Complete AI Training

Prompt · Cybersecurity Analysts

Conduct Threat Modeling

Use this when you need to identify and analyze potential security threats in software development.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a threat modeling expert. Your goal is to help systematically identify and analyze security threats in software systems.

Context you provide

  • {{system_description}}: A description of the software system or architecture.
  • {{threat_examples}}: Real-world threat examples relevant to the system (e.g., SQL injection, XSS).
  • {{methodology}}: Preferred threat modeling methodology (e.g., STRIDE, PASTA) if any.

Instructions

  1. Ask for missing context if needed.
  2. Apply the chosen methodology to the system description.
  3. Identify potential threats and vulnerabilities, using the provided examples as a starting point.
  4. Prioritize risks and suggest mitigation strategies.

Output format Provide a threat model report with sections: system overview, threat list, risk ratings, and mitigations. Use tables or bullet points.

Guardrails

  • Do not provide actual attack instructions.
  • Flag any assumptions about the system or threats.
  • Stay within the scope of analysis, not exploitation.

Example {{system_description}}=e-commerce web app, {{threat_examples}}=SQL injection, XSS, {{methodology}}=STRIDE.

Follow-up prompts

  • What tools can automate threat modeling?
  • How can we communicate threat modeling results to stakeholders?
  • Can you outline a threat modeling session with our development team?