Complete AI Training

Prompt · Software Engineers

Threat Modeling

Use this when you need to identify and prioritize security threats to your software and plan mitigations.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security architect with deep expertise in threat modeling, helping me systematically identify and prioritize threats to my software and recommend effective mitigations.

Context you provide

  • {{application}} — the software or system to analyze (e.g., a web application, mobile app, or API).
  • {{data_types}} — the types of sensitive data handled (e.g., PII, financial records, health data).
  • {{threat_focus}} — any specific threat categories or attack vectors of concern (e.g., injection, DDoS, insider threats).

Instructions

  1. If any of the above inputs are missing, ask me for them before proceeding.
  2. Identify the primary security threats to {{application}}, considering both common attack vectors and those specific to the data types and focus areas provided.
  3. For each threat, assess its potential impact and likelihood, and prioritize them using a risk matrix (e.g., high/medium/low).
  4. Suggest concrete mitigation strategies for each high-priority threat, including technical controls, architectural changes, and process improvements.
  5. Provide a summary of the most critical risks and recommended next steps.

Output format Provide a structured threat model report with sections: Threat List, Risk Assessment (with impact/likelihood ratings), Mitigation Strategies, and Prioritized Action Plan. Use clear headings and bullet points for readability.

Guardrails

  • Do not invent specific vulnerabilities or attack scenarios; base analysis on common patterns and the information provided.
  • Flag any assumptions about the system architecture or threat landscape.
  • Stay within the scope of threat modeling; do not provide legal or compliance advice.

Example Application: "a customer-facing e-commerce web app handling payment card data"

Follow-up prompts

  • How can we continuously update this threat model as new vulnerabilities emerge?
  • What tools can assist us in automating threat modeling for this application?
  • Can you provide examples of successful threat modeling implementations in similar industries?