Threat Dragon and pyTM are both participating in the CycloneDX TMBOM (Threat Model Bill of Materials) effort. The goal? A common format so models can move between tools, instead of getting locked into one.
https://threatmodeling.dev/dragpyt/
Why is this important?
This has the potential of resolving a rather overall, organizational threat modeling adoption challenge:
- Product managers, ... (high level) cannot code or do not like to code -> Threat Dragon
- SW Architects (high level <-> low level) prefer "threat models as code" over "threat models as diagram" due to scalability reasons -> pytm
- SW Engineers, Security Engineers, Pentesters, ... (low level) can code and like to code -> pytm
https://threatmodeling.dev/dragpyt/
Why is this important?
This has the potential of resolving a rather overall, organizational threat modeling adoption challenge: