Threat actors are constantly evolving their tactics, techniques, and procedures (TTPs), which often makes understanding and mitigating potential threats a daunting task. Traditional threat modeling frameworks can fall short or even be seen as intimidating to defenders trying to model potential threats. This is often due to the complexity or amount of effort and knowledge required to build threat models. Additionally, many threat models limit the potential audience due to overly complex or detailed presentations, limiting the overall effectiveness of the model.
To bridge this gap, we have developed the OATMEAL threat modeling framework. OATMEAL stands for Overlays And Threat Modeling Events And Limitations, and it is designed to provide a comprehensive, yet straightforward and unintimidating approach to threat modeling.
Leave a Reply