Last updated
Threat Dagon is an open source threat modeling tool and is an official OWASP project. It is used to draw threat modeling diagrams and to list threats for elements in the diagram
$ winget install --id OWASP.ThreatDragon --exact --version 2.6.2Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.
Threat-Dragon-ng uses EXE (NSIS). The silent install switches are /S.
Threat-Dragon-ng-Setup-2.6.2.exe /S
See the full silent install reference for Threat-Dragon-ng →
For IT teams
App deployment, patching, and remote support in one place. Push this app to every device you manage, keep it patched automatically, and see new CVEs the moment they land. Works with Intune or fully standalone.
Sign up freeFree for up to 5 devices.
OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application. It is used to draw threat modeling diagrams and to list threats for elements in the diagram along with their remediations.
Threat Dragon is designed to be accessible for various types of teams, with an emphasis on flexibility and simplicity. It is an OWASP Lab Project and follows the values and principles of the threat modeling manifesto
| Architecture | Type | Scope | Install | Download |
|---|---|---|---|---|
| x64 | EXE NSIS | - | Direct |
Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.
No known CVEs for Threat-Dragon-ng.
Coverage is best-effort and depends on a winget package mapping to an NVD CPE entry. Absence here is not a guarantee of safety.
More from OWASP or browse owasp, owasp-threat-dragon, sdlc.