Safeguard
Tag

threat-modeling

Safeguard articles tagged "threat-modeling" — guides, analysis, and best practices for software supply chain and application security.

44 articles

Industry Analysis

MITRE ATT&CK Meets SSDF: A Mapping

ATT&CK describes how adversaries operate; SSDF describes how to build software that resists them. Here's how to map adversary techniques to secure-development tasks so your threat model drives real engineering change.

Mar 18, 20267 min read
AI Security

What Is Explainable AI? A Security Practitioner's Guide

Explainable AI makes model decisions inspectable so security teams can trust, audit, and defend them. Here is what that means in practice.

Mar 14, 20266 min read
Engineering

A Beginner's Guide to Threat Modeling Your Build Pipeline

Your CI system is a production system with worse access controls. A first threat model of the pipeline takes one whiteboard session and usually finds something ugly.

Mar 7, 20267 min read
Threat Intelligence

The Supply Chain Attack Kill Chain: A Framework for Defense

We propose a kill chain framework specific to software supply chain attacks, mapping attacker techniques to defensive controls at each stage.

Mar 5, 20266 min read
Security Operations

Security Architecture Review Process: A Practical Framework

Architecture reviews catch security issues before code is written. Most organizations skip them or do them poorly. Here is a process that works.

Feb 18, 20266 min read
Best Practices

What is a Trust Boundary

A trust boundary is where data crosses into a higher-privilege context and must be verified. Learn where they hide and how breaches like Log4Shell exploited them.

Feb 3, 20266 min read
Open Source Security

A Taxonomy of Open Source Supply Chain Attacks

Supply chain attacks on open source come in distinct flavors. Understanding the taxonomy helps defenders prioritize controls and recognize threats before they reach production.

Jan 25, 20267 min read
Threat Modeling

Threat Modeling the Software Supply Chain

Traditional threat modeling focuses on your code. Supply chain threat modeling extends to every tool, dependency, and process that touches your software. Here is how to do it systematically.

Jan 24, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

threat-modeling (Page 4) — Safeguard Blog