेट फ़ाइल निर्दिष्ट करने के लिए, `-dashboard-template` फ़्लैग का उपयोग करें। एक उदाहरण के लिए, [dashboard-template.tpl](https://github.com/threatcl/threatcl/blob/HEAD/examples/dashboard-template.tpl) देखें।

थ्रेटमॉडल टेम्पलेट फ़ाइल निर्दिष्ट करने के लिए, `-threatmodel-template` फ़्लैग का उपयोग करें। एक उदाहरण के लिए, [threatmodel-template.tpl](https://github.com/threatcl/threatcl/blob/HEAD/examples/threatmodel-template.tpl) देखें।

### डैशबोर्ड इंडेक्स फ़ाइल के लिए कस्टम फ़ाइलनाम

`threatcl dashboard` कमांड एक वैकल्पिक फ़्लैग भी ले सकता है ताकि जनरेट की गई डैशबोर्ड फ़ाइल के लिए फ़ाइलनाम निर्दिष्ट किया जा सके। डिफ़ॉल्ट रूप से यह फ़ाइल `dashboard.md` है। इस फ़ाइलनाम को बदलने के लिए बिना एक्सटेंशन के `-dashboard-filename` फ़्लैग का उपयोग करें।

## डेटा फ़्लो डायग्राम

जैसा कि [spec](https://github.com/threatcl/threatcl/blob/HEAD/spec.hcl) में उल्लेखित है, एक `threatmodel` में `data_flow_diagram_v2` ब्लॉक शामिल हो सकते हैं। एक सरल DFD का उदाहरण [यहाँ](https://github.com/threatcl/threatcl/blob/HEAD/examples/tm2.hcl) उपलब्ध है। पुराने, एकल-उपयोग वाले ब्लॉक `data_flow_diagram` को किसी बिंदु पर हटा दिया जाएगा, इसलिए `data_flow_diagram_v2` नामित ब्लॉक का उपयोग करना बेहतर है, क्योंकि इस तरह आपके पास कई संबंधित DFD हो सकते हैं।

`threatcl dfd` कमांड `threatcl` spec HCL फ़ाइलों को लेता है, और कई png फ़ाइलें जनरेट करता है, उन्हें एक चयनित फ़ोल्डर में डालता है।

यदि HCL फ़ाइल में `data_flow_diagram` या `data_flow_diagram_v2` ब्लॉक के साथ `threatmodel` ब्लॉक शामिल नहीं है, तो कुछ भी आउटपुट नहीं होता है।

कमांड स्वयं डैशबोर्ड कमांड के समान है।```bash
$ threatcl dfd -overwrite -outdir testout examples/*
Successfully created 'testout/tm2-modellymodel.png'

यदि आपके threatmodel में diagram_link शामिल नहीं है, लेकिन इसमें data_flow_diagram शामिल है, तो threatcl dashboard चलाने पर यह भी प्रस्तुत होगा।

Mermaid

spec के अनुसार, एक threatmodel में मुक्त-रूप mermaid ब्लॉक भी शामिल हो सकते हैं। data_flow_diagram_v2 के विपरीत (जिसे threatcl आपके लिए प्रस्तुत करता है), एक mermaid ब्लॉक कच्चे mermaid स्रोत को शब्दशः एम्बेड करता है - mermaid आरेख प्रकार (अनुक्रम, अवस्था, प्रवाह चार्ट, आदि) का अनुमान सामग्री की पहली पंक्ति से लगाता है।

threatcl mermaid कमांड उस कच्चे स्रोत को निकालता है ताकि इसे अन्य रेंडरिंग टूल्स में पाइप किया जा सके। यह स्वयं छवियाँ प्रस्तुत नहीं करता है।

डिफ़ॉल्ट रूप से स्रोत STDOUT पर मुद्रित होता है:```bash $ threatcl mermaid examples/tm2.hcl sequenceDiagram User->>App: credentials App->>Auth: verify Auth-->>App: token

यह एक renderer जैसे [mermaid-cli](https://github.com/mermaid-js/mermaid-cli) में pipe करना आसान बनाता है:```bash
$ threatcl mermaid model.hcl | mmdc -o diagram.svg -i -

यदि कई mermaid ब्लॉक हैं, तो -index=n के साथ एक का चयन करें, या -outdir के साथ उन सभी को एक निर्देशिका में लिखें (प्रति ब्लॉक एक .mmd फ़ाइल)। आप -out के साथ एकल ब्लॉक को फ़ाइल में भी लिख सकते हैं।```bash $ threatcl mermaid -outdir testout model.hcl Successfully created 'testout/model-mymodelloginsequence.mmd'

## Terraform

`threatcl terraform` कमांड `terraform show -json` [docs here](https://www.terraform.io/docs/cli/commands/show.html) आउटपुट से डेटा संसाधनों को निकालने में सक्षम है, योजना फ़ाइलों या सक्रिय स्थिति फ़ाइलों से, और इन्हें `threatcl` फ़ाइलों में शामिल करने के लिए मसौदा `information_asset` ब्लॉक में बदल देता है।

यदि आप मौजूदा स्थिति वाले फ़ोल्डर में हैं, तो आप निम्न को निष्पादित कर सकते हैं:```bash
terraform show -json | threatcl terraform -stdin

यह इस प्रकार का आउटपुट देगा:```bash information_asset "aws_rds_cluster default" { description = "cluster_identifier: aurora-cluster-demo, database_name: mydb" information_classification = "" source = "terraform state" } information_asset "aws_s3_bucket example" { description = "bucket: terraform-20211107232017071500000001" information_classification = "" source = "terraform state" }

आप Terraform के साथ अभी तक लागू नहीं किए गए प्लान फ़ाइल से समान आउटपुट को चलाकर भी देख सकते हैं:```bash
terraform show -json <plan-file> | threatcl terraform -stdin

यदि आप किसी मौजूदा threatcl थ्रेट मॉडल फ़ाइल ("threatmodel.hcl") को अपडेट करना चाहते हैं, तो आप इसके साथ कर सकते हैं:```bash terraform show -json | threatcl terraform -stdin -add-to-existing=threatmodel.hcl > new-threatmodel.hcl

`-add-to-existing` फ़्लैग के साथ, आप `-tm-name=<string>` भी निर्दिष्ट कर सकते हैं यदि आपको स्रोत फ़ाइल से किसी विशेष threat model को निर्दिष्ट करने की आवश्यकता है, यदि कई हों। और आप `-default-classification=Confidential` फ़्लैग के साथ एक डिफ़ॉल्ट वर्गीकरण भी लागू कर सकते हैं।

ये कमांड इनपुट के रूप में एक फ़ाइल भी ले सकते हैं, ऐसी स्थिति में, `-stdin` फ़्लैग को छोड़ दें।

`threatcl` जिन terraform संसाधनों के बारे में जानता है, वे [pkg/terraform/terraform.go](https://github.com/threatcl/threatcl/blob/HEAD/pkg/terraform/terraform.go) में हार्ड कोडित हैं। यदि आप चाहते हैं कि `threatcl terraform` कमांड उन `information_asset` संसाधनों को आउटपुट करे जो वहाँ नहीं हैं, तो आप `-tf-collection=<json file>` फ़्लैग के माध्यम से इस json का अपना संस्करण प्रदान कर सकते हैं।

श्रेणियाँ