OWASP / OWASP/pytm

Applying custom threats only to specific elements.

Open
#262 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.2k
Forks
229
PR merge metrics
No merged PRs in 30d

Description

Thanks guys for your comments, I'll see what I can share in terms of threat library with putting my org at risk.

Usually I run into another problem also, when I add my custom threats I would like to apply those threats to specific assets in my threat model but I'd have to pick (asset, dataflow etc.) as target element. Any ideas to do this easier way?

Originally posted by @harsh02 in #261

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points. Start by reviewing how custom threats are defined and how asset and dataflow targets are currently selected. Define the desired way to target specific model elements, then confirm the behavior with maintainers before implementing tests or documentation.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.