Published by OWASP

Threat Dragon

An open-source threat modeling tool and official OWASP project.

Version2.5.0 LicenseApache-2.0 winget • nullsoft Archx86 ReleasedAugust 19, 2025
securitythreat-modelingowaspstridesdlcdevsecops

OWASP Threat Dragon is a free, cross-platform threat modeling application for drawing data-flow diagrams and documenting threats per the STRIDE methodology. List mitigations, assign severity scores, and generate reports. Follows the values of the Threat Modeling Manifesto. Available as a desktop app or self-hosted web application. An official OWASP Lab Project.

Release notes: Added demo models from Threat Model Cookbook, about box for all platforms, CIA-DIE classification extension, keyboard shortcut save fix, and multiple UX improvements.

winget install --id OWASP.ThreatDragon

PACKAGE IDENTIFIER: OWASP.ThreatDragon