in comparison to existing technologies, we provide a:

  • Low entry barrier to generating threat models by allowing the ingestion of existing design documents, thus empowering organizations to design secure systems from the start unlike some technologies that require a system to be in production
  • Comprehensive, global picture of threat model that identifies attack paths taken through the system unlike most technologies that only identify siloed threats on individual system components
  • Contextualized security controls that identify specific system components to be protected unlike most technologies that only provide generic explanations regarding the controls

Currently, we are offering short trials to interested customers.

Current manual threat modelling approaches take weeks to create a system-specific threat model. Our approach reduces that to within a comfortable day. User studies have shown that manual input by users takes less than three hours. We also support the ingestion of existing system documentation to streamline the data gathering stage, which reduces the time taken for users to manually fill in system information to our tool. 

Once all system information is provided, our tool takes less than 5 minutes to generate a threat model specific to your system along with the security controls needed to address the threats. 

We support NIST CSF, ISO 27001, and Singapore’s CCoP and IM8. We are continuously expanding to other industry-specific compliance standards.

ThreatMirror supports a growing number of threat modelling frameworks including MITRE ATT&CK, STRIDE-LM, PASTA, and STPA-SEC.

Besides our SaaS service, we support on-prem installations of ThreatMirror. Our AI technologies can also be configured to utilize models deployed on-premise. Thus, no sensitive data will leave your premises.

We use a combination of deterministic attack graph generation and AI threat generation to produce ranked attack paths. The attack steps are grounded in the MITRE ATT&CK framework which extends to domains including enterprises, industrial control systems, embedded devices, 5G networks, and AI systems. We also ingest threat intelligence and automatically update our knowledge base.

ThreatMirror ingests intelligence feeds such as NIST’s National Vulnerability Database (NVD), automatically models the ingested security intelligence in our knowledge base, and applies it to your existing systems automatically at the click of a button.

Your latest vulnerability assessments and pentesting results (VAPT) can also be ingested to identify critical attack paths exploiting the found vulnerabilities.