microsoft / threat-modeling-templates Goto Github PK
View Code? Open in Web Editor NEWMicrosoft Threat Modeling Template files
License: MIT License
Microsoft Threat Modeling Template files
License: MIT License
Do you have an ETA for when the missing Azure resources will be added to the Azure template? For example, we'd like to see the API Management, AD B2C, Function Apps and Azure Firewall as well as other resources added. Thanks.
I am getting "Unable to convert Threat Model" error when trying to load MedicalDeviceTemplate message with the following detail, when I try to open the template:
"Version of Selected Template is not newer or Template ID does not match with current threat model".
Any ideas how to resolve? I have the Azure template loaded.
Presently in the default template (default.tb7) the "contains cookies" attribute is yes by default. All other attributes default to a neutral / negative value.
There are important files that Microsoft projects should all have that are not present in this repository. A pull request has been opened to add the missing file(s). When the pr is merged this issue will be closed automatically.
Microsoft teams can learn more about this effort and share feedback within the open source guidance available internally.
One of my colleagues has noted a few spelling errors in the default template, most notably
Brower Plug-in Object (BHO)
(should be)
Browser Plug-in Object (BHO)
and
Represents the point where an application calls into an unmanged runtime library such as the CRT.
(should be)
Represents the point where an application calls into an unmanaged runtime library such as the CRT.
Why HTTP and HTTPS stencils are not available in Azure Cloud Services.tb7 ?
Hello,
Is there any potential for Microsoft Threat Modeling Tool to be directly integrated with Visio online? Would be great to have a threat model be auto-created when doing online collaboration when architecture diagrams are being drafted (similar to IriusRisk). Thoughts? Probably not the right place for this, but I wanted to ask to see if the right Microsoft contacts would have some insight.
Hi there,
What would be the easiest way to merge stencils? I have noticed that a lot of useful SDL ones are in the default stencil but not in the Azure one, for example, HTTPS traffic which is very common on threat models.
It would be nice to possibly get the option or at least an stencil pack that has both of best worlds. I don't mind creating a new stencil with that, but first would like to know if there is any easier way to possibly merge them together and then edit so we can still use the same icons and what not.
Thank you,
-Marco
When downloading the tool from https://aka.ms/threatmodelingtool, it uses v1 template which is 3 years old template with missing latest Azure stencils and properties.
Hi,
It would be great to have IoT objects template.
I'm not experienced developer but I know I can define my own objects. Which guide I should go with ?
I 've received feedback from Microsoft that they do not support the "merge" function available in the tool. This was after I've noticed that when you try to merge all 3 templates provided, some errors occur. Would it be possible to assist in merging all 3 templates provided using XML editor and provide 1 combined template? The community will benefit from such template as choosing either of the templates leaves us with missing vital components from the other templates.
Unfortunately, I'm not that versed into XML, even more merging them.
Would really thank you if you can assist on this.
Please publish the template file schema.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.