Back to Threat Model Lab
STRIDE Exercise

STRIDE Threat Model Builder

Drag each threat card into the correct STRIDE category. All 12 must be placed before you can check.

🏦
🏥
🔐
🏦

Online Banking Portal

Scenario 1 of 3

A retail bank's web application. Customers log in, view balances, transfer funds, and download statements. The system uses a login service, a transaction database, and an audit log.

Threats to classify 12 remaining

A customer exploits a parameter manipulation vulnerability to change their account type from 'basic' to 'premium'

Thousands of automated login attempts flood the authentication service, locking out real users

A teller processes a fraudulent withdrawal and deletes the paper trail, claiming the transaction never occurred

A bug in the transfer form allows a standard user to approve transactions above their authorised limit

A misconfigured API exposes account balances in unencrypted HTTP responses

An error in the statement download feature allows users to retrieve other customers' documents

A customer claims they never initiated a transfer that's clearly in the logs

An attacker deliberately triggers the bank's fraud detection rules thousands of times to freeze all legitimate transactions

An attacker uses stolen credentials to log in as another customer

A fraudulent third-party app presents itself as the bank's official mobile application to harvest credentials

An attacker intercepts and modifies a fund transfer request mid-transit

An insider alters historical transaction records to cover fraudulent activity

STRIDE Categories — drop threats here

S

Spoofing

Pretending to be someone or something else

T

Tampering

Modifying data or code without authorisation

R

Repudiation

Denying that an action was performed

I

Info Disclosure

Exposing data to unauthorised parties

D

Denial of Service

Disrupting availability of a system

E

Elevation of Privilege

Gaining capabilities beyond what was granted

Feisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.