OWASP Threat Dragon is a powerful, open-source tool designed to help developers and security teams create threat models through intuitive data flow diagrams. As part of the , it provides a structured yet flexible environment to identify, evaluate, and mitigate security risks early in the software development lifecycle (SDLC). Download and Install OWASP Threat Dragon
Threat Dragon is available as a cross-platform desktop application and a web-based version. As of May 2026, the . 1. Desktop Application (Windows, macOS, Linux) download owasp threat dragon
The desktop version stores threat models exclusively on your local filesystem, making it a secure choice for offline work. Releases · OWASP/threat-dragon - GitHub OWASP Threat Dragon is a powerful, open-source tool