New: the first SBOM scanner for machines.Take a look
Designer

Threat modeling has never been this simple.

Upload product data, the AI creates the architecture model. Identify threats with STRIDE and MITRE ATT&CK, assess risks, assign mitigations.

PROFINET IOCP 1543-1 Ethernet1 property · 6 attributesSCALANCE XC2081 property · 6 attributesPROFINET RTSIMATIC S7-1500 CPU2 Eigenschaften · 6 AttributeET 200SP Station #11 property · 6 attributesZebra ZM400 Printer1 property · 6 attributes

Visual Architecture Modeling

Visually model your product architecture with components, interfaces and data flows, directly in the browser.

Attributes

Which threats are relevant for this component?

SSpoofingViolated: Authentication
TTamperingViolated: Integrity
RRepudiationViolated: Non-Repudiation

STRIDE Analysis

Systematic threat analysis with the proven STRIDE framework. Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.

Listed 1Edit properties
Control Server

Component type

ProcessData StoreExternal Entity

MITRE ATT&CK for ICS & EMB3D

Link threats to real attack techniques from MITRE ATT&CK for ICS and the EMB3D model for embedded systems.

NANation-State ActorExternal attacker

A nation-state actor conducting targeted cyber espionage.

Attacker Modeling (ISO 18045)

Define attacker profiles according to ISO 18045: expertise, resources, motivation. Understand who you need to protect against.

An attacker triggers functions on the pressure regulator via an interface.

LikelihoodLow
ImpactHigh
Risk levelMedium

Automatic Risk Assessment

Risks are automatically calculated from threat, attacker profile and damage scenario. No more manual scoring.

Risk treatment1/4 Measures
ReduceAcceptShareAvoid
Authorization EnforcementApplied

MITRE ATT&CK for ICS · M0800

MITRE Mitigations & Treatment

Assign concrete countermeasures from the MITRE catalog to each threat. Traceable, standardized, audit-ready.

How it works

Three steps to your threat model.

01

Upload your documents

A PDF, a draw.io, a Word file. The AI builds a first architecture picture from it, with components and data flows.

02

Find the threats

STRIDE and MITRE ATT&CK for ICS work through what can go wrong, step by step. The AI suggests fitting scenarios.

03

Rate risks and handle them

How strong is the attacker, how big is the damage? Designer works out the risk and you assign measures. Current vulnerabilities feed straight in.

supported by Observer

The difference

Write for three weeks.
Or upload one document.

By hand3 weeks

Someone sits down and writes 40 pages of Word. No link to real attacks, no link to current vulnerabilities. By the next audit it is out of date again.

With Designer2 hours

Upload the specification, the AI builds the architecture picture. You improve it instead of starting from zero. When something changes you version it instead of rewriting it.

Cyber Resilience Act

December 11, 2027.

From then on, product security is a legal obligation. No evidence, no CE marking.

486
Days
:
11
Hrs
:
19
Min
:
36
Sec

Threat modeling that fits your process.

Model architectures, identify threats, assess risks. Visually and structured.