ThreatTree is a browser-based threat-modeling tool that groups work into forests containing Data Flow Diagrams and Attack Trees. It scores risk by likelihood and impact, then creates a ranked risk register across the trees in a forest. Threats can be tagged with STRIDE, LINDDUN, OWASP Top 10, CAPEC and MITRE ATT&CK, while mitigations can be mapped to standards such as ISO 27001:2022, NIST SP 800-53 Rev 5, CIS Controls v8, PCI DSS v4.0, NIST CSF 2.0 and SOC 2. Invited collaborators can have owner, editor or viewer roles. Reports are available as PDFs, with JSON and STIX 2.1 exports. Optional per-forest AES-256-GCM encryption is offered on every plan, including Free. ThreatTree says data is kept on UK servers, connections use TLS 1.2 or higher, and encrypted database backups are made daily and retained for 30 days. Free allows up to three forests, three DFDs per forest and five Attack Trees per DFD. Pro costs 29.00 USD per month per user, billed monthly; Enterprise pricing is by quote. ThreatTree says it is not currently SOC 2 or ISO 27001 certified.
Who it is for
ThreatTree suits security teams, from solo consultants to CISO organizations, that need to model threats and prioritize risk. Its collaboration roles support invited team members.
What is good
- Ranks risks by likelihood and impact
- Supports multiple threat frameworks and control standards
- Exports PDF, JSON and STIX 2.1 reports
- Optional AES-256-GCM encryption is available on every plan
What to know first
- Free plan limits forests and diagrams
- Pro costs 29.00 USD per month per user
- Enterprise pricing is by quote
- Not currently SOC 2 or ISO 27001 certified
Verdict
ThreatTree combines threat diagrams, risk ranking, framework tags and control mappings with collaboration and export options. Its free plan has modeling limits, and the maker says the product is not currently SOC 2 or ISO 27001 certified.
ThreatTree plans and pricing
All plansCompared on threat modeling software
- Free plan
- Yes
- Attack-path analysis
- Yes
- Risk prioritization
- Yes
- Collaborative review
- Yes
- Templates and frameworks
- Yes
- Modeling methods
- multiple
- Deployment
- cloud


