{"repo":"bogdanticu88/threatmap","free":true,"listed":false,"github":"https://github.com/bogdanticu88/threatmap","clone":"git clone https://github.com/bogdanticu88/threatmap.git","description":"IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and Kubernetes.","language":"Python","stars":61,"topics":["cloudformation","devsecops","dfd","github-actions","iac-security","kubernetes","mermaid","security-tools","static-analysis","stride"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"threatmap Static IaC threat modeler that parses Terraform, CloudFormation, and Kubernetes manifests and produces structured threat model reports using STRIDE, MITRE ATT&CK, or PASTA frameworks. No network calls, no cloud credentials, fully offline. Runs as a CLI, REST API, or containerized service. --- Quick Start CLI: Docker: REST API Server: GraphQL API: --- Supported Formats and Providers Format Provider Extension -------- ---------- ----------- Terraform HCL AWS, Azure, GCP .tf CloudFormation AWS .yaml , .yml , .json Kubernetes manifests Kubernetes .yaml , .yml --- Install Install from PyPI: Or for local development: --- Usage Scan a directory and print a Markdown report to stdout: Scan multiple paths and write a JSON report to a file: Generate an interactive HTML report or a SARIF report for GitHub Security: CI gate — exit code 1 if any CRITICAL or HIGH threat is found: Print a terminal summary table only, without writing a full report: Use ASCII-only severity indicators (no emojis) for environments that don't support Unicode: Analyze using different threat modeling frameworks: --- Threat Modeling Frameworks STRIDE (73 rules) - Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege - Threat-centric approach ideal for identifying attack surface - Provider-specific: AWS (22 rules), Azure (19 rules), GCP (15 rules), Kubernetes (17 rules) - Best for: Traditional threat modeling, security architecture reviews MITRE ATT&CK (11 rules","default_branch":null,"files":null,"tree":[],"storefront":"/r/bogdanticu88","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bogdanticu88/threatmap/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}