The Art of Practical Threat Modelling Training @BSides Perth
Description
They say Threat Modelling is an art form just as technical as it is. It was also thought to be hard to use or teach. I will show you how to do it, step-by-step as I have done in my security consulting practice and past experiences. We will dive into different Threat Modelling methodologies from the most common STRIDE and DREAD methodologies to the more advanced PASTA and NIST methodologies. This will help you decide which ones to use, but the ultimate goal is to identify threats, work with your engineers, agree on fixes, perform mitigation, and improve your layered defense-in-depth.
This full day Threat Modelling training is geared towards intermediate audiences with software engineering and security engineer/pentester backgrounds who have never done any threat modelling work but are trying to get into it. However, it also has modules that would help beginners get up to speed in threat modelling practically right after the training, so beginners are also welcomed. Many cybersecurity practitioners face threat modelling requirements as part of their jobs but don't know where to start or how to do it. This training focuses on arming them with the knowledge and techniques used by the instructor in his security consultancy career. Practically, anyone can join this class even without those backgrounds, provided they have at least some basic idea of how programs work at a code level, basic cybersecurity issues and threats and anyone interested in learning them.
The main goal of this training is to equip participants with an understanding of the importance of threat modelling in dealing with and understanding cyber threats to their applications and networks. The trainer's goal is to prevent more software security bugs from inception by teaching students how to build more secure software or find underlying security flaws and bugs, minimizing the risks and impact of the engineered software. Participants will be immersed in STRIDE, DREAD, PASTA and NIST methodologies for threat modelling and will create their own threat models during the training. STRIDE and DREAD are the most common threat modelling methodologies which we will focus on during the first part of the training. In the remaining half, we will move on to PASTA, which has become an increasingly popular methodology asked of practitioners and consultants to present a different point of view of an organization's potential threats. We will also look at the NIST threat modelling methodology as another comparison. This class focuses on being technology-agnostic with threat modelling methodologies; threat modelling software, while useful, is not relevant to the main goal of the training.
Agenda
- 8:30 am - 5:00 pm
Training Outline
Full Session Outline: * Basics and Overview of Threat Modelling * Threat Modelling Terminologies * Real-life examples of threat models of information systems (let's skip the example of a house, office, etc) and this will be about web apps, mobile apps, networks, cloud infrastructure, etc. * Hands-on Exercises for Identifying Threat Model Elements * Q&A * Threat Modelling Techniques * Discuss STRIDE and DREAD in detail usage for threat models * The Threat Modelling Process * Real-life examples of information system threat models using STRIDE and DREAD * Q&A * Hands-on Exercises with STRIDE on the first two-three exercises each * Hands-on Exercises with DREAD overlay of risk on the first two-three exercises each * Discuss mitigation/recommendations * Discuss Full Threat Models from start to finish using STRIDE and DREAD * Q&A * Overview of PASTA methodology * The 7 stages in PASTA methodology * PASTA vs STRIDE and DREAD * Discuss PASTA in detail usage for threat models * The PASTA Threat Modelling Process * Hands-on Exercises with PASTA threat modelling * Discuss Full Threat Models from start to finish using PASTA * Q&A * Discuss the Overview of NIST methodology * STRIDE vs DREAD vs PASTA vs NIST * Q&A ** Threat Modelling Tools (OWASP Threat Dragon, Lucid Chart and any other diagramming software) ** More interactive workshop examples of threat modelling (depends on the group's pace) ** Q&A ** These depend on the class' pace and if we still have more time.
FAQs
- Do I need to know how to write code? Does this training require me to be hands-on with pentesting and coding?
You don't need to write code in this training, but understanding how code works, how systems work, security implications and issues of changes in the features, system or code would go a long way.
You also don't need to have pentesting and coding experience, but that helps in understanding the threat models and security issues we will discuss and the mitigation for it.
- Since this says that it is an intermediate Threat Modelling training, am I expected to know STRIDE & DREAD threat modelling methodologies?
It is indeed an intermediate Threat Modelling training as you will learn deeper techniques and strengthen your threat modelling knowledge to aid you in Security Architecture and Security Design Review work as well as Security Engineering types of work. While it is expected you know the basics of STRIDE & DREAD, we will go through it just a refresher but not dive too much on it especially if the whole group are quite well-versed about it so that we can dive deeper into PASTA & NIST methodologies.
- Do I need to bring a laptop and install anything for this training?
This Threat Modelling training is a technology-agnostic training. You can actually just learn by a pen and paper as how I learned to do threat modelling in the first place. If you wish to bring your laptop for note taking, by all means please do so! You may also want to install some of the Threat Modelling and Diagramming software I used in this work, so you could install: OWASP Threat Dragon, Lucid Chart, Smart Draw, Draw.io and other threat modelling software if you wish. I will demo them if time permits.
- Will I be a master Security Engineer / Architect after this class? Will it be easy for me to threat model after this?
No, but you will be having the foundations to easily do it on your own without any software aiding you. Through the hands-on exercises, you will be thinking deeper than prior to taking this class and by the end of the training I can assure you would have at least the basic chops to get started with this type of work. Now, most hiring positions for Security Engineers, Security Consultants and Security Architects require some level of experience and skill sets, but the good news is you are a few steps closer to that vs prior to having the class. As with every skill set, practice makes you have more mastery of it.
- Do I need to have a BSides Perth conference ticket to join this training? Can I just go to this training if I wish?
No, you do not need a BSides Perth conference ticket to join this training. This training is a separate ticket from the main conference.
- I am a Pentester/Security Consultant, will this training be helpful to me if I won't do Security Architecture and Design Review/Security Engineering work?
Congrats being a Pentester/Security Consultant in your job. Let me tell you something, being a Pentester is great and fun, but being a Security Consultant who can do more than hacking stuff makes you more valuable so yes, this training helps elevate your skills. Even if you want to stay in the offensive security space, Threat Modelling helps you map out potential attack surfaces that you may have never thought of in your daily pentest engagements, so I believe this training is still valuable for those folks. If you wish to add more skills to your arsenal, then kudos to you in taking the first step in checking out our training!
Gallery
Trainer Bio
Ralph Andalis is the Director of Security & Founder of Gridlock Security (GridlockSec) - a company that focuses on cybersecurity consulting services. He has 11 years experience in the industry as a Security Consultant/Pentester/Security Researcher. His expertise is mainly Web, Mobile, and Network Pentesting, Threat Modelling, Security Architecture Review, and Security Design Reviews. He recently worked at Microsoft as a Senior Security Engineer handling solely the product security of his assigned product for all his 130+ Software Engineers.
He is also a major active contributor and a member of the working group for the OWASP Application Security Verification Standard (ASVS) project, making the standard better for fellow pentesters and developers alike. Recently, he started helping on OWASP Artificial Intelligence Security Verification Standard (AISVS) to help address the AI-security needs of the global community and open-source standards.
He trained attendees at BSides Vancouver 2025, BSides Orlando 2025, BSides Luxembourg 2026, OWASP AppSec New Zealand Days 2026 for a similar earlier versions of Threat Modelling Trainings which had been well received. He has presented his talk as well on OWASP AppSec Pacific Northwest conference (PNW) 2024 in Vancouver, BC Canada and HackStop Cybersecurity Summit 2024 in Ljubljana, Slovenia.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity