Threat Modeling for PentestersThreat Modeling for Pentesters room icon

Threat Modeling for Pentesters sits in the Pentesting Methodologies and Reporting module of the Jr Penetration Tester path. It teaches the thinking that happens before you ever run a scan: decompose the target, work out what can go wrong, and rank those threats so your ten days of testing hit the things the client actually cares about. The room leans on frameworks you may already know in pieces, and it ties into the Cyber Kill Chain room directly and the AI Threat Modelling room by theme.

This is a reading room with no attached VM. Eight content tasks cover four frameworks (STRIDE, DREAD, PASTA, MITRE ATT&CK), and a capstone in Task 8 walks you through a guided five-step exercise on a static site, ending in a flag. Every answer comes from the task text or the capstone, and the only real friction is the answer mask deciding exact wording.

Task 1: Introduction

Task 1 sets the scene: you are a pentester handed a Stratford Systems engagement, and a threat model is how you turn a 50-page scope into a prioritized test plan. No answer is needed here, so the single prompt is acknowledged with a click to complete it.

Task 2: Four Questions and Three Frameworks

The task introduces Adam Shostack’s four questions (what are we working on, what can go wrong, what are we going to do about it, did we do a good job) and the three frameworks that answer question two from different angles. The question asks which framework uses six threat categories including Spoofing and Tampering.

That is STRIDE, the Microsoft model whose six categories are Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Task 3: Assets, Data Flows, and Trust Boundaries

This task is the shared vocabulary all three frameworks depend on: assets, Data Flow Diagrams, and trust boundaries. In standard DFD notation each element has a shape, and the question asks which element a dashed line represents.

A dashed line is a Trust Boundary, the point where data crosses between zones of different trust and where vulnerabilities concentrate. The second question asks which element type represents application logic that transforms or acts on data, drawn as a circle.

That is a Process.

Task 4: STRIDE: Systematic Threat Identification

STRIDE maps each category to a violated security property. The first question asks which category directly violates integrity.

That is Tampering, the unauthorized modification of data in transit or at rest. The second question describes the StratPay Portal failing to log failed authentication attempts and asks which category that gap falls under.

That is Repudiation: without logs, an attacker who brute-forces a login cannot be reliably tied to the action. The third question asks which DFD element type the mapping table marks as susceptible to all six STRIDE categories.

That is a Process. Processes transform data and face the widest range of threats, which is why every process on a DFD earns full STRIDE treatment.

Task 5: Scoring Threats with DREAD

DREAD adds prioritization on top of STRIDE’s categories, scoring Damage, Reproducibility, Exploitability, Affected Users, and Discoverability. The first question asks what the “A” stands for.

That is Affected Users, the proportion of users or systems impacted by a successful exploit. The second question gives a Denial of Service scenario: anyone on the Internet can trigger it with no authentication, it crashes the whole payment portal, but there is no data loss and the system recovers automatically on restart. It asks which DREAD category scores lowest.

That is Damage. A temporary availability disruption with automatic recovery and no data loss scores low on Damage, even though Affected Users and Exploitability are high.

Task 6: PASTA: Risk-Centric Threat Modeling

PASTA (Process for Attack Simulation and Threat Analysis) runs seven stages from business objectives down to prioritized attack paths. The first question asks which stage provides the business-risk evidence to justify prioritizing the payment portal over an internal wiki.

That is Stage 7, Risk and Impact Analysis, which quantifies the business consequences of each validated attack path. The second question asks where you would incorporate a finding that financial-sector threat intelligence shows a 300% jump in API-targeted attacks.

That is Stage 4, Threat Analysis, the stage that gathers and analyzes threat intelligence specific to the client’s industry.

Task 7: MITRE ATT&CK for Threat Modeling

ATT&CK grounds the model in observed adversary behavior. The first question asks how many tactics are in the Enterprise matrix (v18).

The matrix lists 14 tactics, from Reconnaissance through Impact. The second question asks for the first tactic alphabetically that has no direct equivalent in the Cyber Kill Chain.

The room names five tactics the Kill Chain does not model: Privilege Escalation, Defense Evasion, Credential Access, Discovery, and Lateral Movement. Alphabetically the first is Credential Access. These five describe what happens inside a network after initial access, which is where pentesters spend most of an engagement.

  # Kill Chain phase            -> ATT&CK tactics
  # Reconnaissance              -> Reconnaissance
  # Weaponization               -> Resource Development
  # Delivery                    -> Initial Access
  # Exploitation                -> Execution
  # Installation                -> Persistence
  # Command and Control         -> Command and Control
  # Actions on Objectives       -> Collection, Exfiltration, Impact
  # no Kill Chain equivalent    -> Privilege Escalation, Defense Evasion,
  #                                Credential Access, Discovery, Lateral Movement

Task 8: Putting It All Together, and the Flag

This is the capstone. A static site, the Stratford Engagement Console, walks through five steps that apply every framework to one financial-services target with a payment portal, an internal API gateway, a SQL Server cluster, an Active Directory domain, an admin dashboard, and an employee directory.

The engagement briefing frames the CISO’s actual fear: a phished employee credential reaching the payment database. That one sentence drives the whole model.

Stratford Systems DFD with five trust boundaries

Step 1 is the expanded DFD. You click each of the five trust boundaries to inspect the data flows crossing it. TB5, the boundary between the VPN tunnel and the internal network, is the load-bearing one: if the VPN drops authenticated users onto a flat internal network, the attacker’s path from stolen credentials to the database is one hop, not five.

Inspecting trust boundary TB5 between the VPN tunnel and internal network

Step 2 applies STRIDE to four components, Step 3 scores four threats with DREAD, Step 4 fills in the missing ATT&CK tactics on a five-step attack chain, and Step 5 ranks four test objectives. The three Task 8 questions ask you to recall specific answers from those steps.

The first asks which of two threats scored higher in the DREAD exercise: the phished VPN credentials or the SQL injection in the transaction search. Direct database access to all customer payment records outscores network access that still needs more steps, so the answer is SQL injection.

The second asks which ATT&CK tactic you assigned to the step where the attacker uses stolen VPN credentials (T1133, External Remote Services) to enter the network. Entering from outside with legitimate credentials is Initial Access, not Lateral Movement.

Completing all five steps reveals the flag.

  # flag awarded after finishing the Stratford capstone
What flag did you get after going through all the steps?
THM{Thr347-Modeling}

The flag is THM{Thr347-Modeling}.

Task 9: Conclusion

The closing task restates the point: no single framework covers everything, and a threat model is a living document that evolves before, during, and after the engagement. The next room in the module is Planning and Scoping, where the threat model feeds the scope document and Rules of Engagement. No answer is needed, so the task is marked complete.

Takeaways

Two things worth carrying out of this room:

  • The frameworks stack, they do not compete. STRIDE tells you what can go wrong, DREAD ranks it, PASTA adds business context, and ATT&CK grounds it in real adversary behavior. Use STRIDE inside PASTA’s Stage 4, then let the later PASTA stages chain and prioritize. A pentest plan built this way tests the client’s actual risk, not whatever you happened to scan first.
  • Trust boundaries are your initial target list. Every data flow crossing a boundary is a place where a security control must exist and where you should test whether it actually works. On the Stratford DFD, the VPN-to-internal boundary was the whole engagement in one line: if it is flat, phished credentials reach the payment database in a single hop.

Room solved 100%: 9 tasks, 13 answers.