100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
Security & Networking Foundations
55 minbeginner

Practice — Build a Threat Model for a Sample Web App

This exercise applies every concept from Module 1 to a concrete target: a small web application with a login page, a user profile API, and a database storing personal data. You will identify assets worth protecting, list plausible threat actors, map the attack surface, and score each risk by likelihood and impact using Lesson 2's vocabulary. The goal is a working habit: given any new system, you should be able to produce a first-pass threat model within an hour.

Analogy🏏Cricket
💪 Think of it like fitness: injuries follow a predictable chain — poor warm-up, then form breakdown, then compensation, then the actual tear — and a good physio catalogs where each patient's chain can be interrupted early, rather than only treating the tear afterward. MITRE ATT&CK is the sports-medicine literature of intrusions: a public catalog of every observed breakdown pattern, organized by the stage it serves — how attackers get in, how they escalate, how they extract. Coaches worldwide describe an athlete's risk in that shared vocabulary. This reveals ATT&CK's real value: intrusions become a sequence you can interrupt at stage two, not a disaster you discover at stage five.
Lesson 6 of 35
0% complete