Course Overview

Threat modeling is a critical cybersecurity practice for identifying, assessing, and mitigating security risks before they become costly incidents. Modern tools and frameworks such as Threat Dragon, STRIDE, MITRE ATT&CK, PASTA, NIST CSF, and DREAD help security teams understand attack surfaces, prioritize risks, and design more resilient systems. This course begins with the modern threat landscape and compares major threat modeling frameworks before moving into lab setup, data flow diagrams, trust boundaries, asset classification, and DREAD-based risk assessment. It then covers cloud and supply chain attack surfaces, DevSecOps, CI/CD security, attack trees, CVSS, Kubernetes, serverless and microservices security, validation with CALDERA and Atomic Red Team, threat intelligence, governance, FAIR quantification, AI and LLM threats, Zero Trust, OT/ICS, and advanced APT and nation-state scenarios. By completing this course, you will be able to perform practical threat modeling, assess risks, validate defenses, communicate findings, and develop a structured cybersecurity roadmap.

What You Will Learn

  • Build complete Data Flow Diagrams (DFDs) with trust boundaries for real-world web, cloud, and microservices architectures using OWASP Threat Dragon and pytm
  • Apply the full STRIDE framework to identify Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege threats acro
  • Score and prioritise threats using DREAD and CVSS v3.1, build a risk register, and present a one-page executive risk dashboard to non-technical stakeholders
  • Translate cyber risk into dollar figures using the FAIR model — calculate Annualised Loss Expectancy (ALE) and justify security budgets with board-ready ROI ana
  • Threat model cloud-native architectures on AWS including IAM roles, S3, Lambda, and Kubernetes clusters — and validate findings with Prowler and ATT&CK Navigato
  • Integrate threat modeling into CI/CD pipelines using pytm and GitHub Actions so every code merge automatically checks for new unmitigated threats
  • every code merge automatically checks for new unmitigated threats Run live adversary simulations with MITRE CALDERA and Atomic Red Team to validate whether your threat model's mitigations actually hold up against real attack
  • Threat model AI and LLM systems using the OWASP LLM Top 10 — including prompt injection, training data poisoning, and insecure output handling in RAG pipelines
  • Generate Software Bills of Materials (SBOMs) with Syft, scan for CVEs with Grype, and automatically push findings into a GRC platform via API — eliminating manu
  • Map threat model outputs directly to ISO 27001, NIST CSF 2.0, SOC 2, HIPAA, PCI-DSS, and GDPR controls — using a single TM workflow as evidence across all frame

Program Curriculum

  • Introduction
  • Chapter 1 Quiz

  • Meet Your Instructor
  • Chapter 2 Quiz

  • Why CISOs Must Think Like Attackers in 2026
  • Chapter 3 Quiz

  • STRIDE, ATT&CK, PASTA, NIST CSF, ISO 27005, LINDDUN & TM Policy
  • Chapter 4 Quiz

  • Install Threat Dragon + Lab Environment Walkthrough
  • Chapter 5 Quiz

  • DFDs, Trust Boundaries, Asset Classification + Lab 4.6
  • Chapter 6 Quiz

  • Risk Heatmaps, DREAD + Lab 6.6 Risk Register
  • Chapter 7 Quiz

  • Cloud TM, Multi-cloud, Prowler Lab + AWS DFD Lab 7.3
  • Chapter 8 Quiz

  • SBOM, Vendor Risk, Lab 8.4 + Lab 8.6
  • Chapter 9 Quiz

  • pytm, CI/CD Gates, STRIDE Chaining, Attack Trees, CVSS, K8s, Serverless, Microservices
  • Chapter 10 Quiz

  • CALDERA, Atomic Red Team, ATT&CK Navigator, D3FEND, Threat Intel, Sector TMs
  • Chapter 11 Quiz

  • Board Communication, FAIR Quantification, Threat Hunting, GRC Automation
  • Chapter 12 Quiz

  • OWASP LLM Top 10, Zero Trust, OT/ICS, Quantum, Continuous TM, PASTA Walkthrough
  • Chapter 13 Quiz

  • Full PayFlow TM — DFD + STRIDE + Risk Register + Board Summary
  • Chapter 14 Quiz

  • RaaS Scenario, CI/CD Breach, Peer Review, Maturity Lab, Templates, APT29 Tabletop
  • Chapter 15 Quiz

  • Chapter 16: 90-Day CISO Roadmap
  • Key Takeaways, Resources, What's Next + Final Thank You
Load more modules

Instructor

Armaan Sidana

Armaan Sidana is a multifaceted individual with a passion for excellence across various domains. His expertise lies in the dynamic field of cybersecurity, where he holds notable certifications such as OSCP, CEH, CISA, and CSFPC. As a committed professional, He consistently seeks opportunities to contribute to the ever-evolving landscape of information security. Secured 100+ Companies with 1500+ Security Bugs. Mentored 25000+ students till now, being the guest lecturer at many educational institutions.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50