> For the complete documentation index, see [llms.txt](https://docs.devarmor.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.devarmor.com/modules/threat-modeler.md).

# Threat Modeler

How to do threat modeling with DevArmor

DevArmor's Threat Modeler turns a description of your application, architecture, or feature into a structured threat model: the trust boundaries and components at risk, the threats that apply to them, and the controls and tasks needed to mitigate those threats.

A threat model moves through five stages:

1. [**Starting a threat model**](/modules/threat-modeler/starting-a-threat-model.md) — import an existing threat model, or describe your application from code, documents, and diagrams.
2. [**Verify Application Attributes**](/modules/threat-modeler/verify-application-attributes.md) — review and correct what DevArmor inferred about your application before analysis runs.
3. [**Architecture & Diagrams**](/modules/threat-modeler/architecture-and-diagrams.md) — DevArmor's view of your system: components, data flows, and trust boundaries.
4. [**Review Threat Model Output**](/modules/threat-modeler/review-threat-model-output.md) — the threats, risks, and controls DevArmor identified.
5. [**Implement Threat Model Results**](/modules/threat-modeler/implement-threat-model-results.md) — turn output into mitigation actions, tests, and tasks in your existing tools.

See [Data Model Hierarchy](/modules/threat-modeler/data-model-hierarchy.md) for how threat models relate to projects, teams, and your organization; [Threat Model Versions](/modules/threat-modeler/threat-model-versions.md) for iterating on a threat model over time; and [Reports & Exports](/modules/threat-modeler/reports-and-exports.md) for sharing results outside DevArmor.
