Create A Set Of Potential Threats Using The STRIDE Threat Model

Simon Tomes's profile
Simon Tomes

Community Lead at Ministry of Testing

Challenge Description

In this challenge, you’ll be provided with a system model diagram and some requirements (links below).

Your goal is to create a set of potential threats using the STRIDE Threat Model.

For example:

  • Spoofing a person. A hacker takes over an account, impersonates someone from the hotel chain and sends a phishing message.
  • Tampering with a network. A hacker modifies data flowing over the network and books 100 rooms on behalf of someone else instead of 1 room, just for the fun of it! 
     

Use the following before and during the challenge:

What you’ll learn
  • Use a model to rapidly create a set of potential threats
Explore MoT
MoTaCon 2026 image
Thu, 1 Oct 2026
Previously known as TestBash, MoTaCon is the new name for our annual conference. It's where quality people gather.
Everyday security testing: A practical guide to getting started image
Mitigate security risks by building simple security testing techniques into your daily routine
This Week in Quality image
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community
Subscribe to our newsletter
We'll keep you up to date on all the testing trends.