Glossary

    Threat Modeling

    Architecture & Design

    Threat Modeling is a proactive security practice where you systematically identify threats, vulnerabilities, and attack vectors for your architecture before (or as) you build it.

    Common Frameworks

    • STRIDE: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege
    • PASTA: Process for Attack Simulation and Threat Analysis (7-step risk-centric approach)
    • AWS Threat Composer: free AWS tool for creating threat models based on your architecture

    AWS-Specific Threats

    • Overprivileged IAM roles enabling lateral movement
    • Public S3 buckets or security groups exposing data/services
    • Cross-account trust relationships being abused
    • Credential exposure through metadata service (IMDSv1)
    • Supply chain attacks through third-party Lambda layers or container images

    Process

    1. Define what you're building (architecture diagram)
    2. Identify threats (what could go wrong)
    3. Assess risk (likelihood × impact)
    4. Design mitigations (security controls)
    5. Validate (penetration testing, red team)

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.