ThreatModeler Platform could be improved by providing more context-aware recommendations based on the specific architecture and technology, as sometimes the automatically generated threats or controls need to be manually reviewed and adjusted. The integration part of ThreatModeler Platform is adequate, while the user interface is very good. For reporting, prioritization based on our top ten controls would be helpful.
I would like to see deeper integration of ThreatModeler Platform with CI/CD pipelines, cloud platforms, and infrastructure as code tools. More automation to automatically update threat models when application architecture changes would reduce manual maintenance. AI-driven recommendations for threat prioritization and mitigation could expedite reviews significantly. Better integration with vulnerability management and ticketing platforms would enhance end-to-end tracking. Overall, increased automation and real-time integration would make ThreatModeler Platform even more effective in the DevSecOps environment. I would like to see improvements mainly in the user interface and integrated reporting capabilities of ThreatModeler Platform. A more modern and intuitive UI would make it easier for new users to create and navigate complex models. Reporting could offer more customizable dashboards and executive-level summaries, so more flexible report options would also assist in sharing security findings with application and management teams. These enhancements would improve the platform's usability and reporting experience. We have covered most improvement areas needed for ThreatModeler Platform, such as real-time integration with CI/CD pipelines. In terms of reporting, I mentioned earlier the need for clear and easily understandable security documentation. The UI could become more intuitive when working with large and complex application models, and stronger AI-based threat prioritization and remediation recommendations would minimize manual review efforts. Enhanced integration with cloud and ticketing or vulnerability management platforms would also provide a more complete end-to-end security workflow.
The biggest improvement I see for ThreatModeler Platform would be closing the gap between the model and the architecture it describes; right now, everything is built manually. There is no importing from Terraform, CloudFormation, or CDK, so the moment the real infrastructure changes, the model quietly goes stale and nobody gets told. If it could ingest infrastructure-as-code to pre-populate the diagram and flag when a deployed architecture has drifted from the last saved model, that would remove the single biggest source of friction in the whole workflow. Additionally, I notice smaller things such as comment and collaboration features are thin, and there is no persistent link between threat statements and detection. ThreatModeler Platform is AWS-native by design, which cuts both ways. If pressed to prioritize one, I would say the infrastructure-as-code sync is most important; everything else is a usability improvement.
Some users have noticed a learning curve to fully utilize the platform's advanced features, and there is a desire for more intuitive customization options for specific reporting needs. These areas can be improved based on feedback from our organization.
There are areas for improvement in ThreatModeler Platform, particularly in cloud integration. You can connect with your VPC and it'll build models for you. That is definitely an area that needs improvement. We've tested it a few times and it's somewhat buggy. It'll double add components, stack components on top of each other, and doesn't make a readable diagram. It's a really good idea in theory because it can build out your entire VPC, but it's unpredictable. Aside from that major area for improvement, a minor issue with ThreatModeler Platform is being able to pin connections between components. Sometimes it won't connect to the right side of the left component. It'll circle all the way around, making an odd-looking connection. Where it could be a straight line, it does something unusual. It's a minor thing, but when you build a complex model, you want to make sure that your connection points are very concise and clear.
We meet with our customer rep on a regular basis and go over new features we request. The team has been quite responsive in fulfilling most of the things we've requested in the revisions as we go along. They implemented changes related to colors. That was one of the things we asked for. One feature that I would like to see is related to comments. Comments need to be layered so that they are always on top. When you click on the comment feature, a dialogue box pops up, and you start entering a comment and put it into a VPC or a group of some sort. When you click on that group, the comment shouldn’t disappear behind the group. That's a problem that I would like to see fixed. The comment should always stay on top. It should be at the top layer above everything else because I can't see a reason why the comments should be under the things that you're commenting on. ThreatModeler Platform needs an enhancement so that comments always remain on top layers in diagrams, preventing them from disappearing when interacting with other components.
ThreatModeler Platform automates threat modeling during application development to identify and analyze potential security risks, providing visual threat representations that facilitate collaboration.Designed for professionals in security, ThreatModeler Platform simplifies threat assessment by automating and streamlining the process. It integrates seamlessly into the development lifecycle, providing comprehensible visual insights into potential risks. This enables teams to efficiently address...
ThreatModeler Platform could be improved by providing more context-aware recommendations based on the specific architecture and technology, as sometimes the automatically generated threats or controls need to be manually reviewed and adjusted. The integration part of ThreatModeler Platform is adequate, while the user interface is very good. For reporting, prioritization based on our top ten controls would be helpful.
I would like to see deeper integration of ThreatModeler Platform with CI/CD pipelines, cloud platforms, and infrastructure as code tools. More automation to automatically update threat models when application architecture changes would reduce manual maintenance. AI-driven recommendations for threat prioritization and mitigation could expedite reviews significantly. Better integration with vulnerability management and ticketing platforms would enhance end-to-end tracking. Overall, increased automation and real-time integration would make ThreatModeler Platform even more effective in the DevSecOps environment. I would like to see improvements mainly in the user interface and integrated reporting capabilities of ThreatModeler Platform. A more modern and intuitive UI would make it easier for new users to create and navigate complex models. Reporting could offer more customizable dashboards and executive-level summaries, so more flexible report options would also assist in sharing security findings with application and management teams. These enhancements would improve the platform's usability and reporting experience. We have covered most improvement areas needed for ThreatModeler Platform, such as real-time integration with CI/CD pipelines. In terms of reporting, I mentioned earlier the need for clear and easily understandable security documentation. The UI could become more intuitive when working with large and complex application models, and stronger AI-based threat prioritization and remediation recommendations would minimize manual review efforts. Enhanced integration with cloud and ticketing or vulnerability management platforms would also provide a more complete end-to-end security workflow.
The biggest improvement I see for ThreatModeler Platform would be closing the gap between the model and the architecture it describes; right now, everything is built manually. There is no importing from Terraform, CloudFormation, or CDK, so the moment the real infrastructure changes, the model quietly goes stale and nobody gets told. If it could ingest infrastructure-as-code to pre-populate the diagram and flag when a deployed architecture has drifted from the last saved model, that would remove the single biggest source of friction in the whole workflow. Additionally, I notice smaller things such as comment and collaboration features are thin, and there is no persistent link between threat statements and detection. ThreatModeler Platform is AWS-native by design, which cuts both ways. If pressed to prioritize one, I would say the infrastructure-as-code sync is most important; everything else is a usability improvement.
Some users have noticed a learning curve to fully utilize the platform's advanced features, and there is a desire for more intuitive customization options for specific reporting needs. These areas can be improved based on feedback from our organization.
There are areas for improvement in ThreatModeler Platform, particularly in cloud integration. You can connect with your VPC and it'll build models for you. That is definitely an area that needs improvement. We've tested it a few times and it's somewhat buggy. It'll double add components, stack components on top of each other, and doesn't make a readable diagram. It's a really good idea in theory because it can build out your entire VPC, but it's unpredictable. Aside from that major area for improvement, a minor issue with ThreatModeler Platform is being able to pin connections between components. Sometimes it won't connect to the right side of the left component. It'll circle all the way around, making an odd-looking connection. Where it could be a straight line, it does something unusual. It's a minor thing, but when you build a complex model, you want to make sure that your connection points are very concise and clear.
We meet with our customer rep on a regular basis and go over new features we request. The team has been quite responsive in fulfilling most of the things we've requested in the revisions as we go along. They implemented changes related to colors. That was one of the things we asked for. One feature that I would like to see is related to comments. Comments need to be layered so that they are always on top. When you click on the comment feature, a dialogue box pops up, and you start entering a comment and put it into a VPC or a group of some sort. When you click on that group, the comment shouldn’t disappear behind the group. That's a problem that I would like to see fixed. The comment should always stay on top. It should be at the top layer above everything else because I can't see a reason why the comments should be under the things that you're commenting on. ThreatModeler Platform needs an enhancement so that comments always remain on top layers in diagrams, preventing them from disappearing when interacting with other components.