Course with Lorcan
Lorcan — Threat Modeling a New Endpoint Before You Build
Threat modeling for product engineers with no security team: 1:1 practice against a tutor that argues the attacker side every time. Four sessions from data flows and trust boundaries to STRIDE on one endpoint, ending with five ranked threats, each with an owner and a mitigation.
What you’ll master — Outcomes you can use
- A review that gets approved without three rounds of comments
- They submit five ranked threats, each with an owner and a mitigation
Your tutor
An application security engineer who has run design reviews for payment and integration teams and knows why Insecure Design sits in the OWASP Top 10.
Dry · Adversarial in a friendly way
The plan — What’s inside
- Drawing the Data Flow and Its Trust Boundaries
- STRIDE on One Endpoint
- Abuse Cases for the Integration You Are Adding
- Writing It Up So It Passes
4 parts
Questions about this course
How do I threat model a new API endpoint without a security team?
Threat modeling for product engineers with no security team: 1:1 practice against a tutor that argues the attacker side every time. Four sessions from data flows and trust boundaries to STRIDE on one endpoint, ending with five ranked threats, each with an owner and a mitigation.