Skip to main content

python tool for Microsoft Threat modeling tool

Project description

TMTool

A Threat Modeling GUI utility that works with Microsoft Threat Modeling Tool. This project aims to assist with the workfolw of template developers and model makers. For template design, this project hopes to address some of the complexities that come with managing a “database” of threats and stencils. For modeling, this project experiments with extracting information from our model and improving how Threat Modeling fits within DevOps and SDLC.

Installation

$ pip install TMTool

Scripts

.tb7 template files:

  • template2xlsx.py - enumerate a template's stencils, threat categories, and threats, and threat logic. Save elements/stencils and threats as a .xlsx file.

  • xlsx2template.py - script to convert template.xlsx file back into a .tb7 file. For merging new threats or editing templates, you would modify and convert back to .tb7 format

  • template2sql.py - enumerate a template's threats and stencils/elements. Save as SQLite .db file.

.tm7 model files:

  • model2csv.py - enumerate a model's flows, notes, stencils, stencil properties, and any other information from a model which we cannot get from TMT's built-in csv file generation but which will later be used in conjunction with the generated csv file.

  • set_metadata_tags.py (work in progress) - set a model's metadata such as risk level and compliance standards

  • cvss.py (work in progress) - experimental script for scoring threat IDs with CVSS

MS Threat Model generated .csv threat list files:

  • jira_issues.py - experimental script to add generated threat list to Jira Project as a set of issues. Also sets issue priority level and issue description from the threat. See empty_creds.py accessing your JIRA. This script can set the issue status to the threat's status if the JIRA transitions are available.

HTML report files:

  • fix_report_hyperlinks.py - This script will fix report hyperlinks that are broken since MS TMT encodes HTML entities within their generated report

  • confluence.py - Script will publish a HTML and .docx report to confluence as an attachment

View threat_modeling_notes.txt for more

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

TMTool-0.0.13.tar.gz (14.6 kB view details)

Uploaded Source

Built Distribution

TMTool-0.0.13-py3-none-any.whl (19.4 kB view details)

Uploaded Python 3

File details

Details for the file TMTool-0.0.13.tar.gz.

File metadata

  • Download URL: TMTool-0.0.13.tar.gz
  • Upload date:
  • Size: 14.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/47.1.0 requests-toolbelt/0.9.1 tqdm/4.56.2 CPython/3.7.9

File hashes

Hashes for TMTool-0.0.13.tar.gz
Algorithm Hash digest
SHA256 a680e0721a9bb0fa99d3908573451542d6fbc1ab305e677394de2d700a2f13d4
MD5 dc151429fedb0d985030e5973238e214
BLAKE2b-256 62d7bc318f01fdec017e092d0da2c7476737b343578c4d7c3acaf3b597a8c503

See more details on using hashes here.

Provenance

File details

Details for the file TMTool-0.0.13-py3-none-any.whl.

File metadata

  • Download URL: TMTool-0.0.13-py3-none-any.whl
  • Upload date:
  • Size: 19.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/47.1.0 requests-toolbelt/0.9.1 tqdm/4.56.2 CPython/3.7.9

File hashes

Hashes for TMTool-0.0.13-py3-none-any.whl
Algorithm Hash digest
SHA256 7518a17e3261b9b89ff9d434f6bdb6fb07dbfdf72adddb2118073a82e5138527
MD5 e744964d35c0999cd554633d2c8d3dee
BLAKE2b-256 f79eb4f56c492eda0083225cc4cf434f6c53a9f632574d32596d0b3e0ab0d070

See more details on using hashes here.

Provenance

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page