Sign In
Microsoft Application Threat Modeling Blog
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
No tags have been created or used yet.
Archive
Archives
July 2009
(3)
June 2009
(2)
March 2009
(2)
December 2008
(1)
November 2008
(1)
September 2008
(1)
June 2008
(1)
May 2008
(3)
March 2008
(1)
February 2008
(1)
January 2008
(1)
October 2007
(3)
August 2007
(1)
June 2007
(3)
May 2007
(1)
April 2007
(1)
February 2007
(3)
January 2007
(1)
December 2006
(1)
November 2006
(1)
October 2006
(4)
September 2006
(1)
August 2006
(5)
July 2006
(2)
June 2006
(2)
May 2006
(2)
April 2006
(4)
March 2006
(5)
February 2006
(5)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Application Threat Modeling Blog
Security Guidance and Threat Modeling
Posted
over 3 years ago
by
rvanil
5
Comments
I just posted a blog entry on the main drivers behind CTL in TAM v3.0. You can check it out at IST blog site. http://blogs.msdn.com/securitytools/archive/2009/07/30/security-guidance-and-threat-modeling.aspx Thanks RV
Microsoft Application Threat Modeling Blog
TAM 3.0 Beta is Now Live!
Posted
over 3 years ago
by
rvanil
2
Comments
I am excited to say that Threat Analysis and Modeling (TAM) 3.0 Beta is now live on download center. You can download it from here . As this is a beta build we have set up a Connect site that enable you to submit bugs and feature requests. You will...
Microsoft Application Threat Modeling Blog
Threat Analysis And Modeling (TAM) v3.0 – Learn about the New Features!
Posted
over 3 years ago
by
rvanil
0
Comments
Last time we briefly talked about releasing TAM v3.0 this year. With each week we’re inching closer to that goal. TAM v3.0 release is focused on 3 main areas of the tool including: threat modeling methodology gathering application architecture...
Microsoft Application Threat Modeling Blog
TAM 3.0
Posted
over 3 years ago
by
talhahm
0
Comments
Been a little quiet lately on TAM related news but head over to Channel9 to hear RV talk about what's upcoming for TAM 3.0 . -Talhah
Microsoft Application Threat Modeling Blog
Beautiful Security
Posted
over 3 years ago
by
talhahm
0
Comments
My colleague Mark Curphey made available a chapter he wrote for a recently released security book . I had a chance to read his chapter and it’s an absolutely fantastic read with some great thoughts! It’s a must read even if you have even a passing interest...
Microsoft Application Threat Modeling Blog
Tax Season... So Threat Model This...
Posted
over 3 years ago
by
talhahm
2
Comments
Tax Season! I came across a scenario that I wanted to share… Scenario : You have some tax application that, let’s say, we’ll call OnlineTaxApp. You also have your online banking site where you manage your finances/investments/etc. called OnlineBankingSite...
Microsoft Application Threat Modeling Blog
Updated SDL TM Tool Now Available!!
Posted
over 3 years ago
by
talhahm
1
Comments
Very excited to announce that the SDL folks have released v3.1.4 of the SDL Threat Modeling Tool , as the latest and greatest release to apply the DFDs and STRIDE per Element approach to threat modeling. It's a free download, so why not check it out?...
Microsoft Application Threat Modeling Blog
Announcing CAT.NET CTP & Anti-XSS v3 BETA
Posted
over 4 years ago
by
talhahm
1
Comments
Continuing our work to share the tools and techniques we use internally to maintain a secure application portfolio, we today announced the release of CAT.NET CTP and the next version of Anti-XSS . Irfan (Director of ACE) posted a nice entry on the...
Microsoft Application Threat Modeling Blog
SDL Threat Modeling Tool Now Available!
Posted
over 4 years ago
by
talhahm
2
Comments
We're really excited that our colleagues over in the SDL team have released a beta of their threat modeling tool , as one of several SDL-related announcements . As threat modeling matures as a discipline, there's no single 'right' way to do it. Both...
Microsoft Application Threat Modeling Blog
New SDL Threat Modeling Tool Coming Soon!
Posted
over 4 years ago
by
talhahm
2
Comments
Even though this blog’s focus has always been the ACE Threat Modeling tool and methodology which is aligned to our SDL-IT process we use for line-of-business application in Microsoft, there is another security team in Microsoft dedicated to SDL . And...
Microsoft Application Threat Modeling Blog
Is Threat Modeling Right For You?
Posted
over 4 years ago
by
talhahm
2
Comments
Great post by my friend and colleague around threat modeling in a series he's doing on application security lifecycle. http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for...
Microsoft Application Threat Modeling Blog
Threat Management the bigger picture
Posted
over 4 years ago
by
TheRockyH
2
Comments
Threat Modeling is one those ‘sciences’ that is just now starting to gel into something that can be implemented in a semi-automated fashion. With TAM /e, we have a good approach to threat modeling that is both easy on the development...
Microsoft Application Threat Modeling Blog
Using Threat Models Beyond the Design Stage
Posted
over 4 years ago
by
TheRockyH
0
Comments
Threat Modeling is no longer the obscure magic is used to be. With the creation of tools like the Threat Analysis and Modeling tool from the ACE Team, Threat Modeling is now easier to implement, faster and more comprehensive. Threat Modeling is...
Microsoft Application Threat Modeling Blog
Hello Secure World
Posted
over 4 years ago
by
talhahm
1
Comments
An awesome site to check out which also includes virtual labs you can leverage for secure coding! Check it out: www.hellosecureworld.com -Talhah
Microsoft Application Threat Modeling Blog
Customizing TAM Dropdown lists
Posted
over 4 years ago
by
rvanil
0
Comments
One of the most frequent questions we get is that someone is using a technology that is not listed in the “Technology” drop downs and how can they customize it. Most of the dropdowns are part of the metadata system in the tool and are stored in an XML...
Microsoft Application Threat Modeling Blog
[VIDEO] Threat Modeling and Discovering Security Issues
Posted
over 4 years ago
by
talhahm
2
Comments
Raffaele Rialdi, a Microsoft Developer Security MVP, sits down with Lori Grosland at TechEd ATE in Barcelona 2007 and talks about security and the Threat Analysis & Modeling tool (with demo). http://www.virtualteched.com/pages/videossearch.aspx...
Microsoft Application Threat Modeling Blog
Threat Modeling: Diving into the Deep End
Posted
over 4 years ago
by
talhahm
1
Comments
IEEE paper on the TAM tool. "Ford Motor Company is currently introducing threat modeling on strategically important IT applications and business processes. The objective is to support close collaboration between IT Security & Controls (the ITS...
Microsoft Application Threat Modeling Blog
A discussion on threat modeling
Posted
over 5 years ago
by
talhahm
2
Comments
There is a discussion I had recently with a few folks over email around threat modeling that I thought would be nice to share on this blog. I’ll reduce the discussion down to 3 questions/responses. Question : Where does the line between Threat Modeling...
Microsoft Application Threat Modeling Blog
TAM/TAMe and Other ACE Tools
Posted
over 5 years ago
by
talhahm
1
Comments
Mark Curphey (newest member of ACE) recently did a post on a set of tools we have in our portfolio that we're starting to take out to our customers (including TAMe). Read more here . -Talhah
Microsoft Application Threat Modeling Blog
XSSDetect BETA now available!
Posted
over 5 years ago
by
talhahm
1
Comments
I've talked about threat modeling being one part of the overall information security puzzle... there are other controls and tools you need to make the process run smoothly. Our team recently released another of these tools called XSSDetect which helps...
Microsoft Application Threat Modeling Blog
Threat Modeling & SDL-IT
Posted
over 5 years ago
by
talhahm
1
Comments
A common challenge for folks looking at threat modeling as a control to potentially help them secure their software is setting the correct expectations. So what exactly can threat modeling do for you? In order to answer this question, I think it’s important...
Microsoft Application Threat Modeling Blog
Threat Profile and "Composite Threat"
Posted
over 5 years ago
by
rvanil
2
Comments
Threat profile is a very interesting concept that identifies the complete set of threats in a given application context. The Threat Analysis and Modeling (TAM) tool generates a threat profile using an inclusive methodology; in other words, it uses the...
Microsoft Application Threat Modeling Blog
Create a good threat model in 10 simple steps
Posted
over 5 years ago
by
rvanil
2
Comments
How can I get a great and secure product without killing myself? This is not just a question for how-to diet magazines; it’s a legitimate business problem. I teach the ACE Threat Modeling class (First Wednesday of every month!), and that is the question...
Microsoft Application Threat Modeling Blog
Rich Internet Applications - The New Security Frontier
Posted
over 5 years ago
by
MJD
3
Comments
In the past we have been relying on the web browser to provide/restrict the user interface for interacting with applications on the Internet. As security teams slowly work to fix the usual SQL Injection, XSS, Input validation attacks there is a whole...
Microsoft Application Threat Modeling Blog
Enterprise Edition
Posted
over 5 years ago
by
talhahm
0
Comments
I recently did a TechNet webcast to talk about how Microsoft IT Manages Security Knowledge for Better Application Risk Management and in it had a chance to demo a near release build of TAM Enterprise. Check it out: http://msevents.microsoft.com/CUI...
Page 1 of 3 (62 items)
1
2
3
MSDN Blogs
>
Microsoft Application Threat Modeling Blog