OWASP Threat Dragon is a threat-modeling tool for developers and defenders working on secure development. It creates diagrams and records threats associated with their elements, which can include processes, data stores, actors, data flows and trust boundaries. Supported threat categories include STRIDE, LINDDUN, CIA, CIA-DIE, DIE and PLOT4ai. A rule engine can suggest threats and mitigations, including suggestions informed by diagram-element properties. Threat Dragon is free and open source under Apache License 2.0. It can run as a containerized, self-hosted web app or as desktop software, with installers for Windows, macOS and Linux. The web app supports local file storage and configurable connections to services such as GitHub, Google Drive, Bitbucket and GitLab; the desktop app stores models locally. Analytics are disabled by default, require server configuration and, for Plausible, do not collect threat-model content or usernames. The project is maintained by volunteers and notes that immediate incident investigation or response may not always be possible.
Who it is for
Threat Dragon is intended for developers and defenders, including both experienced threat modelers and beginners. It suits teams that want to diagram threats using supported frameworks and can work with either a self-hosted web app or desktop software.
What is good
- Free and open source under Apache License 2.0.
- Available as desktop software or a self-hosted web app.
- Supports six listed threat categories.
- Rule engine can suggest threats and mitigations.
What to know first
- Immediate incident investigation or response is not always possible.
- Desktop models are stored locally.
Verdict
Threat Dragon offers diagramming, framework support and rule-based suggestions in desktop and self-hosted web versions. Its volunteer maintenance model means immediate incident response cannot always be expected.
OWASP Threat Dragon plans and pricing
All plansCompared on threat modeling software
- Free plan
- Yes
- Risk prioritization
- Yes
- Templates and frameworks
- Yes
- Modeling methods
- multiple
- Deployment
- self_hosted



