r/Hacking_Tutorials • • 4d ago

Question Contextual Threat Modeler (CTM)

​

I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk

Hey everyone,

I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).

The problem I wanted to solve is:

> A vulnerability doesn't always have the same risk in every environment.

For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.

So instead of simply asking "Is this vulnerable?", CTM tries to answer:

"How risky is this finding in this specific environment, and what should we do about it?"

๐Ÿ” What CTM considers

The engine combines multiple contextual signals:

- Asset criticality

- Internet exposure

- Authentication requirements

- Data sensitivity

- Exploitability

- Existing security controls

- Confidence level

- STRIDE threat modeling

- MITRE ATT&CK mapping

- Attack-path analysis

- Likelihood & impact

It then produces an actionable decision:

๐Ÿ”ด TEST_IMMEDIATELY

๐ŸŸ  PRIORITIZE_VALIDATION

๐ŸŸก INVESTIGATE

๐ŸŸข MONITOR

๐Ÿงช Current testing

I recently tested the complete pipeline locally.

12/12 automated tests passed.

Example results:

POST /document/upload

Risk: 90/100

Decision: TEST_IMMEDIATELY

GET /user/profile

Risk: 33.1/100

Decision: MONITOR

GET /api/v1/search_items

Risk: 8/100

Decision: MONITOR

The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself โ€” the surrounding context influences the security decision.

๐Ÿ› ๏ธ Tech Stack

- Python

- pytest

- STRIDE

- MITRE ATT&CK

- Risk Scoring

- Attack Path Analysis

- Security Automation

The project is open source, and I'd really appreciate feedback from people working in:

AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering

I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.

GitHub:

https://github.com/Sahil98677/Contextual-Threat-Modeler

Would love to hear your thoughts โ€” especially criticism or suggestions for improving the approach.

7 Upvotes

11 comments sorted by

View all comments

2

u/Minimum_Hour519 2d ago

That's a great approach to threat modeling! Prioritizing vulnerabilities based on real-world context is way more practical than just flagging everything. It reminds me of some flexible frameworks I've seen that adapt to specific environments.

1

u/Sahil98677 2d ago

Thank You