Stride Analysis Patterns

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

Instructions onlySecurity
AI-generated overview

Guides systematic STRIDE threat modeling to identify security threats in system designs.

What it does
This skill provides a structured approach to threat identification using the STRIDE methodology. It explains the six STRIDE categories, maps each to the security question it answers and the corresponding control family, and offers best-practice guidance for running threat modeling sessions. It also points to a reference file containing templates and worked examples.
When to use it
Use it when starting a threat modeling session, analyzing an existing system architecture, or reviewing security design decisions. It also fits security documentation, team training on threat identification, and compliance or audit preparation.
Requirements
No scripts or tools are required; it is instructions only. Reading the bundled reference file references/details.md is suggested for templates and worked examples.

STRIDE Analysis Patterns

Systematic threat identification using the STRIDE methodology.

When to Use This Skill

  • Starting new threat modeling sessions
  • Analyzing existing system architecture
  • Reviewing security design decisions
  • Creating threat documentation
  • Training teams on threat identification
  • Compliance and audit preparation

Core Concepts

1. STRIDE Categories

S - Spoofing       → Authentication threatsT - Tampering      → Integrity threatsR - Repudiation    → Non-repudiation threatsI - Information    → Confidentiality threats    DisclosureD - Denial of      → Availability threats    ServiceE - Elevation of   → Authorization threats    Privilege

2. Threat Analysis Matrix

CategoryQuestionControl Family
SpoofingCan attacker pretend to be someone else?Authentication
TamperingCan attacker modify data in transit/rest?Integrity
RepudiationCan attacker deny actions?Logging/Audit
Info DisclosureCan attacker access unauthorized data?Encryption
DoSCan attacker disrupt availability?Rate limiting
ElevationCan attacker gain higher privileges?Authorization

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Involve stakeholders - Security, dev, and ops perspectives
  • Be systematic - Cover all STRIDE categories
  • Prioritize realistically - Focus on high-impact threats
  • Update regularly - Threat models are living documents
  • Use visual aids - DFDs help communication

Don'ts

  • Don't skip categories - Each reveals different threats
  • Don't assume security - Question every component
  • Don't work in isolation - Collaborative modeling is better
  • Don't ignore low-probability - High-impact threats matter
  • Don't stop at identification - Follow through with mitigations

Source and attribution

Source:wshobson/agentsinplugins/security-scanning/skills/stride-analysis-patternsat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal