OWASP Threat Dragon
Threat modeling tool: create diagrams, document threats (STRIDE, etc.), and optionally save models to GitHub, Bitbucket, or GitLab. OWASP Threat Dragon runs as a web app, no host ports; access via Caddy.
Standard isolation
What to know
- Access
- Caddy route available; choose an access policy
- Login
- Application login
- Shared services
- No shared resources
- Backups
- No persistent backup requirement recorded
- Resource size
- Small
- Lifecycle
- Stable
Ready for the technical setup?
The stack README documents configuration, storage, networking, deployment, verification, upgrades, and troubleshooting.
View technical setup