Threat Thinker is designed to make threat modeling lightweight and continuously usable in modern development environments.
It automatically extracts components, data flows, and trust boundaries from system architecture diagrams and produces a prioritized list of threats with concise explanations and ASVS/CWE references.
Threat Thinker is composed of five major layers:
-
Parser Layer
Converts diagrams (Mermaid, Draw.io, Threat Dragon, or image files via LLM vision) into a unified intermediate representation (GraphofNodeandEdge) and also accepts nativeGraphIR JSON directly. Supports Mermaid.mmd/.mermaid, Draw.io.drawio/.xml, Threat Dragon v2.json, native IR.jsonvia explicit selection, and image files (.jpg/.jpeg/.png/.gif/.bmp/.webp). -
Inference Layer (LLM-assisted)
Infers missing attributes such as zone, type, and data sensitivity using a combination of syntax parsing and large language model reasoning. Supports multiple LLM providers (OpenAI, Anthropic, AWS Bedrock). -
Threat Generation Layer
Uses LLM-based analysis to enumerate and score threats based on STRIDE categories, providing one-line rationales and references to OWASP ASVS and CWE. Supports multilingual output. -
Threat Filtering & Denoising Layer
Applies sophisticated filtering algorithms to remove generic threats, enforce quality thresholds (ASVS references, confidence scores, evidence requirements), eliminate near-duplicates, and rank threats by score and severity. -
Reporting Layer
Outputs results as Markdown or JSON and supports incremental updates through diff comparison between versions. Includes Web UI interface powered by Gradio.
Diagram or IR (.mmd/.mermaid, .drawio/.xml, Threat Dragon JSON, native IR JSON, or image files)
↓
[Parser/Input Loader] → Graph(nodes, edges) + ImportMetrics
↓
[LLM Attribute Inference] (optional, multilingual)
↓
[LLM Threat Generation] (multilingual)
↓
[Threat Filtering & Denoising]
↓
[Export] → Markdown / JSON / Diff
- Multi-Format Support: Supports Mermaid diagrams, Draw.io files, and image-based architecture diagrams using LLM vision capabilities.
- Multilingual Support: Attribute inference and threat generation support multiple languages through ISO language codes.
- Multiple LLM Providers: Supports OpenAI, Anthropic, and AWS Bedrock APIs with flexible configuration.
- Hybrid Parsing: Combines static syntax parsing with LLM completion to improve structure accuracy and reduce noise.
- Low-Noise Threat Extraction: Advanced filtering and denoising algorithms remove generalized findings and focus on diagram-specific risks through multiple quality gates including ASVS reference requirements, confidence thresholds, evidence validation, and near-duplicate detection.
- Explainable Output: Every threat includes a one-line reason and references to ASVS or CWE, plus evidence nodes/edges.
- Incremental Analysis: Supports differential updates when diagrams change.
- Dual Interface: CLI-based tool for automation and Gradio Web UI for interactive use.
- Import Metrics: Tracks parsing success rates and provides feedback on diagram interpretation quality.