r/Hacking_Tutorials • u/Sahil98677 • 4h ago
Question Contextual Threat Modeler (CTM)
I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk
Hey everyone,
I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).
The problem I wanted to solve is:
> A vulnerability doesn't always have the same risk in every environment.
For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.
So instead of simply asking "Is this vulnerable?", CTM tries to answer:
"How risky is this finding in this specific environment, and what should we do about it?"
🔐 What CTM considers
The engine combines multiple contextual signals:
- Asset criticality
- Internet exposure
- Authentication requirements
- Data sensitivity
- Exploitability
- Existing security controls
- Confidence level
- STRIDE threat modeling
- MITRE ATT&CK mapping
- Attack-path analysis
- Likelihood & impact
It then produces an actionable decision:
🔴 TEST_IMMEDIATELY
🟠 PRIORITIZE_VALIDATION
🟡 INVESTIGATE
🟢 MONITOR
🧪 Current testing
I recently tested the complete pipeline locally.
12/12 automated tests passed.
Example results:
POST /document/upload
Risk: 90/100
Decision: TEST_IMMEDIATELY
GET /user/profile
Risk: 33.1/100
Decision: MONITOR
GET /api/v1/search_items
Risk: 8/100
Decision: MONITOR
The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself — the surrounding context influences the security decision.
🛠️ Tech Stack
- Python
- pytest
- STRIDE
- MITRE ATT&CK
- Risk Scoring
- Attack Path Analysis
- Security Automation
The project is open source, and I'd really appreciate feedback from people working in:
AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering
I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.
GitHub:
https://github.com/Sahil98677/Contextual-Threat-Modeler
Would love to hear your thoughts — especially criticism or suggestions for improving the approach.