Visualizing attack trees

Came across these tools referenced in an article, and thought it was worth capturing here.

  • Attack Flow Builder
  • SecurITree, developed by Amenaza Technologies, is purpose-built for attack tree analyses and allows for the addition of detailed attributes to different attack paths, risk metrics, and adversary personas.
  • The AT-AT (Attack Tree Analysis Tool) allows users to develop and analyze attack scenarios in much the same way.
  • AttackTree by Isograph similarly allows for attack tree modeling and additional threat analyses beyond the capabilities of a basic visualization tool.

If you know of any more tools for attack trees, add them to the thread!

1 Like

I find it useful to know that everyone can show and edit an attack tree everywhere with just plain indented text. And I use :open_umbrella: / :cloud_with_lightning_and_rain: unicode a lot. :smiley:

  • :cloud_with_lightning_and_rain: ThreatModCon fails
    • :cloud_with_lightning_and_rain: Nobody buys any tickets
      • :question:
    • :cloud_with_lightning_and_rain: Talks are bad
      • :open_umbrella: Invite awesome speakers with hot topics
      • :open_umbrella: Have different stages so attendees can decide
    • :cloud_with_lightning_and_rain: Talks can’t be delivered
      • :cloud_with_lightning_and_rain: Speaker misses flight
      • :cloud_with_lightning_and_rain: Speaker gets sick
      • :open_umbrella: Have backup talks
1 Like

@Dave
One more tool I can add:
AttackTree: Model, Simulate, Defend - attacktree.online

I haven’t used it myself yet, but I have seen how its inventor used it very sophisticatedly.

The creator is Christian Schneider, who is also known in our Community as the creator of threagile.

I’m about to develop a tool for model-based attack defence trees. If anyone is interested in experimenting with it for expressing their real-world attack defence trees, let’s talk.

1 Like

Adding couple of more tools, I haven’t tried them myself yet, but they look promising based on what I’ve read.

deciduous - A web app that simplifies building decision trees to model adverse scenarios

ADTool - Attack-Defense Tree Tool

ENT - An attack tree visualiser built in Node.js

Mermaid.js and Mermaid.live