A threat model of one site, from evidence
Ivy Insight draws one website, asset or scan from what the scan observed: the findings, the coverage records and the facts on the asset. Every part is marked observed, inferred, assumed or not observed.
Each threat links to the findings behind it, with its STRIDE (Spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege. The six kinds of threat used in threat modelling.) category. Threats that were not tested are listed apart and never rated. An attack path is shown only when every step of it was observed.
- It covers one asset or scan at a time, and is built for websites and APIs
- It does not model business logic