OWASP Threat Dragon
Ranked in Threat Modeling Software ·Free plan
About
OWASP Threat Dragon creates threat-model diagrams and records threats associated with their elements as part of secure development work. Diagrams can show processes, data stores, actors, data flows and trust boundaries. The tool supports STRIDE, LINDDUN, CIA, CIA-DIE, DIE and PLOT4ai categories. A rule engine can suggest threats and mitigations using properties of diagram elements. Threat Dragon is free and open source under Apache License 2.0. It can run as a containerized, self-hosted web application or as a desktop app, with installers for Windows, macOS and Linux. The web version supports local files and configurable access to GitHub, GitHub Enterprise, Google Drive, Bitbucket, Bitbucket Enterprise and GitLab; the desktop app saves models locally. The project says analytics are disabled by default, require server configuration, and do not collect threat-model content or usernames for Plausible. It also describes repository and release security practices, including signed commits and desktop releases signed and notarized where possible. The project is volunteer-maintained and notes that immediate investigation or response to incidents may not always be possible.
Who it is for
Threat Dragon is intended for developers and defenders, including both experienced threat modelers and beginners. It suits teams that want desktop or self-hosted modeling and configurable storage integrations.
What is good
- Free, open-source software under Apache License 2.0
- Supports six threat category frameworks
- Rule engine suggests threats and mitigations
- Desktop and self-hosted web deployment options
- Analytics disabled by default
What to know first
- Volunteer maintainers may not respond immediately to incidents
- Web integrations require configuration
Verdict
Threat Dragon offers diagram-based threat modeling with multiple frameworks and deployment options, at no listed cost. Teams should weigh its volunteer maintenance model and configure web integrations to suit their storage needs.
Compared on threat modeling software
- Free plan
- Yesthreatdragon.com
- Risk prioritization
- Yesthreatdragon.com
- Templates and frameworks
- Yesthreatdragon.com
- Modeling methods
- multiplethreatdragon.com
- Deployment
- self_hostedthreatdragon.com
Facts
- Purpose
- Threat Dragon creates threat model diagrams and lists threats for diagram elements as part of a secure development lifecycle.owasp.org · 3 Oct 2026
- Threat frameworks
- It supports STRIDE, LINDDUN, CIA, CIA-DIE, DIE and PLOT4ai threat categories.threatdragon.com · 3 Oct 2026
- Threat suggestions
- A rule engine can suggest threats and mitigations, including context-specific suggestions based on diagram element properties.threatdragon.com · 3 Oct 2026
- Diagrams
- Diagrams can include processes, data stores, actors, data flows and trust boundaries.threatdragon.com · 3 Oct 2026
- Storage and integrations
- The web app supports local file storage and configurable access to GitHub, GitHub Enterprise, Google Drive, Bitbucket, Bitbucket Enterprise and GitLab; the desktop app saves models locally.threatdragon.com · 3 Oct 2026
- Desktop platforms
- Desktop installers are provided for Windows, macOS and Linux.threatdragon.com · 3 Oct 2026
- License
- The OWASP project page lists the license as Apache License 2.0.owasp.org · 3 Oct 2026
- Security practices
- The project says its repository enforces signed commits, supply-chain actions use full-length SHAs, and desktop releases are signed and notarized where possible.threatdragon.com · 3 Oct 2026
- Security testing
- The project says automated dependency, SAST, DAST and container security scans run on every commit.threatdragon.com · 3 Oct 2026
- Privacy
- Analytics are disabled by default, require server configuration, and do not collect threat model content or usernames for Plausible.threatdragon.com · 3 Oct 2026
- Support
- The project directs users to its mailing list, OWASP Slack channel, GitHub issues and public discussions for questions, bugs and feature requests.owasp.org · 3 Oct 2026
- Maintenance limitation
- The project is maintained by volunteers and says immediate investigation or response to incidents is not always possible.threatdragon.com · 3 Oct 2026
- Intended users
- OWASP describes Threat Dragon as intended for developers and defenders, and says both experienced threat modelers and beginners can use it.owasp.org · 3 Oct 2026
Best OWASP Threat Dragon alternatives
See all 20Where it ranks on Inferse
Sources
- owasp.org/projects/threat-dragon· checked 3 Oct 2026
- threatdragon.com/docs/· checked 3 Oct 2026
- threatdragon.com/docs/usage/threats.html· checked 3 Oct 2026
- threatdragon.com/docs/usage/diagrams.html· checked 3 Oct 2026
- threatdragon.com/docs/trust/trust.html· checked 3 Oct 2026
- threatdragon.com/docs/trust/analytics.html· checked 3 Oct 2026



