AWS Threat Composer
About
AWS Threat Composer is a threat-modeling project for identifying security issues and developing response strategies through iterative modeling. Its structured threat grammar offers adaptive suggestions as users compose threat statements. Models can include architecture and data-flow diagrams, tracked assumptions, links between threats and mitigations, and an insights dashboard with quality metrics and improvement suggestions. Multiple models can be managed and exported as JSON, Markdown, DOCX or PDF. The web app stores data in the browser and supports import and export; users can work with a hosted demo or deploy a static site in an AWS account. The VS Code extension in AWS Toolkit edits .tc.json files, works offline and stores data locally. A browser extension displays model files on GitHub, GitLab, Bitbucket and Amazon CodeCatalyst, including configured self-hosted instances. The AI-assisted CLI and MCP server analyze source code to generate starter models, but are marked experimental and incur AWS Bedrock inference costs.
Who it is for
Threat Composer suits people modeling system security issues who want diagrams, assumptions, mitigations and exports in one workflow. Its VS Code integration also fits teams keeping models alongside code in version control.
What is good
- Threat grammar provides adaptive writing suggestions
- Models include diagrams, assumptions and mitigations
- Exports JSON, Markdown, DOCX and PDF
- VS Code extension works offline
- Web app supports browser storage and import/export
What to know first
- AI CLI and MCP server are experimental
- AI tools incur AWS Bedrock inference costs
- Browser extension is read-only
- Browser extension needs internet for web-hosted files
Verdict
Threat Composer covers structured modeling, review and export, with web, VS Code and browser-based paths. The AI tools are experimental and have inference costs; browser extension users should note its read-only scope and internet requirement for web-hosted files.
Compared on threat modeling software
- Free plan
- Yesawslabs.github.io
- Risk prioritization
- Yesawslabs.github.io
- Collaborative review
- Yesawslabs.github.io
- Templates and frameworks
- Yesawslabs.github.io
- Deployment
- bothawslabs.github.io
Facts
- Purpose
- Threat Composer helps users identify security issues and develop strategies to address them through iterative threat modeling.github.com · 2 Oct 2026
- Threat writing
- It uses structured threat grammar with adaptive suggestions to help compose threat statements.github.com · 2 Oct 2026
- Modeling features
- It supports architecture and data flow diagrams, assumptions tracking, threat and mitigation links, and an insights dashboard.github.com · 2 Oct 2026
- Exports
- Threat models can be exported in JSON, Markdown, DOCX, and PDF formats.github.com · 2 Oct 2026
- Web app storage
- The web application uses browser-based storage and supports import and export.github.com · 2 Oct 2026
- Self-hosting
- The web application can be deployed to an AWS account with customization.github.com · 2 Oct 2026
- AI tools
- The AI-assisted CLI and MCP server analyze source code to generate starter threat models; the AI tools are marked experimental.github.com · 2 Oct 2026
- AI cost
- The project page says AWS Bedrock inference costs apply to the AI-powered CLI and MCP server.github.com · 2 Oct 2026
- VS Code
- The VS Code extension is included in AWS Toolkit and edits .tc.json files; its documentation says it works offline and stores data in local files.github.com · 2 Oct 2026
- Browser extension integrations
- The browser extension supports GitHub, GitLab, Bitbucket, and Amazon CodeCatalyst, including configurable URL patterns for self-hosted instances.github.com · 2 Oct 2026
- Browser extension limits
- The browser extension is read-only, requires internet access to load web files, and its documentation says Chrome Web Store and Firefox Add-ons publication is not yet available.github.com · 2 Oct 2026
- Browser extension privacy
- Its documentation says it does not collect or transmit data, uses no analytics or tracking, and makes no external API calls.github.com · 2 Oct 2026
- Audience and workflow
- The project is designed for people threat modeling systems, and its VS Code integration supports keeping threat models alongside code in version control.github.com · 2 Oct 2026
- Support
- The project directs users to GitHub Issues and GitHub Discussions for bug reports, feature requests, and questions.github.com · 2 Oct 2026
- Threat statements
- It uses structured threat grammar with adaptive suggestions to help users compose threat statements.github.com · 3 Oct 2026
- Diagrams and insights
- Features include architecture and data flow diagrams, plus an insights dashboard with quality metrics and improvement suggestions.github.com · 3 Oct 2026
- Model management
- Users can track assumptions, link them to threats and mitigations, manage multiple models, and export models as JSON, Markdown, DOCX, or PDF.github.com · 3 Oct 2026
- Web app
- The web application is available as a hosted demo or as a static website users can self-host in their AWS account; it supports browser-based storage and import/export.github.com · 3 Oct 2026
- AI usage costs
- The AI CLI and MCP server use AWS Bedrock, and Bedrock inference costs apply.github.com · 3 Oct 2026
- Browser integrations
- The browser extension supports viewing threat model files on GitHub, GitLab, Bitbucket, and Amazon CodeCatalyst; its documentation says Chrome Web Store and Firefox Add-ons publication is not yet available.github.com · 3 Oct 2026
- Browser extension limitation
- The browser extension provides read-only viewing, requires internet access to load web-hosted files, and may take time to load large models.github.com · 3 Oct 2026
- Support and security reports
- The project directs users to GitHub Issues and Discussions for feedback and support, and asks that security vulnerabilities be reported through AWS's Vulnerability Disclosure Program or [email protected].github.com · 3 Oct 2026
Best AWS Threat Composer alternatives
See all 12
7.4 ThreatModeler Nexus $333.33/mo first paid tier Free plan
7.4 ThreatOpus £129.99/mo first paid tier Free plan
7.4 ThreatTree $29/mo first paid tier Free plan
7.3 CAIRIS Free free plan, no paid price published Free plan
7.3 IriusRisk Free free plan, no paid price published Free plan
6.8 CYMETRIS €99/mo first paid tier Where it ranks on Inferse
Sources
- github.com/awslabs/threat-composer· checked 2 Oct 2026
- github.com/awslabs/threat-composer/blob/main/docs/· checked 2 Oct 2026
- github.com/awslabs/threat-composer/blob/main/docs/· checked 2 Oct 2026




