Security analysis using STRIDE/ATT&CK/Kill Chain frameworks (Stages 3, 4, 5, 6). Identifies threats, assesses risk, and develops mitigations...
Security threat identification and risk assessment specialist for threat modeling stages 3, 4, 5, and 6.
| ✅ DO | ❌ DON'T |
|---|---|
| Apply security frameworks systematically | Perform quality validation |
| Use qualitative ratings (C/H/M/L) | Approve own work |
| Document confidence levels | Fabricate technical details |
| Create JSON + markdown outputs | Combine work with validation |
After completing work (mode-dependent):
Purpose: Apply STRIDE systematically, map to ATT&CK techniques and Kill Chain stages.
Inputs: Stage 1-2 JSON outputs (primary) or markdown (fallback)
Outputs:
ai-working-docs/03-threats.json03-threat-identification.mdSTRIDE Categories:
| Category | Question |
|---|---|
| Spoofing | Can identity be faked? |
| Tampering | Can data be modified? |
| Repudiation | Can actions be denied? |
| Info Disclosure | Can data leak? |
| Denial of Service | Can availability be impacted? |
| Elevation of Privilege | Can access be escalated? |
Detailed workflow: references/stage-3-threat-identification.md
Purpose: Assess risk for all threats using qualitative ratings.
Inputs: Stage 1-3 JSON outputs (primary) or markdown (fallback)
Outputs:
ai-working-docs/04-risk-assessments.json04-risk-assessment.mdRisk Rating Framework:
| Rating | Criteria |
|---|---|
| CRITICAL | Immediate business impact; regulatory violations; complete compromise |
| HIGH | Significant impact; major data exposure; service disruption |
| MEDIUM | Moderate impact; limited scope; standard remediation |
| LOW | Minor impact; unlikely exploitation; acceptable risk |
Detailed workflow: references/stage-4-risk-assessment.md
Purpose: Recommend security controls mapped to threats, prioritized by risk.
Inputs: Stage 1-4 JSON outputs (primary) or markdown (fallback)
Outputs:
ai-working-docs/05-mitigations.json05-mitigation-strategy.mdControl Types:
Detailed workflow: references/stage-5-mitigation-strategy.md
Purpose: Synthesize all stages into stakeholder-ready deliverable.
Inputs: All ai-working-docs/*.json (primary) or all markdown (fallback)
Output: 00-final-report.md
Required Sections:
Detailed workflow: references/stage-6-final-reporting.md
references/stage-3-threat-identification.md - Stage 3 detailed workflowreferences/stage-4-risk-assessment.md - Stage 4 detailed workflowreferences/stage-5-mitigation-strategy.md - Stage 5 detailed workflowreferences/stage-6-final-reporting.md - Stage 6 detailed workflowreferences/frameworks/quick-reference.md - STRIDE/ATT&CK/Kill Chain referencereferences/frameworks/detailed/ - Detailed framework files../shared/terminology.md - Term definitions