Threat Modelling

CI/CD

Mitre ATT&CK aligned approach to thread modelling CI/CD environments

https://github.com/rung/threat-matrix-cicd

Threat Actors

STIX's threat actor capability definitions. Useful to calibrate your threat model against.

https://docs.oasis-open.org/cti/stix/v2.1/csprd01/stix-v2.1-csprd01.html#_Toc16070817