Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
pytm — Un framework Pythonic per la modellazione delle minacce | Kitploit
Strumenti/GitHubGitHub/izar/pytm
Analisi delle VulnerabilitàDevSecOpsThreat IntelligenceApprendimento e Formazione
GitHubizar/pytm

pytm

Un framework Pythonic per la modellazione delle minacce

Vedi Repository
2216 giorni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

build+test OpenSSF Best Practices

pytm: Un framework Pythonic per la modellazione delle minacce

logo pytm

Introduzione

La modellazione delle minacce tradizionale arriva troppo spesso in ritardo, o a volte non arriva affatto. Inoltre, creare manualmente flussi di dati e report può richiedere molto tempo. L'obiettivo di pytm è spostare la modellazione delle minacce a sinistra, rendendola più automatizzata e incentrata sullo sviluppatore.

Caratteristiche

Basandosi sul tuo input e sulla definizione del progetto architetturale, pytm può generare automaticamente i seguenti elementi:

  • Diagramma del flusso di dati (DFD)
  • Diagramma di sequenza
  • Minacce rilevanti per il tuo sistema

Requisiti

  • Linux/MacOS
  • Python 3.11+
  • Pacchetto Graphviz
  • Java (OpenJDK 10 o 11)
  • plantuml.jar

Per Iniziare

tm.py è un modello di esempio. Puoi eseguirlo per generare il report e i file immagine del diagramma a cui fa riferimento:``` mkdir -p tm ./tm.py --report docs/basic_template.md | pandoc -f markdown -t html > tm/report.html ./tm.py --dfd | dot -Tpng -o tm/dfd.png ./tm.py --seq | java -Djava.awt.headless=true -jar $PLANTUML_PATH -tpng -pipe > tm/seq.png

root@kitploit:~
C'è anche un esempio di `Makefile` che racchiude tutto questo in target che possono essere facilmente condivisi per più modelli. Se hai [GNU make](https://www.gnu.org/software/make/) installato (disponibile per impostazione predefinita sulle distribuzioni Linux ma non su OSX), esegui semplicemente:```
make MODEL=the_name_of_your_model_minus_.py

Dovresti avere plantuml.jar nella stessa directory del tuo modello, oppure impostare PLANTUML_PATH.

Per evitare di installare tutte le dipendenze, come pandoc o Java, lo script può essere eseguito all'interno di un container:```

do this only once

export USE_DOCKER=true make image

call this after every change in your model

make

root@kitploit:~
### Getting Started - Devbox Variant

Per semplificare l'utilizzo di `pytm`, le dipendenze dell'host possono essere completamente isolate utilizzando [`Devbox`](https://github.com/jetify-com/devbox). Questa è solitamente un'alternativa a minor carico di lavoro e più comoda rispetto all'approccio del contenitore OCI.

- Installa Devbox su Linux/MacOS: `curl -fsSL https://get.jetify.com/devbox | bash`
- Installa Devbox su [Windows/WSL](https://www.jetify.com/docs/devbox/installing-devbox/index#installing-wsl2)
- Aggiorna all'ultima versione di devbox: `devbox version update`
- Imposta il tuo token di accesso GitHub nel file `~/.config/nix/nix.conf`: `access-tokens = github.com=YOUR_TOKEN_HERE`
- Crea un nuovo ambiente shell isolato che include tutti gli strumenti e i pacchetti specificati nel file `devbox.json` del progetto: `devbox shell`
- Mostra il percorso completo dell'eseguibile Python che verrà utilizzato quando digiti semplicemente `python` nel terminale usando il comando which python. L'output dovrebbe essere il seguente percorso:  `.devbox/nix/profile/default/bin/python`
- Testa eseguendo il seguente comando, che dovrebbe generare un DFD come file PNG chiamato `sample.png`:  `./tm.py --dfd | dot -Tpng -o sample.png`
- Esci dall'ambiente shell Devbox: `exit`

## Usage

Tutti gli argomenti disponibili:```text
usage: tm.py [-h] [--debug] [--dfd] [--report REPORT]
             [--exclude EXCLUDE] [--seq] [--list] [--describe DESCRIBE]
             [--list-elements] [--json JSON] [--levels LEVELS [LEVELS ...]]
             [--stale_days STALE_DAYS]

optional arguments:
  -h, --help            show this help message and exit
  --debug               print debug messages
  --dfd                 output DFD
  --report REPORT       output report using the named template file (sample
                        template file is under docs/template.md)
  --exclude EXCLUDE     specify threat IDs to be ignored
  --seq                 output sequential diagram
  --list                list all available threats
  --colormap            color the risk in the diagram
  --describe DESCRIBE   describe the properties available for a given element
  --list-elements       list all elements which can be part of a threat model
  --json JSON           output a JSON file
  --levels LEVELS [LEVELS ...]
                        Select levels to be drawn in the threat model (int
                        separated by comma).
  --stale_days STALE_DAYS
                        checks if the delta between the TM script and the code
                        described by it is bigger than the specified value in
                        days

L'argomento stale_days tenta di determinare quanto distanti in giorni siano lo script del modello (che stai scrivendo) dal codice che implementa il sistema modellizzato. Idealmente, dovrebbero essere abbastanza vicini nella maggior parte dei casi di un sistema attivamente sviluppato. Puoi eseguirlo periodicamente per misurare il polso del tuo progetto e la 'freschezza' del tuo modello di minaccia.

Gli elementi attualmente disponibili sono: TM, Element, Server, ExternalEntity, Datastore, Actor, Process, SetOfProcesses, Dataflow, Boundary, Lambda, LLM e Agent.

Le proprietà disponibili di un elemento possono essere elencate utilizzando --describe seguito dal nome di un elemento:```text

(pytm) ➜ pytm git:(master) ✗ ./tm.py --describe Element Element class attributes: OS definesConnectionTimeout default: False description handlesResources default: False implementsAuthenticationScheme default: False implementsNonce default: False inBoundary inScope Is the element in scope of the threat model, default: True isAdmin default: False isHardened default: False name required onAWS default: False

root@kitploit:~
L'argomento *colormap*, usato insieme a *dfd*, produce un DFD codificato a colori in cui gli elementi sono dipinti in rosso, giallo o verde a seconda del loro livello di rischio (come identificato dall'esecuzione delle regole).

## Utilizzo - Variante Devbox

- `devbox shell`
- `pytm` utilizzo come di consueto
- `exit`

## Creazione di un Modello di Minaccia

Quello che segue è un esempio di file `tm.py` che descrive una semplice applicazione in cui un Utente accede all'applicazione e pubblica commenti sull'app. Il server dell'applicazione memorizza tali commenti nel database. C'è una AWS Lambda che pulisce periodicamente il Database.```python

#!/usr/bin/env python3

from pytm import TM, Server, Datastore, Dataflow, Boundary, Actor, Lambda, LLM, Data, Classification

tm = TM("my test tm")
tm.description = "another test tm"
tm.isOrdered = True

User_Web = Boundary("User/Web")
Web_DB = Boundary("Web/DB")

user = Actor("User")
user.inBoundary = User_Web

web = Server("Web Server")
web.OS = "CloudOS"
web.isHardened = True
web.sourceCode = "server/web.cc"

db = Datastore("SQL Database (*)")
db.OS = "CentOS"
db.isHardened = False
db.inBoundary = Web_DB
db.isSql = True
db.inScope = False
db.sourceCode = "model/schema.sql"

comments = Data(
    name="Comments", 
    description="Comments in HTML or Markdown",  
    classification=Classification.PUBLIC,  
    isPII=False,
    isCredentials=False,  
    # credentialsLife=Lifetime.LONG,  
    isStored=True, 
    isSourceEncryptedAtRest=False, 
    isDestEncryptedAtRest=True 
)

results = Data(
    name="results", 
    description="Results of insert op",  
    classification=Classification.SENSITIVE,  
    isPII=False, 
    isCredentials=False,  
    # credentialsLife=Lifetime.LONG,  
    isStored=True, 
    isSourceEncryptedAtRest=False, 
    isDestEncryptedAtRest=True 
)

my_lambda = Lambda("cleanDBevery6hours")
my_lambda.hasAccessControl = True
my_lambda.inBoundary = Web_DB

llm_api = LLM("AI Writing Assistant")
llm_api.isThirdParty = True
llm_api.processesPersonalData = True
llm_api.hasContentFiltering = False
llm_api.hasSystemPrompt = True
llm_api.processesUntrustedInput = True

my_lambda_to_db = Dataflow(my_lambda, db, "(λ)Periodically cleans DB")
my_lambda_to_db.protocol = "SQL"
my_lambda_to_db.dstPort = 3306

user_to_web = Dataflow(user, web, "User enters comments (*)")
user_to_web.protocol = "HTTP"
user_to_web.dstPort = 80
user_to_web.data = comments

web_to_user = Dataflow(web, user, "Comments saved (*)")
web_to_user.protocol = "HTTP"

web_to_db = Dataflow(web, db, "Insert query with comments")
web_to_db.protocol = "MySQL"
web_to_db.dstPort = 3306

db_to_web = Dataflow(db, web, "Comments contents")
db_to_web.protocol = "MySQL"
db_to_web.data = results

web_to_llm = Dataflow(web, llm_api, "Chat completion request")
web_to_llm.protocol = "HTTPS"
web_to_llm.dstPort = 443

tm.process()

Hai anche la possibilità di utilizzare pytmGPT per creare i tuoi modelli partendo da testo!

Generazione di Diagrammi

I diagrammi vengono generati come Dot e PlantUML.

Quando l'argomento --dfd viene passato al file tm.py sopra menzionato, genera l'output su stdout, che viene inviato a dot di Graphviz per generare il Data Flow Diagram:```bash

tm.py --dfd | dot -Tpng -o sample.png

root@kitploit:~
Genera questo diagramma:

dfd.png

Aggiungere gli attributi ".levels = [1,2]" a un elemento farà sì che esso (e i suoi Dataflow associati se entrambe le estremità del flusso si trovano nello stesso livello DFD) venga visualizzato (o meno) a seconda dell'argomento del comando "--levels 1 2".

Il seguente comando genera un diagramma di sequenza.```bash

tm.py --seq | java -Djava.awt.headless=true -jar plantuml.jar -tpng -pipe > seq.png

Genera questo diagramma:

seq.png

Creazione di un Report

I diagrammi e i risultati possono essere inclusi nel template per creare un report finale:```bash

tm.py --report docs/basic_template.md | pandoc -f markdown -t html > report.html

root@kitploit:~
Il formato di template utilizzato nel modello di report è molto semplice:```text

# Threat Model Sample
***

## System Description

{tm.description}

## Dataflow Diagram

![Level 0 DFD](https://raw.githubusercontent.com/izar/pytm/HEAD/dfd.png)

## Dataflows

Name|From|To |Data|Protocol|Port
----|----|---|----|--------|----
{dataflows:repeat:{{item.name}}|{{item.source.name}}|{{item.sink.name}}|{{item.data}}|{{item.protocol}}|{{item.dstPort}}
}

## Findings

{findings:repeat:* {{item.description}} on element "{{item.target}}"
}

Per raggruppare i risultati per elementi, utilizza un ciclo avanzato e annidato:```text

Findings

{elements🔁{{item.findings:if:

{{item.name}}

{{item.findings🔁 Threat: {{{{item.id}}}} - {{{{item.description}}}}

Severity: {{{{item.severity}}}}

Mitigations: {{{{item.mitigations}}}}

References: {{{{item.references}}}}

}}}}}

root@kitploit:~
Tutti gli elementi all'interno di un ciclo devono essere escaped, raddoppiando le parentesi graffe, quindi `{item.name}` diventa `{{item.name}}`.
L'esempio sopra utilizza due cicli annidati, quindi gli elementi nel ciclo interno devono essere escaped due volte, ecco perché usano quattro parentesi graffe.

### Override

È possibile sovrascrivere gli attributi dei findings (minacce che corrispondono agli asset e/o ai dataflow del modello), ad esempio per impostare un punteggio CVSS personalizzato e/o un testo di risposta:```python
user_to_web = Dataflow(user, web, "User enters comments (*)", protocol="HTTP", dstPort="80")
user_to_web.overrides = [
    Finding(
        # Overflow Buffers
        threat_id="INP02",
        cvss="9.3",
        response="""**To Mitigate**: run a memory sanitizer to validate the binary""",
        severity="Very High",
    )
]

Se stai aggiungendo un Finding, assicurati di aggiungere una gravità: "Molto Alta", "Alta", "Media", "Bassa", "Molto Bassa".

Database delle minacce

Per il professionista della sicurezza, puoi fornire il tuo file di minacce impostando TM.threatsFile. Dovrebbe contenere voci come:```json { "SID":"INP01", "target": ["Lambda","Process"], "description": "Buffer Overflow via Environment Variables", "details": "This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.", "Likelihood Of Attack": "High", "severity": "High", "condition": "target.usesEnvironmentVariables is True and target.controls.sanitizesInput is False and target.controls.checksInputBounds is False", "prerequisites": "The application uses environment variables.An environment variable exposed to the user is vulnerable to a buffer overflow.The vulnerable environment variable uses untrusted data.Tainted data used in the environment variables is not properly validated. For instance boundary checking is not done before copying the input data to a buffer.", "mitigations": "Do not expose environment variable to the user.Do not use untrusted data in your environment variables. Use a language or compiler that performs automatic bounds checking. There are tools such as Sharefuzz [R.10.3] which is an environment variable fuzzer for Unix that support loading a shared library. You can use Sharefuzz to determine if you are exposing an environment variable vulnerable to buffer overflow.", "example": "Attack Example: Buffer Overflow in $HOME A buffer overflow in sccw allows local users to gain root access via the $HOME environmental variable. Attack Example: Buffer Overflow in TERM A buffer overflow in the rlogin program involves its consumption of the TERM environmental variable.", "references": "https://capec.mitre.org/data/definitions/10.html, CVE-1999-0906, CVE-1999-0046, http://cwe.mitre.org/data/definitions/120.html, http://cwe.mitre.org/data/definitions/119.html, http://cwe.mitre.org/data/definitions/680.html" }

root@kitploit:~
Il campo `target` elenca le classi di elementi del modello da confrontare con questa minaccia. Possono essere asset, come: Actor, Datastore, Server, Process, SetOfProcesses, ExternalEntity, Lambda, LLM, Agent o Element, che è la classe base e corrisponde a qualsiasi. Può anche essere un Dataflow che collega due asset.

Tutti gli altri campi (tranne `condition`) sono disponibili per la visualizzazione e possono essere utilizzati nel template per elencare i risultati nel [report](#report) finale.

> **ATTENZIONE**
>
> Il file `threats.json` contiene stringhe che vengono eseguite tramite `eval()`. Assicurati che il file abbia i permessi corretti o rischi che un attaccante modifichi le stringhe e ti costringa a eseguire codice per suo conto.

La logica risiede nella `condition`, dove i membri di `target` possono essere valutati logicamente. Restituire true significa che la regola genera un risultato, altrimenti non è un risultato. La condizione può confrontare attributi di `target` e/o attributi di controllo di 'target.control' e anche chiamare uno dei seguenti metodi:

* `target.oneOf(class, ...)` dove `class` è uno o più: Actor, Datastore, Server, Process, SetOfProcesses, ExternalEntity, Lambda, LLM, Agent o Dataflow,
* `target.crosses(Boundary)`,
* `target.enters(Boundary)`,
* `target.exits(Boundary)`,
* `target.inside(Boundary)`.

Se `target` è un Dataflow, ricorda che puoi accedere a `target.source` e/o `target.sink` insieme ad altri attributi.

Le condizioni sugli asset possono analizzare tutti i Dataflow in entrata e in uscita ispezionando gli attributi `target.input` e `target.output`. Ad esempio, per abbinare una minaccia solo ai server con traffico in entrata, usa `any(target.inputs)`. Un esempio più avanzato, per abbinare elementi che si collegano a datastore SQL, sarebbe `any(f.sink.oneOf(Datastore) and f.sink.isSQL for f in target.outputs)`.

## Importazione da JSON

Con un po' di codice Python è possibile importare un modello di minaccia da JSON (nota il formato speciale nell'esempio presente in `tests/input.json`). Il seguente esempio importa l'esempio `input.json` presente nei test. Salva il seguente codice come `tm2.py`.```python

#!/usr/bin/env python3
# Example tm2.py contents
# Run: python tm2.py --dfd | dot -Tpng -o sample_json.png

from pytm import (
    TM,
    Actor,
    Boundary,
    Classification,
    Data,
    Dataflow,
    Datastore,
    Lambda,
    Server,
    DatastoreType,
    Assumption,
    load,
)

json_file_string = './tests/input.json'
with open(json_file_string) as input_json:
    TM.reset()
    tm = load(input_json)
    tm.process()

Possiamo chiamare tm2.py allo stesso modo di prima, qui con --dfd e poi reindirizzare l'output a Graphviz (dot):```bash

python tm2.py --dfd | dot -Tpng -o sample_json.png

root@kitploit:~
## Creazione di slide!

Una volta che un modello di minaccia è completato e pronto, arriva la temuta fase della presentazione - e ora pytm può aiutarti anche in questo, con un template che esprime il tuo modello di minaccia in slide, sfruttando la potenza di (RevealMD)[https://github.com/webpro/reveal-md]! Basta usare il template docs/revealjs.md e otterrai delle belle slide, completamente configurabili, che puoi presentare e condividere dal tuo browser.



https://github.com/izar/pytm/assets/368769/30218241-c7cc-4085-91e9-bbec2843f838



## Minacce attualmente supportate```text
INP01 - Buffer Overflow via Environment Variables
INP02 - Overflow Buffers
INP03 - Server Side Include (SSI) Injection
CR01 - Session Sidejacking
INP04 - HTTP Request Splitting
CR02 - Cross Site Tracing
INP05 - Command Line Execution through SQL Injection
INP06 - SQL Injection through SOAP Parameter Tampering
SC01 - JSON Hijacking (aka JavaScript Hijacking)
LB01 - API Manipulation
AA01 - Authentication Abuse/ByPass
DS01 - Excavation
DE01 - Interception
DE02 - Double Encoding
API01 - Exploit Test APIs
AC01 - Privilege Abuse
INP07 - Buffer Manipulation
AC02 - Shared Data Manipulation
DO01 - Flooding
HA01 - Path Traversal
AC03 - Subverting Environment Variable Values
DO02 - Excessive Allocation
DS02 - Try All Common Switches
INP08 - Format String Injection
INP09 - LDAP Injection
INP10 - Parameter Injection
INP11 - Relative Path Traversal
INP12 - Client-side Injection-induced Buffer Overflow
AC04 - XML Schema Poisoning
DO03 - XML Ping of the Death
AC05 - Content Spoofing
INP13 - Command Delimiters
INP14 - Input Data Manipulation
DE03 - Sniffing Attacks
CR03 - Dictionary-based Password Attack
API02 - Exploit Script-Based APIs
HA02 - White Box Reverse Engineering
DS03 - Footprinting
AC06 - Using Malicious Files
HA03 - Web Application Fingerprinting
SC02 - XSS Targeting Non-Script Elements
AC07 - Exploiting Incorrectly Configured Access Control Security Levels
INP15 - IMAP/SMTP Command Injection
HA04 - Reverse Engineering
SC03 - Embedding Scripts within Scripts
INP16 - PHP Remote File Inclusion
AA02 - Principal Spoof
CR04 - Session Credential Falsification through Forging
DO04 - XML Entity Expansion
DS04 - XSS Targeting Error Pages
SC04 - XSS Using Alternate Syntax
CR05 - Encryption Brute Forcing
AC08 - Manipulate Registry Information
DS05 - Lifting Sensitive Data Embedded in Cache
SC05 - Removing Important Client Functionality
INP17 - XSS Using MIME Type Mismatch
AA03 - Exploitation of Trusted Credentials
AC09 - Functionality Misuse
INP18 - Fuzzing and observing application log data/errors for application mapping
CR06 - Communication Channel Manipulation
AC10 - Exploiting Incorrectly Configured SSL
CR07 - XML Routing Detour Attacks
AA04 - Exploiting Trust in Client
CR08 - Client-Server Protocol Manipulation
INP19 - XML External Entities Blowup
INP20 - iFrame Overlay
AC11 - Session Credential Falsification through Manipulation
INP21 - DTD Injection
INP22 - XML Attribute Blowup
INP23 - File Content Injection
DO05 - XML Nested Payloads
AC12 - Privilege Escalation
AC13 - Hijacking a privileged process
AC14 - Catching exception throw/signal from privileged block
INP24 - Filter Failure through Buffer Overflow
INP25 - Resource Injection
INP26 - Code Injection
INP27 - XSS Targeting HTML Attributes
INP28 - XSS Targeting URI Placeholders
INP29 - XSS Using Doubled Characters
INP30 - XSS Using Invalid Characters
INP31 - Command Injection
INP32 - XML Injection
INP33 - Remote Code Inclusion
INP34 - SOAP Array Overflow
INP35 - Leverage Alternate Encoding
DE04 - Audit Log Manipulation
AC15 - Schema Poisoning
INP36 - HTTP Response Smuggling
INP37 - HTTP Request Smuggling
INP38 - DOM-Based XSS
AC16 - Session Credential Falsification through Prediction
INP39 - Reflected XSS
INP40 - Stored XSS
AC17 - Session Hijacking - ServerSide
AC18 - Session Hijacking - ClientSide
INP41 - Argument Injection
AC19 - Reusing Session IDs (aka Session Replay) - ServerSide
AC20 - Reusing Session IDs (aka Session Replay) - ClientSide
AC21 - Cross Site Request Forgery
DS06 - Data Leak
DR01 - Unprotected Sensitive Data
AC22 - Credentials Aging (deprecated)
AC23 - Credentials Disclosure
AC24 - Use of hardcoded credentials
LLM01 - Direct Prompt Injection
LLM02 - Indirect Prompt Injection via Retrieved Content
LLM03 - Sensitive Data Leakage to Third-Party Provider
LLM04 - Training Data Poisoning
LLM05 - Excessive Agency via Unauthorized Tool Use
LLM06 - Arbitrary Code Execution via LLM Agent
LLM07 - Jailbreaking and Safety Bypass
LLM08 - Sensitive Information Disclosure Through Output
LLM09 - Untrusted Tool Launch Configuration


Scarica lo strumento