# Good Questions in Threat Modeling?

**URL:** <https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253>\
**Category:** Techniques & Tooling\
**Created:** [July 2, 2026, 7:04pm UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253 "2026-07-02T19:04:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hewerlin](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/hewerlin/32/67_2.png) [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Post date:** [July 2, 2026, 7:04pm UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253/1 "2026-07-02T19:04:02Z")

</div>

I am designing a Threat Modeling tool. It is good at (many to many) relationships!

At it’s heart, it has a set of rules with source type, question/prompt and target type. I can configure this really flexible.

A simple set and example is

```auto
HOME => What are we working on? => PROJECT
PROJECT => What can go wrong with <X>? => THREAT
THREAT => What helps with <X>? => MITIGATION

```

This helps create a tree of PROJECT, THREAT and MITIGATION nodes.

If I want likelihood/impact, I might add

```auto
THREAT => How likely is <X>? => LIKELIHOOD
THREAT => How bad is <X>? => IMPACT

```

If I am concerned about MITIGATION bypasses, I might add

```auto
MITIGATION => How could someone bypass <X>? => THREAT

```

(Notice how I introduced a circular thing?)

I’m fiddling around with different variants.

# Call for ideas

**What would you think would be a promising set of source type =\> question =\> target type rules, so that Threat Modeling will be best supported?**

---

<div class="post-metadata">

**Author:** ![hewerlin](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/hewerlin/32/67_2.png) [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Post date:** [July 6, 2026, 5:54pm UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253/2 "2026-07-06T17:54:36Z")

</div>

There’s some response in OWASP #threat-modeling Slack.

@AviD suggests asking “Tell me more.”

@izar advocates asking “How important is that to you”

…

---

<div class="post-metadata">

**Author:** ![hewerlin](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/hewerlin/32/67_2.png) [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Post date:** [July 7, 2026, 4:53pm UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253/3 "2026-07-07T16:53:08Z")

</div>

See also [OWASP TM Slack](https://owasp.slack.com/archives/C1CS3C6AF/p1783359847027799?thread_ts=1783359847.027799&cid=C1CS3C6AF)

Discussion spawned by @irene221b if we even need generator questions / is TM science and/or art.

---

<div class="post-metadata">

**Author:** ![hewerlin](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/hewerlin/32/67_2.png) [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Post date:** [July 8, 2026, 4:58am UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253/4 "2026-07-08T04:58:53Z")

</div>

More discussion about what static questions can do opposed to creative tailored questions…

OWASP thread evolves interestingly.
