A threat modeling method devised by Microsoft that classifies threats into six categories.
The letters stand for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It's used as a checklist for comprehensively surfacing threats during the design phase.
© 2026 ITBGM