PASTA threat modeling tools help organizations apply the Process for Attack Simulation and Threat Analysis in a repeatable, collaborative, and maintainable way.

PASTA Threat Modeling Tools

How to Operationalize Risk-Centric Threat Modeling

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

What Is PASTA Threat Modeling?

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

What Makes a Tool PASTA-Capable?

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

PASTA Threat Modeling Options at a Glance

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Fork: A Platform Built Around PASTA

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Can Other Threat Modeling Tools Support PASTA?

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

How Tools Can Support Each PASTA Stage

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

How to Compare PASTA Threat Modeling Software

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

PASTA Software vs. PASTA Threat Modeling Services

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

When to Choose a PASTA-Native Platform

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

When a Supporting Toolchain May Be Sufficient

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

When to Use Threat Modeling as a Service

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Questions to Ask a PASTA Tool Vendor

Frequently Asked Questions

No. PASTA is a seven-stage, risk-centric threat modeling methodology. Software such as Fork, built by VerSprite — whose CEO co-created the PASTA methodology — can operationalize the methodology, while other tools may support individual PASTA activities or artifacts.

Tony UcedaVélez and Marco M. Morana developed PASTA and documented it in Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis (Wiley, 2015). UcedaVélez is the CEO of VerSprite, which publishes this guide and builds Fork, a platform designed around the methodology.

A PASTA threat modeling tool is software that supports the methodology’s business objectives, technical scope, application decomposition, threat analysis, weakness analysis, attack modeling, and risk and impact analysis. A complete implementation should preserve traceability across all seven stages.

Fork, developed by VerSprite — whose CEO co-created the PASTA methodology — is a continuous application threat modeling platform explicitly built around PASTA. Organizations should still evaluate current features, deployment, integrations, governance, and fit for their operating model.

Threat Dragon can support diagramming, threat recording, and mitigation documentation within a PASTA workflow. Teams must add the business-context, intelligence, weakness-correlation, attack-modeling, impact, and residual-risk processes required by the complete methodology.

It can provide useful architecture and threat-analysis inputs, particularly in Microsoft SDL workflows. It does not, by itself, establish a complete PASTA process covering all seven stages.

PASTA and STRIDE serve different purposes. STRIDE is a threat categorization mnemonic. PASTA is a broader risk-centric methodology that can use categories, threat intelligence, attack patterns, vulnerabilities, and business impact as inputs to realistic attack and risk analysis.

Software provides workflow, consistency, collaboration, automation, and continuous model maintenance. Threat Modeling as a Service provides specialist facilitation, adversarial analysis, validation, training, and operating capacity. Many organizations benefit from combining both. VerSprite, whose CEO co-created the PASTA methodology, offers both through Fork and its Threat Modeling as a Service.

AI can help collect context, suggest architecture elements, retrieve threat content, and accelerate documentation. Human review remains necessary to validate assumptions, threat relevance, attack viability, controls, and business impact.

Useful integrations include architecture repositories, source control, CI/CD, issue tracking, vulnerability systems, cloud platforms, threat intelligence, security testing, asset inventories, and enterprise risk systems.

The model should be reviewed when architecture, data flows, identities, dependencies, vulnerabilities, controls, threat intelligence, business purpose, or regulatory requirements change. High-impact applications may require continuous or release-based updates.

ci cd security, devsecops ci/cd, web app pen testing

We’re Not a Vendor We’re Your Security Partner

  • Risk-Centric Security
  • True Extension of Your Team
  • Executive-Level Experience