Scaling threat modeling?
More documentation won't help you.
More documentation leads to checkbox compliance, missed opportunities, and analysis paralysis.
Value:
-A culture of finding and fixing design issues over checkbox compliance
-People and collaboration over processes, methodologies, and tools
-A journey of understanding over a security or privacy snapshot
-Doing threat modeling over talking about it
-Continuous refinement over a single delivery

- Agile Threat Modeling Manifesto (1/4)

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile development processes. It is language, platform, and technology-agnostic.

So play OWASP Cornucopia!

The new Companion Edition v1.0 comes with 6 companion suits covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO).

see: https://dev.to/owasp/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-5984

(2/4)

A suit in the Companion deck may replace (or be used in addition to) existing suits.
For example, say you are building an LLM application and want to perform threat modeling and security requirement analysis specifically for LLM.

You would then use the OWASP Cornucopia Website Edition and the LLM companion suit as your elected OWASP Cornucopia focus area.

This, immediately available at copi.owasp.org

You can also download the design files from the latest release. https://github.com/OWASP/cornucopia/releases/tag/v3.0.0

Release Release v3.0.0 · OWASP/cornucopia

What's Changed feat: add companion edition suites to Copi by @Mysterio-17 in #2885 build(deps-dev): bump wrangler from 4.84.1 to 4.85.0 in /cornucopia.owasp.org by @dependabot[bot] in #2884 build(...

GitHub
Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web

Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with...

DEV Community